PipeLedger AI

Subscription Agreement
& Terms of Service

Last updated: August 11, 2026 · Version 2026-08-11 · Effective: August 11, 2026

These Subscription Agreement and Terms of Service ("Terms") are entered into between PipeLedger Inc., a Delaware corporation ("PipeLedger," "we," "us," or "our"), and the legal entity identified during checkout or in an Order Form ("Customer," "you," or "your").

By checking the acceptance box, selecting Start paid subscription, executing an Order Form that references these Terms, or accessing a paid Service, the individual accepting represents that they have authority to bind Customer and agrees to these Terms on Customer's behalf.

1. Agreement structure and precedence

1.1 Agreement

The "Agreement" consists of:

  1. these Terms, including Schedule 1, Standard Data Processing Terms, where applicable;
  2. the applicable checkout or subscription record;
  3. any Order Form, SLA, negotiated Data Processing Addendum, Security Addendum, or amendment executed by authorized representatives of both parties and expressly incorporated into the Agreement; and
  4. any document expressly incorporated by one of the foregoing.

The Privacy Notice and AI Governance & Security Overview are disclosures and informational materials. They are not incorporated as contractual service warranties unless an executed agreement expressly identifies a provision for incorporation.

1.2 Enterprise documents

Enterprise customers accept these Terms as the base agreement and may execute additional documents that supplement or modify the base agreement. Unless an executed document expressly states otherwise, an Enterprise document modifies the Agreement only for the customer, subscription, subject matter, and term it identifies.

1.3 Order of precedence

In a direct conflict, the following order controls, but only for the subject matter of the conflict:

  1. a signed amendment that expressly identifies the provision it overrides;
  2. a signed subject-specific addendum — for example, a negotiated Data Processing Addendum for privacy, an SLA for service levels, or a Security Addendum for security commitments;
  3. a signed Order Form for customer-specific commercial terms;
  4. these Terms, including Schedule 1 where applicable;
  5. the applicable checkout or subscription record; and
  6. Documentation.

A purchase order, vendor-portal term, onboarding form, or similar Customer document is for administrative convenience only. Its terms do not amend or supplement the Agreement, even if PipeLedger processes or acknowledges it, unless an authorized PipeLedger representative expressly agrees to those terms in a signed amendment.

1.4 Marketing and future features

Marketing materials, demonstrations, proposals, security questionnaires, roadmaps, and statements about planned or possible features are not part of the Agreement unless an executed Order Form or addendum expressly states otherwise. Customer's purchase is not contingent on future functionality.

2. Business use and authority

The Service is offered solely for business and professional use and not for personal, family, or household purposes. Customer represents that it is acquiring and using the Service only on behalf of a business or other organization and that it will not make the Service available as a consumer service.

The Service may assist Customer in collecting, organizing, transforming, and presenting financial information, including information that Customer or its professional advisers may use when preparing tax returns or other filings. PipeLedger does not prepare or file tax returns, determine tax treatment, provide tax advice, or replace review by a qualified accountant, tax professional, auditor, or legal adviser.

3. The Service and subscription right

3.1 Service

PipeLedger provides a cloud-hosted platform for financial-data extraction, transformation, governance, financial intelligence, and delivery to authorized people, applications, and AI agents (the "Service"). The Service may include subscription features and metered services measured through Financial Compute Units ("FCU") for pipeline processing and Financial Intelligence Queries ("FIQ") for data delivery.

3.2 Limited right to use

Subject to the Agreement and payment of all applicable fees, PipeLedger grants Customer, during the Subscription Term, a limited, non-exclusive, non-transferable, non-sublicensable right to permit its Authorized Users to access and use the Service for Customer's internal business purposes. No software copy is sold to Customer.

3.3 Organizations and legal entities

Customer storage and access controls are scoped at the organization level as described in the Documentation. Legal entities within an organization are reporting, governance, and authorization dimensions and are not separate tenants or contracting customers unless an Order Form expressly states otherwise. Customer is responsible for determining which affiliates and legal entities may be included and for obtaining their authorization.

3.4 Changes

PipeLedger may modify the Service to improve functionality or security, comply with law, address abuse, or respond to third-party dependencies. PipeLedger will not materially reduce the core functionality of a paid Service during the then-current Subscription Term except where reasonably necessary to address security, legal, regulatory, or third-party-platform requirements. A service level, support commitment, credit, or exclusive remedy applies only if stated in an executed SLA or Order Form.

3.5 Beta and evaluation features

Features identified as beta, preview, early access, evaluation, or similar are optional, may change or be discontinued at any time, and are provided without service levels or production commitments unless an executed agreement expressly states otherwise.

4. Accounts, administrators, and Customer responsibilities

Customer is responsible for:

  • its Authorized Users, Owners, administrators, service accounts, credentials, configurations, and connected applications;
  • ensuring each Authorized User is permitted to access Customer Data;
  • maintaining accurate account, contact, and billing information;
  • protecting credentials and promptly revoking compromised or unnecessary access;
  • configuring governance, scope, approval, identity, memo, publication, release, and data-sharing settings appropriate to its use;
  • all activity under its accounts and Customer-minted credentials, except to the extent caused by PipeLedger's breach of the Agreement; and
  • complying with laws applicable to Customer's data, activities, agents, filings, and decisions.

Owners and administrators may manage subscriptions, payment methods, cancellations, resubscriptions, usage budgets, add-ons, and other settings made available to their roles. Customer authorizes PipeLedger to rely on those actions. Usage budgets and alerts are administrative tools, not guaranteed hard spending limits, unless an Order Form expressly states otherwise.

Customer must not:

  1. access or use the Service unlawfully or beyond the Agreement;
  2. introduce malware or interfere with the Service;
  3. bypass security, usage-metering, approval, publication, delivery-policy, or access controls;
  4. attempt unauthorized access to another customer or system;
  5. use non-public Service elements, PipeLedger proprietary definitions, or PipeLedger proprietary outputs to train, develop, or materially improve a competing governed-financial-data product;
  6. reverse engineer the Service, except to the limited extent applicable law expressly permits notwithstanding this restriction; or
  7. resell, sublicense, time-share, or provide the Service to third parties outside Customer's organization unless an Order Form expressly authorizes managed-service or reseller use.

These restrictions do not limit Customer's lawful use of its own Customer Data.

5. Customer Data, privacy, and data rights

5.1 Customer Data

"Customer Data" means data submitted to, connected to, or processed by the Service on Customer's behalf, including ERP data, configurations, and data delivered through Customer-authorized integrations. As between the parties, Customer retains all right, title, and interest it lawfully holds in Customer Data.

Customer grants PipeLedger and its subprocessors a non-exclusive right to host, copy, transmit, transform, and otherwise process Customer Data only as necessary to provide, secure, support, and improve the Service as permitted by the Agreement; comply with law; and perform Customer's instructions.

5.2 Customer authority

Customer represents that it has all rights, notices, consents, and lawful bases required to provide Customer Data and instruct its processing. Customer is responsible for the accuracy, legality, quality, and integrity of Customer Data and for requests or disputes concerning underlying business records.

5.3 Data processing terms

Where PipeLedger processes Personal Data on Customer's behalf, Schedule 1 applies automatically and forms part of the Agreement. No separate signature is required. If the parties execute a negotiated Data Processing Addendum, that addendum supersedes Schedule 1 only for its subject matter and stated term.

5.4 Privacy Notice

PipeLedger's Privacy Notice describes how PipeLedger handles website, account, billing, sales, security, and operational information for its own business purposes. Customer acknowledges receipt of the Privacy Notice; the Notice is not a contractual service warranty except to the extent applicable law requires otherwise.

5.5 AI model training

PipeLedger will not use Customer Data to train a general-purpose AI model or permit a third-party model provider to train a general-purpose model on Customer Data unless Customer expressly authorizes that use in a written agreement identifying the purpose and applicable controls.

6. Financial data, publication, and independent verification

6.1 Nature of outputs

The Service processes and presents data. It does not provide accounting, audit, assurance, legal, tax, investment, fiduciary, or other professional advice. Customer is solely responsible for its accounting policies, books and records, internal controls, filings, disclosures, business decisions, and engagement of qualified professionals.

6.2 Source and configuration dependencies

Outputs depend on source-system availability and behavior, Customer Data, mappings, classifications, configurations, permissions, selected periods, third-party APIs, and other inputs. Source data may be incomplete, delayed, duplicated, mislabeled, changed, or inconsistent across systems. The Service does not independently verify the existence, accuracy, completeness, commercial substance, legal characterization, or accounting treatment of a source transaction.

Unless an Order Form expressly states otherwise, the Service does not perform or validate consolidation eliminations, tax determinations, audit procedures, statutory reporting, securities-law compliance, or the commercial substance of intercompany transactions.

6.3 Governance status is not certification

Approval, validation, publication, certification-status labels, provenance, reconciliation checks, audit records, and other governance features reflect technical or workflow states within the Service. They do not constitute an audit opinion, assurance engagement, accounting certification, legal-compliance determination, or representation by PipeLedger that Customer Data is accurate, complete, free from fraud, compliant with GAAP or IFRS, or suitable for a statutory filing.

An approval may be recorded by an authorized user or a credential with expressly granted auto-approval permission and therefore does not necessarily reflect human review. Customer remains responsible for independently validating outputs and maintaining its own books, records, internal controls, approvals, and professional review.

6.4 Required review and prohibited reliance

Customer must independently review and validate outputs before using them for a filing, disclosure, payment, journal entry, investment decision, credit decision, employment decision, tax position, or other decision that could create material legal or financial consequences. Customer must not represent that PipeLedger audited, certified, or approved Customer's financial statements or compliance.

7. Connected applications and AI agents

Customer controls which AI hosts, applications, agents, Business Intelligence tools, and other third-party services it authorizes. Requests and actions made with Customer-authorized credentials are attributed to Customer, including resulting usage charges and downstream use of returned data, except to the extent caused by PipeLedger's breach of the Agreement.

Customer is responsible for human oversight, credential scope, prompt-injection and automation risks, output review, and compliance with laws governing Customer's use of AI or automated decisionmaking.

Once data is transmitted to a Customer-authorized third-party host, that host's terms, privacy practices, security, retention, model-training settings, and administrative controls apply. PipeLedger does not control the third party's environment and is not responsible for its acts or omissions.

Customer must not use the Service or its outputs to make or substantially make a legally significant decision about an individual — such as a decision involving employment, housing, education, healthcare, insurance, credit, or access to essential goods or services — unless Customer has independently determined the use is lawful and implemented all required notices, assessments, opt-outs, appeals, human review, and other safeguards.

8. Governance, security, and Corporate Insider features

The Service includes configurable controls intended to support tenant separation, scoped access, data sensitivity, identity handling, publication workflows, release controls, and audit evidence as described in the Documentation. These controls depend on Customer configuration, role assignments, credential management, third-party systems, and Service limitations. They reduce risk but do not eliminate all risk of unauthorized access, disclosure, configuration error, service defect, or human error.

Audit records and publication evidence are technical records generated by the Service. They are not a substitute for Customer's legally required records, internal controls, books and records, compliance program, or independent audit procedures.

If Customer uses a feature intended to separate material nonpublic information or control a scheduled release, Customer remains solely responsible for securities-law compliance, insider lists, trading restrictions, disclosure controls, release authorization, and incident response. The feature is not a legal information barrier, broker-dealer control, disclosure committee, or guarantee against premature disclosure.

The AI Governance & Security Overview provides non-contractual information about current product design. Binding security commitments apply only if stated in these Terms or an executed Security Addendum, DPA, SLA, or Order Form.

9. Intellectual property

PipeLedger and its licensors retain all right, title, and interest in the Service, Documentation, software, schemas, non-customer-specific transformation logic, dbt models, Finance Catalog definitions, usage-measurement methods, and related intellectual property. Except for the limited right expressly granted in Section 3, no rights are granted by implication, estoppel, or otherwise.

If Customer provides feedback, Customer grants PipeLedger a perpetual, irrevocable, worldwide, royalty-free right to use and incorporate the feedback without restriction, provided PipeLedger does not identify Customer as the source without permission.

10. Third-party services

The Service may interoperate with ERP providers, cloud platforms, payment processors, AI hosts, and other third-party services. Customer authorizes PipeLedger to exchange Customer Data with the third parties Customer selects as necessary to provide the integration.

PipeLedger does not control and is not responsible for third-party services, changes to their APIs or terms, suspension of Customer's third-party account, or data handling after delivery to them. PipeLedger may suspend or discontinue an integration if continued operation would create a security, legal, or material technical risk.

11. Fees, usage, taxes, and payment

11.1 Fees and included usage

Subscription fees are billed in advance. Included FCU and FIQ allowances are granted and reset monthly, including for annual prepaid subscriptions, unless the applicable checkout record or Order Form states otherwise. Unused included allocations expire without credit at the end of the applicable monthly period.

Usage exceeding the included allowance is billed monthly in arrears at the rates presented at checkout, in the applicable rate schedule, or in an Order Form. PipeLedger's metering records control billing absent manifest error.

11.2 Billing disputes

Customer must notify PipeLedger of a good-faith billing dispute within thirty (30) days after the applicable invoice and provide reasonable supporting detail. Undisputed amounts remain due.

11.3 Administrator authority

Customer authorizes its Owners and administrators to take billing actions made available to their roles. Unless an Order Form states otherwise, upgrades take effect immediately and may be prorated; downgrades and cancellations take effect at the end of the then-current billing term.

11.4 Taxes

Fees exclude transaction, sales, use, value-added, withholding, and similar taxes. Customer is responsible for applicable taxes associated with its purchase, except taxes based on PipeLedger's net income, property, or employees. If PipeLedger is legally required to collect a tax, PipeLedger may invoice Customer for it unless Customer timely provides a valid exemption certificate.

11.5 Failed or overdue payment

If payment is overdue, PipeLedger may retry the payment method and, after notice where reasonably practicable, restrict, suspend, or terminate access. Customer remains responsible for accrued fees.

11.6 Refunds

Except as required by law or expressly stated in an Order Form, all fees are non-cancelable and non-refundable. PipeLedger does not provide refunds or credits for partial subscription periods, unused features, or expired FCU or FIQ allocations.

12. Subscription term, renewal, suspension, and termination

12.1 Subscription Term and renewal

The "Subscription Term" begins on the date shown at checkout or in the Order Form. Monthly subscriptions automatically renew for successive monthly terms and annual subscriptions automatically renew for successive annual terms unless canceled before the applicable renewal date, except as otherwise stated at checkout or in an Order Form.

Cancellation stops future renewal and takes effect at the end of the then-current Subscription Term. It does not retroactively reverse usage or fees already incurred.

12.2 Termination for breach

Either party may terminate the Agreement for a material breach that remains uncured thirty (30) days after written notice. PipeLedger may terminate or suspend immediately for unlawful use, violation of Section 4, a material security threat, or where continued performance would violate law or a binding third-party requirement.

12.3 Suspension

PipeLedger may suspend affected access immediately to prevent or address a security risk, unlawful use, harm to the Service or another customer, circumvention of governance or metering controls, overdue payment, or a legal or third-party-platform requirement. PipeLedger will use reasonable efforts to limit suspension to the affected portion and notify Customer when legally and operationally appropriate.

12.4 Data export and deletion

Subject to payment and legal restrictions, Customer may export Customer Data using generally available export functionality during the Subscription Term and for thirty (30) days after termination or expiration.

PipeLedger may delete Customer Data from active systems after sixty (60) days following termination or expiration and from backups according to the documented backup-retention cycle, except where retention is required by law or the Agreement. Deletion does not require alteration of records that must remain append-oriented for security, billing, fraud-prevention, dispute, or legal purposes, provided retained data remains protected and is not used for unrelated purposes.

12.5 Survival

Sections that by their nature should survive will survive, including payment, intellectual property, confidentiality, disclaimers, indemnification, limitations of liability, dispute terms, and general provisions.

13. Confidentiality and security

13.1 Confidentiality

Each party will use the other party's non-public information disclosed under the Agreement ("Confidential Information") only to perform or exercise rights under the Agreement and will protect it using at least reasonable care.

Confidential Information does not include information the receiving party can document: (a) is public without breach; (b) was lawfully known without restriction; (c) is received lawfully from a third party without confidentiality duty; or (d) is independently developed without use of the disclosing party's Confidential Information.

The receiving party may disclose Confidential Information to personnel, advisers, and service providers who need to know it and are bound by appropriate confidentiality duties. A legally compelled disclosure is permitted if the receiving party provides advance notice where lawful and reasonable assistance at the disclosing party's expense.

13.2 Security

PipeLedger will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Data, as further described in Schedule 1 or an applicable Security Addendum. No internet-connected service is completely secure, uninterrupted, or error-free.

Customer is responsible for determining whether the Service meets its security, compliance, backup, and retention requirements and for maintaining source records and exports appropriate to its obligations.

14. Warranty disclaimer

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE, DOCUMENTATION, OUTPUTS, BETA FEATURES, AND SUPPORT ARE PROVIDED "AS IS" AND "AS AVAILABLE." PIPELEDGER AND ITS LICENSORS DISCLAIM ALL EXPRESS, IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, COMPLETENESS, QUIET ENJOYMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. PIPELEDGER DOES NOT WARRANT THAT THE SERVICE OR ANY OUTPUT WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, CURRENT, COMPLETE, COMPLIANT WITH CUSTOMER'S OBLIGATIONS, OR SUITABLE FOR A FILING OR DECISION.

No oral or written information creates a warranty not expressly stated in an executed Order Form or addendum.

15. Customer indemnification

Customer will defend PipeLedger, its affiliates, and their respective officers, directors, employees, and agents (the "PipeLedger Parties") against a third-party claim arising from or relating to:

  1. Customer Data or an allegation that Customer lacked the right to provide or process it;
  2. Customer's or an Authorized User's unlawful use of the Service;
  3. a Customer-authorized application, agent, credential, decision, filing, disclosure, or downstream use of an output; or
  4. Customer's material breach of Sections 4, 5, 6, or 7.

Customer will indemnify the PipeLedger Parties for damages, judgments, settlements, penalties, costs, and reasonable attorneys' fees finally awarded or included in a settlement approved by Customer.

PipeLedger must promptly notify Customer of the claim, allow Customer to control the defense and settlement, and provide reasonable cooperation at Customer's expense. Customer may not settle a claim in a manner that admits fault by, imposes non-monetary obligations on, or fails to unconditionally release a PipeLedger Party without PipeLedger's written consent, not to be unreasonably withheld.

Any PipeLedger intellectual-property indemnity applies only if expressly included in an executed Enterprise Order Form or addendum.

16. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PIPELEDGER NOR ITS AFFILIATES, LICENSORS, SUBPROCESSORS, OR SUPPLIERS WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES; ANY LOSS OF PROFITS, REVENUE, SAVINGS, BUSINESS OPPORTUNITY, GOODWILL, OR REPUTATION; ANY LOSS, CORRUPTION, OR UNAVAILABILITY OF DATA; ANY COST OF SUBSTITUTE SERVICES; OR ANY DAMAGES ARISING FROM CUSTOMER'S FILINGS, DISCLOSURES, PAYMENTS, JOURNAL ENTRIES, BUSINESS DECISIONS, OR RELIANCE ON AN OUTPUT, REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE TOTAL AGGREGATE LIABILITY OF PIPELEDGER, ITS AFFILIATES, LICENSORS, SUBPROCESSORS, AND SUPPLIERS ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE FEES PAID BY CUSTOMER TO PIPELEDGER FOR THE AFFECTED SERVICE DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY. FOR A FREE, TRIAL, OR EVALUATION SERVICE, TOTAL AGGREGATE LIABILITY WILL NOT EXCEED ONE HUNDRED U.S. DOLLARS (US$100).

All claims arising from the same or related facts, circumstances, events, defects, or failures will be aggregated and treated as a single claim for purposes of the cap. The exclusions and limitations apply notwithstanding any failure of essential purpose of a limited remedy and form an essential basis of the parties' bargain.

Nothing in the Agreement excludes or limits liability to the extent that liability cannot lawfully be excluded or limited. No provision is intended to exempt any person from responsibility in contravention of California Civil Code section 1668 or other applicable law.

Customer's obligation to pay fees properly due, its indemnification obligations, and its liability arising from unauthorized use of the Service, infringement or misappropriation of PipeLedger intellectual property, or circumvention of security, governance, publication, or usage-metering controls are not limited by this Section.

Except for a claim that applicable law does not permit the parties to shorten, any claim arising out of or relating to the Agreement must be filed within one (1) year after the claim accrued or is permanently barred. This contractual period does not extend any shorter statutory period.

17. Governing law and disputes

California law governs the Agreement and any dispute arising out of or relating to it, without regard to conflict-of-laws rules. The parties consent to exclusive personal jurisdiction and venue in the state courts located in Los Angeles County, California, and the United States District Court for the Central District of California.

Either party may seek temporary or preliminary injunctive relief in a court of competent jurisdiction to prevent actual or threatened misuse of intellectual property, Confidential Information, credentials, or security controls.

Before filing a claim, the complaining party must provide written notice describing the dispute and requested relief. Business representatives with authority to resolve the dispute will attempt in good faith to resolve it for thirty (30) days. This requirement does not prevent urgent injunctive relief or a filing required to preserve a limitations period.

18. General terms

18.1 Assignment

Neither party may assign the Agreement without the other's written consent, except that PipeLedger may assign it without consent in connection with a merger, reorganization, sale of substantially all relevant assets, or transfer to an affiliate. Any prohibited assignment is void.

18.2 Force majeure

Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disasters, labor disputes, utility or internet failures, government actions, war, terrorism, or failures of unaffiliated platforms. This provision does not excuse Customer's payment obligations for Service already provided.

18.3 Notices

Notices concerning breach, indemnity, or termination must be in writing and sent to the notice contact in the applicable Order Form or, for self-serve subscriptions, to the organization's Owner email on file. Legal notices to PipeLedger must be sent by email to support@pipeledger.ai. Routine product notices may be delivered electronically through the Service or to an account email.

18.4 Updates to these Terms

PipeLedger may update these Terms prospectively. For a material change, PipeLedger will provide reasonable advance notice by email, in-product notice, or another reasonable method. An update will not retroactively alter an executed Order Form or claim that accrued before the update.

Where the Agreement permits an update without renewed assent, continued use after the effective date constitutes acceptance to the extent permitted by law. PipeLedger may require renewed affirmative acceptance for specified updates. If Customer does not agree, its remedy is to stop using and cancel the Service before the update takes effect, subject to existing payment commitments and any executed Enterprise document.

18.5 Relationship and construction

The parties are independent contractors. The Agreement does not create a partnership, joint venture, fiduciary, employment, agency, professional-client, or adviser relationship. No third party is a beneficiary.

Failure to enforce a provision is not a waiver. If a provision is unenforceable, it will be enforced to the maximum lawful extent and the remainder will continue. Headings are for convenience. The Agreement is the entire agreement on its subject and supersedes prior or contemporaneous proposals and communications. An amendment to an executed Order Form or addendum must be in a writing accepted by authorized representatives of both parties.


Schedule 1: Standard Data Processing Terms

These Standard Data Processing Terms ("Data Processing Terms") apply automatically where PipeLedger processes Personal Data on behalf of Customer in providing the Service. They form part of the Agreement and require no separate signature.

1. Definitions and roles

"Applicable Data Protection Law" means privacy, data-protection, and data-security law applicable to PipeLedger's processing of Customer Personal Data under the Agreement.

"Customer Personal Data" means Personal Data contained in Customer Data that PipeLedger processes on Customer's behalf.

"Personal Data" includes "personal information," "personal data," and analogous terms under Applicable Data Protection Law.

"Security Incident" means unauthorized access to or acquisition, use, destruction, modification, or disclosure of Customer Personal Data in PipeLedger's possession or control, excluding unsuccessful attempts that do not compromise Customer Personal Data.

Customer acts as the business or controller and PipeLedger acts as the service provider, contractor, or processor for Customer Personal Data, except where Applicable Data Protection Law assigns a different role for a specific processing activity. Each party is responsible for its own legal obligations.

2. Processing details and instructions

Item Description
Subject matter Providing, securing, supporting, and administering the PipeLedger Service
Duration The Agreement term plus the return, deletion, backup, dispute, and legal-retention periods described in the Agreement
Nature and purpose Acquiring authorized ERP data; hosting; organizing; normalizing; transforming; enriching; validating; governing; publishing; querying; delivering; securing; supporting; metering; and deleting Customer Data according to the Agreement and Customer's documented instructions
Categories of Personal Data Business identity and contact data; user and authentication data; employee, customer, vendor, project, transaction, ledger, sub-ledger, budget, dimension, account, and payment-related business records; governance and configuration data; and other Personal Data selected by Customer
Categories of individuals Customer personnel and users; employees and contractors; customers and prospects; vendors and payees; project participants; business contacts; and other individuals represented in Customer Data
Sensitive data May include account credentials, financial-account information, compensation data, or other sensitive information selected by Customer; Customer must not provide regulated data outside the documented Service scope without written agreement
Frequency Continuous or as initiated or configured by Customer during the Subscription Term

Customer instructs PipeLedger to process Customer Personal Data to provide, secure, support, and administer the Service; comply with the Agreement; perform documented configurations and requests; prevent or investigate security incidents, fraud, or unlawful activity; and comply with law.

PipeLedger will process Customer Personal Data only on Customer's documented instructions unless law requires otherwise. If legally permitted, PipeLedger will inform Customer of the legal requirement before processing. PipeLedger will promptly inform Customer if, in its opinion, an instruction violates Applicable Data Protection Law, but PipeLedger does not provide legal advice and may suspend the affected processing.

3. CCPA service-provider and contractor restrictions

For Customer Personal Data subject to the California Consumer Privacy Act ("CCPA"), PipeLedger will:

  1. not sell or share Customer Personal Data;
  2. process Customer Personal Data only for the limited and specific business purposes described in Section 2 of this Schedule and the Agreement;
  3. not retain, use, or disclose Customer Personal Data for a purpose other than those business purposes or as otherwise permitted by the CCPA and its regulations;
  4. not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer, except as permitted by the CCPA and its regulations;
  5. not combine Customer Personal Data with Personal Data received from another person or collected from PipeLedger's own interaction with an individual, except as permitted by the CCPA and its regulations;
  6. comply with applicable CCPA obligations and provide the same level of privacy protection required of businesses for Customer Personal Data;
  7. notify Customer if PipeLedger determines it can no longer meet its CCPA obligations;
  8. grant Customer the right, upon reasonable notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data;
  9. provide information reasonably necessary for Customer to monitor compliance, subject to confidentiality, security, privilege, and protection of other customers;
  10. assist Customer with applicable consumer requests as described below; and
  11. require subprocessors processing Customer Personal Data to accept materially equivalent data-protection obligations appropriate to their services.

Customer may take reasonable and appropriate steps to verify that PipeLedger processes Customer Personal Data consistently with Customer's CCPA obligations. The parties will first use available compliance documentation, certifications, reports, and written responses. Any additional audit must be reasonably scoped, coordinated in advance, avoid disruption and access to other customers' data, and be subject to confidentiality and security requirements. Customer bears its audit costs unless the audit identifies a material breach by PipeLedger.

4. Confidentiality and personnel

PipeLedger will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive appropriate privacy and security instruction for their roles.

5. Security

PipeLedger will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Personal Data and processing risks. These may include access controls, encryption in transit and at rest for supported systems, credential protection, logging, monitoring, vulnerability management, backup, incident response, and tenant-scoped authorization.

Customer is responsible for using available security features, configuring roles and governance settings, protecting credentials, and determining whether the Service is appropriate for the Customer Personal Data it chooses to process.

An executed Security Addendum may specify additional or different commitments for an Enterprise subscription.

6. Subprocessors

Customer generally authorizes PipeLedger to use subprocessors to provide the Service. PipeLedger will maintain a current subprocessor list on the Trust & Security page and will require subprocessors that process Customer Personal Data to enter into written terms providing data-protection obligations appropriate to their services.

PipeLedger will provide notice of a new subprocessor by email to the organization's Owner and administrator contacts at least thirty (30) days before the subprocessor begins materially processing Customer Personal Data where reasonably practicable.

If Customer reasonably objects on data-protection grounds, the parties will work in good faith toward a commercially reasonable solution. If no solution is available, PipeLedger may discontinue the affected feature or Customer may terminate only the affected Service, subject to the refund treatment stated in an executed Enterprise addendum. Self-service Customer preferences do not require PipeLedger to redesign the generally available Service.

7. Individual rights requests

Taking into account the nature of processing, PipeLedger will provide reasonable assistance through available technical and organizational measures for Customer to respond to requests to access, correct, delete, obtain, or restrict Customer Personal Data and to exercise other applicable privacy rights.

If PipeLedger receives a request directly concerning Customer Personal Data, PipeLedger will, unless prohibited by law, direct the requester to Customer or notify Customer and act on Customer's documented instructions. Customer is responsible for determining the appropriate response.

8. Compliance assistance

Taking into account the nature of processing and information available to PipeLedger, PipeLedger will provide reasonable assistance for Customer's applicable data-protection impact assessments, CCPA risk assessments, cybersecurity audits, regulator consultations, and compliance inquiries concerning PipeLedger's processing of Customer Personal Data.

Assistance beyond generally available documentation or ordinary support may be subject to reasonable fees, unless required due to PipeLedger's breach. PipeLedger will not disclose information that would compromise security, privilege, trade secrets, or another customer's confidentiality.

9. Security Incidents

PipeLedger will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data, by email to the organization's Owner and administrator contacts, and will provide information reasonably available to support Customer's legal obligations. Notification is not an admission of fault or liability.

PipeLedger will take reasonable steps to contain, investigate, mitigate, and remediate a confirmed Security Incident. Customer is responsible for notifications to individuals, regulators, and other third parties unless law assigns that obligation directly to PipeLedger.

10. Return, deletion, and retention

During the Subscription Term and applicable post-termination export period, Customer may retrieve Customer Data through generally available export features. Following termination or Customer's valid instruction, PipeLedger will delete or return Customer Personal Data in accordance with Section 12.4 of the Terms, unless law requires retention.

Deletion from active systems may precede deletion from encrypted backups. Personal Data retained for legal, security, fraud-prevention, billing, dispute, or backup purposes will remain protected and restricted from unrelated use until deletion or anonymization.

11. Data location

PipeLedger stores and processes Customer Personal Data in the United States, in the primary regions described on the Trust & Security page, and does not offer data services outside the United States. Limited operational information, such as network traffic transiting a subprocessor's global edge infrastructure, may be handled outside the United States by that subprocessor. If Applicable Data Protection Law ever requires a transfer mechanism, the parties will use the applicable standard contractual clauses or another lawful mechanism.

12. Government requests

Unless prohibited by law, PipeLedger will notify Customer of a legally binding request for Customer Personal Data and provide reasonable information. PipeLedger may disclose Customer Personal Data where legally required and may challenge a request where it reasonably determines there are grounds to do so.

13. Term and precedence

These Data Processing Terms remain effective while PipeLedger processes Customer Personal Data. A negotiated Data Processing Addendum executed by authorized representatives supersedes this Schedule only for the subject matter and term it expressly covers. The liability provisions of the Terms apply to this Schedule unless an executed addendum expressly provides otherwise.