Data Processing Addendum (DPA)
Last updated: June 7, 2026
Controller / Processor
Clarifies roles: your firm is the Data Controller, Enma Labs is the Data Processor.
Security Measures
We implement industry-grade technical safeguards to prevent unauthorized data access.
Compliance Assured
Enables firms to demonstrate compliance with standard data protection regulations.
1. Scope and Applicability
This Data Processing Addendum ("DPA") governs the processing of personal and business data provided by the Chartered Accountant Firm ("Customer" or "Controller") to Enma Labs ("Processor") in connection with the Enma automation services. This DPA is integrated into, and forms part of, our Terms of Service.
2. Roles and Responsibilities
- Controller: The Customer determines the purposes and means of processing personal data, controls files uploaded to the Telegram bot or dashboard, and ensures the necessary consents are in place before processing begins.
- Processor: Enma Labs processes personal and business data solely on the Customer's written instructions, including the metadata extraction, OCR processing, and automated auditing requested through the platform dashboard.
3. Processor Obligations
As Processor, Enma Labs agrees to:
- Process data only on documented instructions from the Controller, including with respect to transfer of data outside the originating country.
- Ensure that all personnel authorized to process personal data have committed themselves to confidentiality agreements or are under an appropriate statutory obligation of confidentiality.
- Implement technical and organizational measures to assist the Controller in responding to requests from data subjects exercising their legal rights (e.g., access, deletion, correction).
4. Security Measures
Enma Labs will maintain appropriate technical and organizational safeguards to protect data from accidental loss, alteration, unauthorized disclosure, or access:
- Pseudonymization & Encryption: All client records are logically isolated using Postgres Row-Level Security. Database tables and storage buckets are encrypted using AES-256 at rest and HTTPS/TLS in transit.
- System Resilience: Automated backups, distributed container services, and physical redundancies to ensure continuous service availability.
- Incident Response: Regular vulnerability scanning and immediate incident logging in our system logs.
5. Sub-processors
Customer authorizes Processor to engage sub-processors to perform infrastructure services necessary to deliver the platform. We bind all sub-processors to standard contractual clauses ensuring an equivalent level of data protection. Our primary sub-processor list includes:
| Sub-processor | Service Description | Location |
|---|---|---|
| Supabase Inc. | Database Hosting, Auth, and Storage | United States (AWS) |
| Vercel Inc. | Frontend Application Hosting & Deployment | Global CDN |
6. Incident Notification & Audit Rights
- Breach Notification: In the event of a verified security incident affecting Controller data, Enma Labs will notify the Customer within 72 hours of detection and provide regular updates.
- Audits: Enma Labs will provide reasonable compliance summaries, configuration reports, and documentation to allow the Customer to verify compliance with this DPA.
7. Data Return and Deletion
Upon termination of the service agreement, Enma Labs will delete all Customer-provided personal and financial documents, along with all associated database records, within 30 days, unless statutory storage obligations require longer retention.