← Back to snapExpense

Data Processing Agreement

Last updated: August 10, 2026

1. Introduction

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between snapExpense (“Processor”) and the organization subscribing to a paid plan (“Controller”). It applies when snapExpense processes personal data on behalf of the Controller.

2. Definitions

  • Personal Data means any information relating to an identified or identifiable natural person uploaded to or processed by the Service.
  • Processing means any operation performed on Personal Data, including collection, storage, retrieval, extraction, use, disclosure, and deletion.
  • Sub-processor means a third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • Data Subject means the individual to whom Personal Data relates.

3. Scope of processing

snapExpense processes Personal Data solely to provide the Service as described in the Terms. The categories of data processed include:

  • Account data. Email addresses of team members for authentication.
  • Expense data. Merchant names, dates, amounts, tax figures, and categories.
  • Receipt images. Processed in real time for data extraction; not retained after extraction is complete.

Data subjects are the Controller’s employees and authorized users of the Service.

4. Processor obligations

snapExpense shall:

  • Process Personal Data only on documented instructions from the Controller, unless required by law.
  • Ensure that persons authorized to process Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures to protect Personal Data, including encryption in transit (HTTPS) and at rest, access controls, and rate limiting.
  • Not engage a Sub-processor without prior notice to the Controller. Current Sub-processors are listed on our Subprocessors page.
  • Assist the Controller in responding to Data Subject requests (access, correction, deletion, portability) to the extent technically feasible.
  • Notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach, and cooperate in breach response. We will also notify the Massachusetts Attorney General’s Office as required by M.G.L. c. 93H.
  • Make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits and inspections upon reasonable request.

5. Controller obligations

The Controller shall:

  • Ensure it has a lawful basis for providing Personal Data to snapExpense.
  • Provide processing instructions that comply with applicable data protection laws.
  • Notify snapExpense promptly of any Data Subject requests it cannot fulfill independently.

6. Sub-processors

snapExpense uses the Sub-processors listed on our Subprocessors page. We will notify the Controller at least 30 days before adding or replacing a Sub-processor. If the Controller reasonably objects to a new Sub-processor, either party may terminate the affected Service with a prorated refund.

Each Sub-processor is bound by data protection obligations no less protective than those in this DPA.

7. International transfers

Personal Data is stored and processed in the United States. If the Controller is subject to GDPR or other international data protection laws, we will cooperate to put in place appropriate transfer mechanisms (such as Standard Contractual Clauses) upon request.

8. Data retention and deletion

We retain Personal Data for as long as the Controller maintains an active account. The Controller may delete their account at any time from Settings, which removes all Personal Data immediately. Upon termination of the Service or upon the Controller’s written request, we will delete all Personal Data within 30 days, except where retention is required by law. The Controller may export their expense data to CSV at any time before deletion.

We do not maintain a separate archive of deleted data and cannot restore it once removed. See our retention policy for detail.

9. Security measures

snapExpense maintains the following security measures:

  • Encryption of data in transit (TLS/HTTPS).
  • Encryption of data at rest.
  • Authentication via secure, token-based magic links (no passwords stored).
  • Rate limiting on API endpoints.
  • Access controls limiting personnel access to Personal Data on a need-to-know basis.
  • A written information security program as required by 201 CMR 17.00.

10. Liability

Each party’s liability under this DPA is subject to the limitations set out in the Terms of Service.

11. Term and termination

This DPA takes effect when the Controller subscribes to a paid plan and remains in effect for the duration of the subscription. Obligations relating to data deletion, confidentiality, and breach notification survive termination.

12. Governing law

This DPA is governed by the laws of the Commonwealth of Massachusetts. Any dispute shall be resolved in the state or federal courts located in Boston, Massachusetts.

13. Contact

To execute this DPA, request modifications, or ask questions, email support@snap-expenses.com.