Closebook · Legal
Data processing addendum
The terms that apply when Closebook processes personal data on your instructions: what we may do with it, the security measures behind it, who else touches it, and how it crosses borders lawfully.
Last updated 10 September 2026
Scope and roles
This addendum forms part of the terms of service between [REGISTERED ENTITY NAME], Inc. ("processor", "we") and the customer organisation ("controller", "you"), and applies whenever we process personal data contained in your workspace on your behalf.
You are the controller: you decide what personal data enters Closebook and for what purpose. We are the processor and act only on your documented instructions, of which your configuration and use of the product are part. Where terms conflict, this addendum governs for personal data processing.
Subject matter, duration, nature and purpose
- Subject matter — provision of the Closebook financial data platform.
- Duration — for as long as your workspace is open, plus the retention window in §7.
- Nature and purpose — importing, storing, mapping, reconciling and reporting on financial records you supply or connect.
- Categories of data subject — your personnel who use Closebook, and any individual named in the financial records you import: counterparties, suppliers, contractors, employees, customers.
- Categories of personal data — names, business contact details, account identifiers, payment and transaction details, invoice contents, and whatever else appears in the statements you import.
- Special category data — Closebook is not designed for it and you should not put it in. If your records happen to contain it, you remain responsible for the lawfulness of that.
Our obligations
- Process personal data only on your instructions, and never for our own purposes. We do not sell it and we do not use your workspace content to train models.
- Keep it confidential, and bind our personnel to confidentiality.
- Implement appropriate technical and organisational measures — see §5 and the security page.
- Assist you, at your cost where the work is substantial, with data subject requests, impact assessments and regulator enquiries.
- Tell you without undue delay if we become aware of a personal data breach affecting your data, with the information you need to meet your own notification duties.
- Tell you if an instruction of yours appears to us to breach applicable data protection law.
Your obligations
You confirm you have a lawful basis for the personal data you put into Closebook and for having us process it, that you have given any notices and obtained any consents required, and that your instructions will not put us in breach of applicable law. You are responsible for the accuracy of what you import and for managing who you admit to your workspace.
Security measures
The measures we apply, described in full on the security page, include:
- tenant isolation enforced by database row-level security rather than application filtering;
- encryption in transit (TLS) and at rest, with connector credentials separately encrypted using AES-256-GCM;
- role-based access control inside each workspace, managed by you;
- restricted, recorded production access on our side, and an append-only audit log of administrative actions;
- automated backups with point-in-time recovery;
- change control through version control, review, automated checks and ordered database migrations.
We may change these measures over time provided the level of protection is not reduced.
Sub-processing
You give general authorisation for us to engage sub-processors. The current list, with each one's purpose and processing location, is published at /sub-processors and forms part of this addendum.
We will give workspace owners at least thirty days' notice by email before a new sub-processor begins processing your data. You may object on reasonable data protection grounds within that period; if we cannot offer an alternative, you may terminate the affected part of the service without penalty for the unused, prepaid remainder of the term.
Each sub-processor is engaged under written terms no less protective than these, and we remain liable to you for its performance.
International transfers
The application runs in Frankfurt, European Union (Vercel, region fra1) and the database is hosted Frankfurt, European Union (Supabase, eu-central-1). We are a US company, so personal data is accessed from the United States, and some sub-processors process there.
Where personal data of individuals in the EEA, UK or Switzerland is transferred outside those regions, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), incorporated into this addendum by reference, together with the UK International Data Transfer Addendum where UK data is involved and the Swiss adaptations where Swiss data is. We assess the laws of the destination and apply supplementary measures where needed.
Return and deletion
You may export your data at any time in CSV or Excel. On termination you have thirty days to export, after which we delete workspace content, subject to the retention periods in the privacy policy and to any legal obligation to retain records. Ask us in writing during those thirty days and we will delete sooner. Backups age out on their own cycle.
Audits and information
On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this addendum. We do not currently hold a third-party audit report or certification, so this takes the form of written answers and, where appropriate, a call with the engineers who operate the service.
Getting this signed
These terms apply automatically to every paid workspace. If your procurement needs a signed counterpart, or your own paper instead, write to legal@vizio.ai and we will sign. A signed addendum is included on Enterprise.