Effective October 8, 2026 · Version 2026-10-08
Data Processing Addendum
This Data Processing Addendum (“DPA”) is between AJAI LLC and Customer and forms part of the PayCanvas Terms of Service when PayCanvas processes Customer Personal Data on Customer’s behalf.
1. Definitions and scope
“Customer Personal Data” means personal information or personal data contained in Customer Data that AJAI LLC processes as a processor or service provider for Customer. “Data Protection Law” means privacy and data-protection law applicable to that processing. “Process,” “controller,” “processor,” “business,” “service provider,” “sell,” and “share” have the meanings given by applicable Data Protection Law. Capitalized terms not defined here have the meanings in the Terms.
This DPA applies only to Customer Personal Data processed to provide PayCanvas. It does not govern information AJAI LLC processes as an independent controller or business for its own account administration, billing, security, legal, or public-site purposes, as described in the Privacy Policy.
2. Roles and instructions
Customer is the controller or business and AJAI LLC is the processor or service provider. Customer instructs AJAI LLC to process Customer Personal Data to provide, secure, maintain, and support PayCanvas; perform actions initiated by authorized users; comply with the agreement and documented lawful instructions; and comply with law. The agreement, product configuration, authorized user actions, and written support requests constitute Customer’s documented instructions.
AJAI LLC will process Customer Personal Data only for those purposes and will notify Customer if we reasonably believe an instruction violates Data Protection Law, unless prohibited. Customer is responsible for the legality, accuracy, and scope of its instructions; its notices and consents; and responding as controller or business to its workers and other data subjects.
3. U.S. service-provider commitments
Where U.S. state privacy law applies, AJAI LLC will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship or for a commercial purpose other than the business purposes specified in the agreement, or combine it with personal information received from another person or collected from our own interactions except as permitted by law to provide the service. AJAI LLC will comply with applicable obligations, provide the same level of privacy protection required by applicable law, notify Customer if we can no longer meet an applicable obligation, and allow reasonable steps to stop and remediate unauthorized use.
4. Confidentiality and personnel
AJAI LLC will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only as needed for their responsibilities. Access may also be provided to approved subprocessors under written data-protection obligations.
5. Security
AJAI LLC will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Personal Data and the risks of processing. Current measures include logical tenant and role controls; MFA requirements for sensitive workflows; managed authentication, database, hosting, and secrets services; encryption in transit; provider encryption at rest where supported; audit and provenance records; backups and recovery controls; restricted credential handling; and processes for vulnerability, incident, and access management.
Customer is responsible for secure endpoints, user access, role assignment, source-provider configuration, and prompt reporting of suspected compromise. The safeguards may evolve without materially reducing the overall protection of Customer Personal Data.
6. Security incidents
AJAI LLC will notify Customer without undue delay after confirming a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in our possession or control (“Security Incident”). Notice will include available information reasonably needed for Customer’s legal obligations and will be supplemented as information becomes available. Notice is not an admission of fault or liability. Unsuccessful attempts, scans, blocked requests, and events that do not compromise Customer Personal Data are not Security Incidents under this DPA.
7. Subprocessors
Customer gives general authorization for AJAI LLC to use subprocessors to provide PayCanvas. The current list is at paycanvas.io/legal/subprocessors. We will impose data-protection obligations appropriate to the services and remain responsible for a subprocessor’s performance of those obligations to the extent required by the agreement and law.
We will post a material new subprocessor at least 30 days before it begins processing Customer Personal Data when practical. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate the affected feature. Emergency replacements needed for security, continuity, or law may occur sooner with notice as soon as practical.
8. Data-subject and compliance assistance
Taking into account the nature of processing and information available to us, AJAI LLC will provide reasonable assistance for verified data-subject requests, security and breach obligations, and legally required assessments or consultations. If we receive a request concerning Customer-controlled data, we may direct the requester to Customer and notify Customer where permitted. Customer is responsible for determining whether and how to respond. Assistance beyond standard product functionality may be subject to reasonable fees where permitted.
9. Government requests
AJAI LLC will disclose Customer Personal Data in response to legal process only where required by law. Unless prohibited, we will notify Customer before disclosure so Customer may seek protection. We will review requests for facial validity and disclose only information reasonably responsive to the request.
10. Return, deletion, and retention
During the subscription, Customer may access or export supported data through available features. After termination or a verified instruction, AJAI LLC will delete or return Customer Personal Data within a commercially reasonable period, except where retention is required by law, legal hold, dispute, security need, payroll-record instruction, backup rotation, or the agreement. Retained data remains protected and is processed only for the retention purpose. Current operational schedules are described in the Privacy Policy.
11. Information and audits
On reasonable written request, AJAI LLC will provide information reasonably necessary to demonstrate compliance with this DPA, such as relevant policies, summaries, or third-party reports then available. If that information is insufficient and Data Protection Law requires an audit, Customer may conduct one no more than annually through an independent auditor under confidentiality, on reasonable notice, during normal business hours, without accessing another customer’s data or disrupting the service. Customer bears its audit costs unless a material breach by AJAI LLC is found.
12. International transfers
PayCanvas is presently designed for U.S. business operations. Customer will not direct the transfer of European Economic Area, United Kingdom, or Swiss personal data to PayCanvas unless the parties first put an applicable lawful transfer mechanism in place. If the parties execute Standard Contractual Clauses or another transfer addendum, that instrument controls for the covered transfer.
13. Processing details
Subject matter and purpose: hosting and operating PayCanvas for source connection, onboarding, policy configuration, mapping, payroll preparation, calculation, explanation, review, support, security, and audit.
Duration: the subscription term plus the limited retention period described in the agreement and Privacy Policy.
Data subjects: Customer’s prospective, current, and former employees, contractors, owners, administrators, payroll operators, provider users, and other individuals whose information Customer directs PayCanvas to process.
Data categories: identity and contact information; employment and contractor information; roles, locations, schedules, time, attendance, bookings, work events, sales, tips, commissions, earnings, rates, pay rules, adjustments, totals, and payroll evidence; provider identifiers and connection metadata; account, authorization, security, support, and audit information. The public connector excludes the restricted categories identified in the AI and Connector Terms and Acceptable Use Policy.
Sensitive data: PayCanvas is not designed to process health information, benefits information, payment-card data, bank credentials, or government identifiers through public AI or connector channels. Customer must not provide those categories there. Other compensation and precise employment data may be sensitive under applicable law and is processed only as needed for the service.
Frequency and operations: continuous or user-initiated collection, recording, organization, storage, retrieval, consultation, calculation, comparison, disclosure to authorized recipients, restriction, deletion, and related processing as directed by Customer.
14. Liability, precedence, and contact
The liability limitations and exclusions in the Terms apply to this DPA. If this DPA conflicts with the Terms about Customer Personal Data, this DPA controls. Otherwise, the Terms remain in effect. Contact hello@paycanvas.io for data-protection matters.