Paprel
  • Pricing
LoginGet API keys

Start Here

Embedded Accounting OverviewLedger APIs, workflows, reports, and MCP.All CapabilitiesAccounting EngineEmbedded UI & White-Label

Accounting Core

Ledger & JournalsFinancial ReportingMulti-Entity BooksPermissions & Audit

Workflows

Invoicing & ReceivablesExpenses & PayablesBanking & ReconciliationPayment Workflows

Built For

Vertical SaaSFintech PlatformsB2B MarketplacesAI Agents & MCP

Build

Developer DocumentationAPI reference, MCP, guides, and architectureAPI ReferenceIntegrationsEmbedded UI

Learn

BlogNewLedger Case Study2026 Accounting LandscapeImplementation Guides

Evaluate & Trust

Compare PaprelBuild vs BuyEvaluation ChecklistSecurity & TrustVulnerability Disclosure
Paprel
  • Start Here

    Embedded Accounting OverviewAll CapabilitiesAccounting EngineEmbedded UI & White-Label

    Accounting Core

    Ledger & JournalsFinancial ReportingMulti-Entity BooksPermissions & Audit

    Workflows

    Invoicing & ReceivablesExpenses & PayablesBanking & ReconciliationPayment Workflows

    Built For

    Vertical SaaSFintech PlatformsB2B MarketplacesAI Agents & MCP
  • Build

    Developer DocumentationAPI ReferenceIntegrationsEmbedded UI

    Learn

    BlogNewLedger Case Study2026 Accounting LandscapeImplementation Guides

    Evaluate & Trust

    Compare PaprelBuild vs BuyEvaluation ChecklistSecurity & TrustVulnerability Disclosure
  • Pricing
Get API keysLogin

Paprel · Legal

Data Processing Addendum

Processing terms for personal data entrusted to Paprel by business customers.

Last updated: 9 September 2026

TermsPrivacySecurityLicenseData processingProviders

1. Application and roles

This Addendum forms part of the Terms of Service for personal data processed by Paprel on behalf of the Customer (Customer Personal Data). The Customer acts as controller/organisation or as an authorised processor/intermediary for another organisation; Paprel acts as processor/intermediary or subprocessor accordingly. The Customer must have authority for its instructions and any onward appointment. Paprel’s own account, billing and website processing is described separately in the Privacy Policy.

This Addendum controls conflicting processing provisions. Liability follows the applicable limit, exclusions and exceptions in section 9 of the Terms, including any express variation in a signed agreement or order; nothing restricts mandatory duties or independent statutory rights.

2. Processing description

The subject matter is provision of hosted accounting, embedded interfaces, API and connected-client services for the contracted term and the agreed return/deletion period. Processing includes collection, hosting, organisation, retrieval, calculations/reporting, transmission to authorised recipients, support, security, export and deletion as instructed through the Service and agreement.

Data subjects may include Customer users, employees, contractors, customers, suppliers and their contacts. Data may include identifying/contact details, accounting transactions, invoices, receipts, bank transaction details, attachments, authorisation metadata and relevant activity records. The Customer determines the records it supplies. Do not submit unnecessary sensitive data; processing requiring additional safeguards or a materially different scope must be agreed before submission.

3. Instructions and confidentiality

Paprel will process Customer Personal Data only on documented lawful instructions, including the agreement, authorised product settings and requests, unless law requires otherwise. Where lawful, Paprel will notify the Customer of a compulsory requirement before processing. Paprel will inform the Customer if it considers an instruction infringes applicable data-protection law and may suspend that instruction pending resolution.

Personnel authorised to process this data must be bound by confidentiality and have access appropriate to their responsibilities. Paprel will not independently repurpose Customer Personal Data for advertising or training general-purpose AI models. Customer-authorised third-party AI clients remain responsible for their own subsequent processing; this restriction does not represent their practices.

4. Security and deployment responsibilities

Paprel will implement technical and organisational measures appropriate to the processing risks and applicable law, addressing confidentiality, integrity, availability and resilience; controlled access and credential handling; protection of transfers and storage; recovery; and regular evaluation of measures. These are obligations, not a statement that a particular certification has been obtained.

Before production processing, the parties must identify the applicable deployment, locations, authorised subprocessors and a documented security-measures schedule covering encryption/key handling, privileged access, tenant boundaries, logs, backup/recovery and incident procedures. A public architecture description does not replace that schedule. Customer-managed components, identity/permission configuration, endpoint security and integration choices remain the Customer’s responsibility as identified in the deployment scope.

5. Subprocessors and transfers

The Customer generally authorises subprocessors identified in the applicable service schedule supplied before processing. Paprel will bind each subprocessor to data-protection obligations no less protective than those applicable to its processing under this Addendum, including sufficient guarantees for appropriate technical and organisational measures. Paprel remains responsible to the Customer for the performance of its subprocessors’ data-protection obligations, including where a subprocessor fails to fulfil them, subject to applicable law and the agreement’s lawful liability provisions. The Provider Information page distinguishes website providers from the service schedule; it is not blanket authorisation of an unspecified provider.

For a planned new or replacement subprocessor, Paprel will give 30 days’ prior notice and allow reasonable objections on data-protection grounds. The parties will seek a reasonable solution; if none resolves the objection, the Customer may terminate the affected service. Any refund or service credit follows section 6 of the Terms or the applicable signed agreement, without limiting mandatory rights. Urgent replacement requires prompt notice and must still satisfy applicable authorisation and safeguard requirements.

International transfers must satisfy applicable law, including comparable protection under Singapore PDPA. Where GDPR transfer rules apply, the parties will put in place the relevant adequacy or safeguard arrangement before the transfer, including appropriate SCC modules, completed annexes and supplementary measures where required. A reference to SCCs here does not execute them; the required instruments and processing locations must be documented for the relevant transfer.

6. Assistance, incidents and audits

Taking account of the processing, Paprel will reasonably assist the Customer with data-subject rights, security, breach obligations, impact assessments and regulator consultation where applicable. Paprel will forward relevant direct requests and will not respond on the Customer’s behalf except as instructed or required by law. Reasonable cost/procedure arrangements must not defeat mandatory assistance duties.

Paprel will notify the Customer without undue delay when it has credible grounds to believe a breach of Customer Personal Data has occurred, provide available information and continuing updates, and cooperate with containment and investigation. It will not await a completed investigation. The Customer manages its own regulatory and individual notifications; Paprel retains any independent duties imposed on it. There is no universal 72-hour discovery deadline replacing those duties.

Paprel will provide information needed to demonstrate compliance and permit proportionate audits or inspections by the Customer or a mandated independent auditor. Agree reasonable notice, confidentiality and security arrangements; routine evidence review may precede inspection, without excluding legally required audits or urgent/regulatory access.

7. Return and deletion

At the Customer’s choice, Paprel will return or delete Customer Personal Data at the end of the processing services and delete remaining copies unless applicable law requires retention. The Terms of Service describe the distinction between subscription cancellation, company deletion and the standard automated cleanup schedule. That schedule does not postpone a return or deletion obligation under this DPA or applicable law. Subscription cancellation alone is not a deletion instruction and does not authorise indefinite retention.

Send authorised instructions to dpo@paprel.com so the scope, applicable requirements and arrangements for completion can be established. Any agreed completion schedule must comply with applicable law. Copies awaiting backup expiry remain protected and subject to applicable deletion requirements; restored data must remain subject to outstanding deletions.

Legally required retention must be limited to its purpose and protected accordingly. DPA obligations continue for retained Customer Personal Data. A separate retained-service arrangement requires lawful documented instructions and cannot override mandatory deletion duties.

Nexara Global Pte. Ltd. · UEN 202516221H
68 Circular Road, #02-01, Singapore 049422
legal@paprel.com · dpo@paprel.com
Paprel

Embedded accounting for SaaS, fintech, and platform teams.

Ledger-backed workflows, reporting, and controls for teams embedding finance into their product.

Follow Paprel on TwitterConnect with Paprel on LinkedIn

Embedded Accounting

  • Overview
  • All Capabilities
  • Accounting Engine
  • Embedded UI & White-Label
  • AI Agents & MCP
  • Pricing

Use Cases

  • Vertical SaaS
  • Fintech
  • Marketplaces
  • Lending
  • E-commerce
  • Property Management

Developers

  • API Documentation
  • Guides & Docs
  • Architecture
  • General Ledger API
  • Journal API
  • Integrations
  • Changelog

Evaluate

  • Compare
  • Build vs Buy
  • Evaluation Checklist
  • NewLedger Case Study
  • 2026 Landscape
  • Design Partners

Company

  • Blog
  • About Us
  • Careers
  • FAQs
  • Contact
  • Security & Trust

Copyright©2026 Paprel. All rights reserved.

LicenseTerms of ServicePrivacy PolicyData ProcessingProvidersEmbedded accounting · AI-native