Skip to content
Gladpaid

Legal

Data processing terms

Last updated 22 September 2026 · Digital Infinity Group LLC

These terms apply automatically to every customer as part of the terms of service. There is nothing to sign; if your procurement process needs a countersigned copy, write to support@gladpaid.com.

01Scope and roles

These data processing terms form part of the agreement between the customer and Digital Infinity Group LLC for Gladpaid. They apply where we process personal data on the customer's behalf.

The customer is the controller of personal data in its business records. We are the processor. For account and billing data about the customer's own users, we act as a controller under the privacy policy.

A countersigned copy is available on request from support@gladpaid.com; the terms apply whether or not one is signed.

02Subject matter, duration, nature and purpose

Subject matter: reconciling stablecoin receipts and payments with the customer's accounting records, and posting entries the customer approves.

Duration: the term of the agreement, plus the retention periods in the retention schedule at /legal/retention.

Nature: collection from connected ledgers and public blockchains, storage, matching, valuation, extraction from uploaded documents, posting to the customer's ledger, export and deletion.

03Categories of data subjects and personal data

Data subjects: the customer's users; the customer's customers and suppliers named in its accounting records; individuals named in uploaded documents; holders of payer wallet addresses where those are individuals.

Personal data: names, business contact details, invoice and payment details, public wallet addresses and transaction references, and document contents. No special categories of data are needed for the service, and the customer agrees not to upload them.

04Our obligations as processor

Process personal data only on the customer's documented instructions, which are these terms and the customer's use of the service, unless the law requires otherwise, in which case we will say so first where allowed.

Make sure everyone with access is bound by confidentiality.

Apply the security measures described below and on /security.

Assist the customer, taking into account the nature of the processing, with data subject requests, security, breach notification, impact assessments and prior consultation.

Notify the customer of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of it, with the information the customer needs to meet its own duties.

At the end of the service, delete or return personal data as the customer chooses, except where the law requires us to keep it.

Make available the information needed to demonstrate compliance, and allow for audits by the customer or an auditor it appoints, on reasonable notice, at the customer's cost, and no more than once a year unless a regulator requires it or a breach has occurred.

05Security measures

Encryption in transit (TLS) and at rest; ledger credentials encrypted with keys held in a cloud key-management service.

Tenant isolation enforced by database row-level security; least-privilege access for staff; two-factor sign-in required for every user.

An append-only, hash-chained audit trail of significant actions; scrubbing of secrets and key material from logs and error reports; refusal of key material at every input.

Monitoring, backups, an incident response plan and an annual review of these controls.

06Subprocessors

The customer gives general authorisation for the subprocessors listed at /legal/subprocessors. Each is bound by written terms that protect personal data at least as well as these.

We will give at least 30 days' notice of a new subprocessor by updating that page and emailing account owners. The customer may object on reasonable data protection grounds; if we cannot address the objection, the customer may end the affected service and receive a pro-rated refund of prepaid fees.

We remain responsible for our subprocessors' performance of these obligations.

07International transfers

Personal data is processed in the United States and the other locations listed for each subprocessor. For transfers from the EEA, the UK or Switzerland, the Standard Contractual Clauses (module two, controller to processor, and module three, processor to processor, as applicable) and the UK addendum are incorporated by reference.

08Data from Xero and QuickBooks

Data obtained from Xero or QuickBooks is used only to provide the service to the business that connected it.

It is never used to train or fine-tune any artificial intelligence or machine-learning model, never pooled with other customers' data, and never sent to a language model unless the business has switched that on.

It is disclosed to third parties only as the subprocessors listed, and is removed when the business disconnects its ledger and its retention period ends.

Gladpaid is operated by Digital Infinity Group LLC, 15732 Los Gatos Blvd #5075, Los Gatos, CA 95032. Questions: support@gladpaid.com.