Back to Onboarding

Data Processing Addendum (DPA)

Last updated: June 7, 2026

Controller / Processor

Clarifies roles: your firm is the Data Controller, Enma Labs is the Data Processor.

Security Measures

We implement industry-grade technical safeguards to prevent unauthorized data access.

Compliance Assured

Enables firms to demonstrate compliance with standard data protection regulations.

1. Scope and Applicability

This Data Processing Addendum ("DPA") governs the processing of personal and business data provided by the Chartered Accountant Firm ("Customer" or "Controller") to Enma Labs ("Processor") in connection with the Enma automation services. This DPA is integrated into, and forms part of, our Terms of Service.

2. Roles and Responsibilities

  • Controller: The Customer determines the purposes and means of processing personal data, controls files uploaded to the Telegram bot or dashboard, and ensures the necessary consents are in place before processing begins.
  • Processor: Enma Labs processes personal and business data solely on the Customer's written instructions, including the metadata extraction, OCR processing, and automated auditing requested through the platform dashboard.

3. Processor Obligations

As Processor, Enma Labs agrees to:

  • Process data only on documented instructions from the Controller, including with respect to transfer of data outside the originating country.
  • Ensure that all personnel authorized to process personal data have committed themselves to confidentiality agreements or are under an appropriate statutory obligation of confidentiality.
  • Implement technical and organizational measures to assist the Controller in responding to requests from data subjects exercising their legal rights (e.g., access, deletion, correction).

4. Security Measures

Enma Labs will maintain appropriate technical and organizational safeguards to protect data from accidental loss, alteration, unauthorized disclosure, or access:

  • Pseudonymization & Encryption: All client records are logically isolated using Postgres Row-Level Security. Database tables and storage buckets are encrypted using AES-256 at rest and HTTPS/TLS in transit.
  • System Resilience: Automated backups, distributed container services, and physical redundancies to ensure continuous service availability.
  • Incident Response: Regular vulnerability scanning and immediate incident logging in our system logs.

5. Sub-processors

Customer authorizes Processor to engage sub-processors to perform infrastructure services necessary to deliver the platform. We bind all sub-processors to standard contractual clauses ensuring an equivalent level of data protection. Our primary sub-processor list includes:

Sub-processorService DescriptionLocation
Supabase Inc.Database Hosting, Auth, and StorageUnited States (AWS)
Vercel Inc.Frontend Application Hosting & DeploymentGlobal CDN

6. Incident Notification & Audit Rights

  • Breach Notification: In the event of a verified security incident affecting Controller data, Enma Labs will notify the Customer within 72 hours of detection and provide regular updates.
  • Audits: Enma Labs will provide reasonable compliance summaries, configuration reports, and documentation to allow the Customer to verify compliance with this DPA.

7. Data Return and Deletion

Upon termination of the service agreement, Enma Labs will delete all Customer-provided personal and financial documents, along with all associated database records, within 30 days, unless statutory storage obligations require longer retention.