PlainNotice Back to site

Data Processing Addendum

Version 1.0 · Effective August 8, 2026
What this page is. This is PlainNotice's Data Processing Addendum ("DPA") — it forms part of our Terms of Service and governs our processing of Personal Data (including Consumer-Report Data) on Customer's behalf. It applies wherever Customer is subject to the GDPR, UK GDPR, CCPA/CPRA, the Colorado Privacy Act, another privacy regime requiring a written DPA, or whenever Customer requests one.

Effective Date: set upon Customer's acceptance of the Terms of Service.

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Terms") between Ellis Intelligence LLC d/b/a PlainNotice ("Processor", "we") and the customer entity identified in the subscription order ("Customer"). It governs Processor's processing of Personal Data — including Consumer-Report Data — on Customer's behalf. Customer acts as the controller of that Personal Data as described in §2.1.


1. Definitions

  • "Consumer-Report Data" means the adverse-action case information Customer transmits through the Service that is derived from a "consumer report" as defined in FCRA 15 U.S.C. §1681a(d) — the adverse-action subject's identifiers, the source of the report Customer obtained, and the basic decision reason Customer supplies. It does not include the consumer report itself or its underlying background-check results or credit-file content: Customer does not upload those to the Service, and the Service does not receive them.
  • "Adequacy Decision" means a decision by the European Commission (or, for transfers from the UK or Switzerland, the competent UK or Swiss authority) that a country or territory ensures an adequate level of data protection, so that Personal Data may be transferred there without additional transfer safeguards.
  • "Customer Data" has the meaning given in the Terms and includes Consumer-Report Data subject to this DPA.
  • "Data Protection Law" means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, in each case as amended: (a) the FCRA (as applicable to processing on Customer's behalf); (b) Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"); (c) the GDPR as incorporated into United Kingdom law by the Data Protection Act 2018 (the "UK GDPR"); (d) the Swiss Federal Act on Data Protection ("FADP"); (e) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA"); (f) the Colorado Privacy Act ("CPA"); and (g) any other law that applies to a party's Processing of Personal Data under this DPA. Where more than one such law applies to a given Processing activity, each applies only to the extent of its own scope, and this DPA does not extend any such law's obligations beyond that scope.
  • "Data Subject" means the identified or identifiable natural person to whom Personal Data relates (including, under the CCPA, a "consumer").
  • "Personal Data" has the meaning set out in applicable Data Protection Law and includes "personal information" as defined in the CCPA.
  • "Process" / "Processing" has the meaning under applicable Data Protection Law.
  • "SCCs" means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, Module 2 (controller-to-processor).
  • "Service" means the PlainNotice software-as-a-service offering provided by Processor under the Terms.
  • "Subprocessor" means a third party engaged by Processor to process Personal Data on Customer's behalf.
  • "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the United Kingdom Information Commissioner's Office ("ICO").

2. Roles and Scope

2.1 As between the parties, Customer is the controller (as that term is defined in applicable Data Protection Law) of Personal Data within Customer Data. Processor processes Personal Data only as Customer's processor and on Customer's documented instructions. (This DPA refers to the parties as "Customer" and "Processor" throughout; "controller" and "processor" are used only when describing the statutory roles.)

2.2 The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Schedule 1: provision of the PlainNotice adverse-action notice service, including generation of the pre-adverse and final adverse-action notice content from Customer-supplied data, per-jurisdiction waiting-period timing enforcement, dispute tracking, and chain-of-custody audit logging — for the term of the subscription plus the §9 deletion/return period. Types of Personal Data / Consumer-Report Data: adverse-action applicant identifiers (name, address, contact information necessary to generate and address the notices); the source of the report Customer obtained and the basic decision reason Customer supplies (never the consumer report itself, which Customer does not upload and the Service does not receive); waiting-period clock state and per-jurisdiction timing data; dispute records; the chain-of-custody events log; and Customer employee identifiers for audit-log attribution. Categories of Data Subjects: applicants subject to adverse action; Customer's employees and sub-tenant (Client Company) users.

2.3 Processor will not process Personal Data for any purpose other than to provide the Service to Customer, except as required by law. If law requires Processor to process for another purpose, Processor will inform Customer before processing (unless prohibited from doing so by law).

2.4 FCRA Allocation of Responsibility. Customer is the "user" of consumer reports under FCRA. Processor provides software tooling that generates the adverse-action notice content from data and a decision reason Customer supplies, runs the per-jurisdiction waiting-period clock, and keeps a chain-of-custody audit record; Customer reviews and approves each notice and sends it under its own name. Processor never delivers a notice to the consumer, and does not independently furnish, resell, or interpret consumer reports. Processor is not a consumer reporting agency or a reseller under FCRA. Customer is responsible for: (a) obtaining the consumer report lawfully and satisfying every FCRA obligation it owes as that report's user; (b) reviewing, approving, and sending each notice, and its substantive accuracy and legal sufficiency; (c) its own FCRA §1681m(a) compliance obligations.


3. Processor's Obligations

3.1 Compliance with Instructions. Processor will process Personal Data only on Customer's documented instructions as set forth in this DPA, the Terms, and Customer's use of the Service. Processor will inform Customer if Processor believes an instruction may violate applicable Data Protection Law.

3.2 Confidentiality. Persons authorized by Processor to process Personal Data are subject to a duty of confidentiality. Consumer-Report Data will not be disclosed to any personnel except as necessary to provide the Service.

3.3 Security Measures. Processor will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the measures described in Schedule 2.

3.4 Assistance to Customer. Processor will assist Customer, taking into account the nature of the Processing, in: - Responding to Data Subject Rights requests (see §4) - Notifying Personal Data breaches (see §6) - Conducting data protection impact assessments (where required) - Consulting with supervisory authorities (where required)

3.5 Records of Processing. Processor maintains records of processing activities as required by Article 30 GDPR and, where applicable, maintains an audit log of processing activities related to Consumer-Report Data (see Schedule 1).

3.6 Use Restrictions. Processor will not use Consumer-Report Data to: (a) profile individuals for purposes other than providing the Service to Customer; (b) build or enrich any data product or model; or (c) share with any party other than authorized Subprocessors under §5.


4. Data Subject Rights

4.1 Where a Data Subject (including an adverse-action applicant) contacts Processor directly with a rights request related to Customer's Personal Data or Consumer-Report Data, Processor will: - Not respond substantively except to acknowledge receipt - Promptly forward the request to Customer (within 5 business days) - Reasonably assist Customer in responding

4.2 Customer is responsible for verifying Data Subject identity and determining whether the request is valid and applicable, including any FCRA dispute-handling obligations Customer bears as the user of the consumer report.

4.3 Processor provides export tooling within the Service — including the chain-of-custody audit-log export — to assist Customer with access, portability, and FCRA-related record-production obligations.

4.4 As between the parties, Customer is solely responsible for responding to Data Subject requests forwarded under §4.1 within the time and in the manner required by applicable Data Protection Law. Liability for a failure to do so is allocated in §10.3.


5. Subprocessors

5.1 Customer authorizes Processor to engage Subprocessors. The current list is at plainnotice.com/subprocessors.

5.2 Processor will impose contractual obligations on each Subprocessor that are no less protective in substance than this DPA with respect to security, confidentiality, Consumer-Report Data use restrictions, and assistance to Customer. Processor's liability to Customer for its Subprocessors is governed by §5.5 and is not conditioned on Processor's recovery from any Subprocessor.

5.3 Processor will notify Customer in writing at least 30 days before adding or replacing a Subprocessor, by emailing the account's designated notification contacts (or by in-product notice) and by posting the change on the public subprocessor list at plainnotice.com/subprocessors. Written notice is deemed given when sent to the contact details then on the account (or when the in-product notice is first displayed); Customer is responsible for keeping those details current, and the notice and objection periods are not extended by a failure to read a properly sent notice. Customer may object on reasonable data-protection grounds within 30 days of the date notice is given. If Customer timely objects, Processor will not process Customer's Personal Data using the objected-to Subprocessor while the objection is unresolved. If the parties cannot agree on a resolution within 15 days of the objection, Customer may terminate the affected subscription by written notice; termination takes effect on Processor's receipt of that notice (or a later date Customer specifies, no more than 30 days after receipt), and Processor will refund the pro rata portion of prepaid fees attributable to the period after the effective date of termination within 30 days after that date.

5.4 Notwithstanding §5.3, where a Subprocessor must be replaced immediately for reasons beyond Processor's reasonable control (including a security incident affecting the Subprocessor, its insolvency, its sudden unavailability, or a change imposed by the Subprocessor on notice too short for Processor to give 30 days' advance notice), Processor may engage a replacement without advance notice and will post and email notice of the replacement without undue delay. Customer's objection right under §5.3 then applies from the date that notice is posted.

5.5 Processor remains liable to Customer for the acts and omissions of its Subprocessors to the same extent as if Processor performed the Processing itself.


6. Personal Data Breaches

6.1 Processor will notify Customer without undue delay, and in any event within five (5) business days of becoming aware, of a Personal Data Breach affecting Customer's Personal Data or Consumer-Report Data; provided that where the strictest applicable state breach-notification law or an FCRA-specific notice trigger requires Customer to act on a shorter timeline, Processor will use commercially reasonable efforts to notify Customer within whatever shorter period is necessary for Customer to meet that deadline.

6.2 The notice will include, to the extent reasonably known: nature of the breach and categories and approximate number of Data Subjects and records affected; whether Consumer-Report Data was involved; likely consequences; measures taken or proposed to address the breach and mitigate adverse effects; and a point of contact for additional information.

6.3 Processor will cooperate with Customer's investigation and provide reasonably necessary information.


7. Audit Rights

7.1 On reasonable advance written notice (at least 30 days, unless an emergency arising from a Personal Data Breach or Consumer-Report Data breach), Customer may verify Processor's compliance with this DPA by: (a) reviewing Processor's security-posture documentation — Processor does not claim SOC 2, ISO 27001, or any audited certification at this time and will make a report available under NDA if and when one exists; or (b) submitting a written questionnaire that Processor will respond to within 30 days; or (c) for material verified deficiencies not addressed within 60 days, conducting an on-site audit during business hours by a mutually agreed independent auditor at Customer's expense, subject to confidentiality and not more than once in any 12-month period.

7.2 Customer may not access another customer's data, Processor's source code, or any data that would breach Processor's confidentiality obligations to third parties.

7.3 For a Customer whose Personal Data is transferred under the SCCs or the UK Addendum incorporated at §8, nothing in this §7 limits that Customer's audit and inspection rights under Clause 8.9 of the SCCs. For that Customer, an audit request is satisfied first by §7.1(a)'s security-posture documentation (or SOC 2 report, once one exists) and the relevant Subprocessors' audit reports under NDA; any further Clause 8.9 inspection is conducted on reasonable notice, during business hours, subject to confidentiality obligations, and at Customer's expense except where the audit reveals material non-compliance.


8. International Data Transfers

8.1 Where Processor's processing of Personal Data subject to the GDPR or UK GDPR involves transfer outside the EEA, UK, or Switzerland to a country not covered by an Adequacy Decision, the SCCs (Module 2) and UK Addendum are incorporated into this DPA by reference, with the following selections: Clause 7 (Docking Clause) does not apply; Clause 9 (Subprocessors) Option 2 (general authorization with notice, per §5); Clause 11 (Redress) independent dispute resolution body not designated; Clause 17 (Governing law) law of Ireland; Clause 18 (Forum) courts of Ireland; Annex I.A (Parties) as set out in this DPA and the subscription order; Annex I.B (Description of Transfer) as set out in Schedule 1; Annex I.C (Competent Supervisory Authority) per the standard cascade (Customer's EEA member state, or its Article 27 representative's member state, or a member state where affected Data Subjects are located); Annex II (Technical and Organizational Measures) as set out in Schedule 2.

8.2 UK Addendum: Table 1 (parties) and Table 3 (transfer information) per the subscription order and this DPA; Table 2 selection: SCC version above; Table 4 (Importer/Exporter ending): neither. For transfers subject to the UK GDPR, the UK Addendum's mandatory clauses override Clauses 17 and 18, so those transfers are governed by the laws of England and Wales with disputes resolved in the courts of England and Wales.


9. Deletion and Return

9.1 Upon Customer's written request, Processor will delete or return (at Customer's option) Personal Data and Consumer-Report Data within 30 days of the request, except as required by law to retain. Upon termination of the Terms, absent such a request, Processor will retain Personal Data and Consumer-Report Data — including the chain-of-custody audit log — for the Retention Period configured for the Service, a single configurable window whose default is set to preserve the tamper-evident chain-of-custody audit log long enough to serve its evidentiary purpose for adverse-action disputes and FCRA-related recordkeeping, after which Processor will delete or return it (at Customer's option) within 30 days, except in each case as required by law to retain.

9.2 Customer may export Personal Data and the full chain-of-custody audit log via in-product export tooling at any time during the subscription.

9.3 Consumer-Report Data will not be retained beyond the applicable retention or deletion period specified in §9.1 in any raw, derived, or aggregated form except as required by applicable law.

Personal Data deleted by Processor under §9.1 may persist for a limited additional period in Processor's Subprocessors' backup, disaster-recovery, or system logs before those copies are themselves purged, consistent with each Subprocessor's own retention practice — for Fly.io (production hosting and database backups), active Customer Data is deleted within 30 days, with residual encrypted backup copies (volume snapshots) purged within 90 days; and up to 180 days for Google Workspace (Ellis's internal business email and documents only; Google Workspace does not process Customer's Personal Data). This subsection does not extend the periods in §9.1, which govern Processor's own systems.


10. Liability and Indemnification

10.1 Each party's liability under this DPA is subject to the limitations of liability in the Terms.

10.2 Notwithstanding §10.1, neither party's limitation of liability applies to violations of GDPR Article 82 that result in supervisory authority fines, which are governed by the parties' respective regulatory obligations.

10.3 Indemnification — stated in the executed contract. Customer acknowledges that Processor provides software tooling and does not guarantee that notices generated through the Service satisfy Customer's FCRA obligations. Customer's indemnification obligations, including the FCRA-claim indemnity, are stated in full on the face of the customer-executed SOW (the executed SOW, §12 — §12.2(h) for FCRA claims; incorporated for direct-tier Customers by the click-signed Order Form). This DPA states no indemnity of its own.

10.4 Data Subject request failures. The indemnity for Customer's failure to timely or properly respond to a Data Subject request forwarded under §4.1 — and its condition that Processor has complied with §3.4 and §4 — is stated at SOW §12.3. The allocation referenced in §4.4 is to that provision.


11. General

11.1 Conflict. In case of conflict between the Terms and this DPA, the DPA controls for matters within its scope.

11.2 Term. This DPA remains in force while Processor processes Customer's Personal Data and survives termination of the Terms for the period required by §9.

11.3 Governing Law. Same as the Terms, except where the SCCs or applicable Data Protection Law specifies otherwise.


Schedule 1 — Processing Description

  • Subject matter: Provision of the PlainNotice adverse-action notice service, including generation of the pre-adverse and final adverse-action notice content from Customer-supplied data, per-jurisdiction waiting-period timing enforcement, dispute tracking, and chain-of-custody audit logging.
  • Duration: Term of the subscription plus the §9 deletion/return period.
  • Nature: Storage, retrieval, processing, structured display, and generation of consumer-report data, adverse-action applicant information, and adverse-action notice content.
  • Purpose: Enable Customer to generate jurisdiction-specific pre-adverse and final adverse-action notices, enforce the FCRA-required waiting-period clock, and maintain an auditable chain-of-custody record.
  • Types of Personal Data: Adverse-action applicant identifiers; the source of the report Customer obtained and the basic decision reason Customer supplies (not the consumer report itself); waiting-period clock state; dispute records; chain-of-custody events log; Customer employee identifiers for audit-log attribution.
  • Categories of Data Subjects: Applicants subject to adverse action; Customer's employees and sub-tenant (Client Company) users.
  • Frequency: Continuous during subscription, on each adverse-action case initiated by Customer.

Schedule 2 — Technical and Organizational Measures

Customer data is stored on encrypted infrastructure (disk-level encryption at rest) and served exclusively over TLS with authenticated, least-privilege access; we operate automated health monitoring, and independent external uptime monitoring on every live brand host.

  • Per-tenant isolation via application-layer, tenant-scoped query enforcement on all Customer Data stores (every query is required to include a tenant-scoping filter, enforced before the query runs) — PlainNotice extends this to a three-level nested tenancy (PlainNotice → Customer → Client Company), row-level-scoped by tenant_id and company_id
  • Annual security review and remediation
  • Personnel confidentiality obligations and security training
  • Subprocessor due diligence and contractual obligations
  • Incident response procedures with a breach-notification commitment of five (5) business days of becoming aware (or sooner, per §6.1, where necessary to meet the strictest applicable state breach-notification law or FCRA-specific notice trigger)
  • LLM subprocessing: LLM API calls processing Customer Data are not currently covered by a written Zero Data Retention ("ZDR") agreement with the provider or a code-level enforcement gate; Processor does not represent Zero Data Retention as a current safeguard and will not make or reinstate that representation until both are in place

Schedule 3 — US State Privacy Terms

Processor is a service provider / processor (as those terms are defined under applicable US state privacy law) with respect to Personal Data processed under this DPA. Processor will not sell or share Personal Data, will not retain, use, or disclose Personal Data for any purpose other than the specific business purpose of performing the Service, and will not combine Personal Data received from Customer with Personal Data received from another source except as permitted by applicable Data Protection Law. No additional jurisdiction-specific term applies beyond the CA/CO baseline stated above.

PlainNotice is software, not a law firm, and does not provide legal advice. PlainNotice is not a consumer reporting agency and not a furnisher under the FCRA, and has not been reviewed, approved, endorsed, certified, or licensed by the FTC, the CFPB, or any state regulator.