Data Processing Agreement
Last Updated: September 29, 2026
This Data Processing Agreement ("DPA") governs the processing of organizational financial records, employee and contractor information, and user metadata in connection with Money OS.
1. Processing Roles
Under GDPR, CCPA, and associated privacy standards, the roles of the parties are defined as follows:
- The Customer (You): Acts as the Data Controller, maintaining ownership and governance over your transactions, client details, project rates, and billing logs.
- Money OS: Acts as the Data Processor, maintaining database clusters, cryptographic safeguards, and executing operations strictly on behalf of the Controller.
2. Technical Security & Logical Isolation
Money OS enforces rigorous security configurations within the platform architecture:
- Multi-Tenant Database Partitioning: All queries scope strictly by a verified
tenantId, preventing data leakage across customer organizations. - Credential Vault Encryption: Tenant payment secrets (such as Razorpay API keys) are encrypted at rest using AES-256-GCM with a dedicated master key.
- Audit Trail: Key financial actions, user invitations, and permission updates generate immutable logs.
3. Authorized Subprocessors
To provide the financial platform and agency operating system, we utilize trusted infrastructure subprocessors:
- MongoDB Atlas: Cloud database infrastructure for multi-tenant transactional and growth ledgers.
- Clerk: Identity infrastructure, user authentication, and organization membership directories.
- Razorpay: Payment gateway infrastructure for invoice payment links and webhook processing.
- Supabase / AWS / Cloudflare: Secure object storage for agency logos, avatars, and invoice attachments.
- PostHog: Privacy-compliant telemetry for error tracking and platform performance.
- Vercel / Cloud Infrastructure: Edge application delivery and serverless runtime execution.
4. Tenant Deletion Request
Upon request from a verified workspace administrator, we will purge all database entries associated with your tenantId, including transactions, bank accounts, projects, clients, and team memberships. Contact us at support@moneyos.tech.