Data Processing Agreement

Last updated on August 5, 2026

Effective Date: June 15, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service or other written agreement between Billable Hub (“Billable Hub,” “we,” “our,” or “us”) and the customer or organization using the Services (“Customer,” “you,” or “your”). This DPA is legally binding on the parties and is incorporated into the Agreement by reference.

This DPA applies when Billable Hub processes Customer Personal Data on behalf of Customer in connection with the Services, including AI-assisted features. Capitalized terms not defined in this DPA have the meanings given in the Terms of Service. “Agreement” means the Terms of Service, order form, master services agreement, or other written agreement governing Customer’s use of the Services.

1. Roles of the Parties

For Customer Personal Data, Customer is the controller, business, or equivalent party that determines the purposes and means of processing. Billable Hub is the processor, service provider, or equivalent party that processes Customer Personal Data on Customer’s behalf. Where Customer acts as a processor on behalf of another controller, Customer is a processor and Billable Hub is Customer’s subprocessor, and the corresponding obligations in this DPA apply accordingly.

Billable Hub may separately act as a controller for account administration, billing, security, support, website operations, legal compliance, fraud prevention, and service improvement data as described in our Privacy Policy.

2. Definitions

“Applicable Data Protection Laws” means privacy, data protection, and data security laws that apply to the processing of Customer Personal Data, including, where applicable, the GDPR, UK GDPR, Swiss data protection law, and applicable U.S. state privacy laws.

“Customer Personal Data” means personal data, personal information, or similar regulated information contained in Customer Data that Billable Hub processes on behalf of Customer through the Services.

“Data Subject” means an identified or identifiable person whose Customer Personal Data is processed through the Services.

“GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as incorporated into United Kingdom law, as amended. “CCPA” means the California Consumer Privacy Act of 2018, as amended, and its implementing regulations.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914, as amended or replaced.

“Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Billable Hub or a Subprocessor, excluding unsuccessful attempts that do not compromise the security, confidentiality, or integrity of Customer Personal Data.

“Subprocessor” means a third party engaged by Billable Hub to process Customer Personal Data on Billable Hub’s behalf to provide the Services.

3. Scope and Instructions

Customer instructs Billable Hub to process Customer Personal Data as needed to:

Customer’s documented instructions include the processing described in the Agreement, this DPA and Schedule 1, Customer’s configuration and use of the Services, and other written instructions mutually agreed by the parties. Billable Hub will process Customer Personal Data only on Customer’s documented instructions, including with respect to international transfers, unless Applicable Data Protection Laws require otherwise.

Billable Hub will not process Customer Personal Data for purposes outside these instructions unless required by law. If Billable Hub believes an instruction violates Applicable Data Protection Laws, we will inform Customer unless prohibited by law.

4. Customer Responsibilities

Customer is responsible for:

Customer must not submit to the Services full payment card numbers, card verification codes, Social Security numbers, government-issued identification numbers or documents, protected health information subject to HIPAA, or other information that Billable Hub expressly identifies as prohibited data. Customer acknowledges that the Services are not designed to process such information.

Customer will not submit sensitive personal information or other highly sensitive personal data to AI-assisted features unless expressly permitted by Billable Hub and Customer has determined that such processing is lawful and necessary and has provided all required notices and obtained all required consents or authorizations.

5. Confidentiality

Billable Hub will ensure that its employees, contractors, and other personnel who are authorized to access or process Customer Personal Data are subject to confidentiality obligations or are otherwise bound by appropriate duties of confidentiality and are permitted to access Customer Personal Data only to the extent reasonably necessary to perform their duties in connection with the Services.

Billable Hub will take reasonable steps to ensure that such personnel are informed of the confidential nature of Customer Personal Data and their obligations to protect it. Applicable confidentiality obligations will continue after the termination of such personnel’s employment or engagement to the extent required by applicable law or the terms of the applicable confidentiality obligation.

6. Security Measures

Billable Hub will maintain reasonable administrative, technical, and organizational measures designed to protect Customer Personal Data against unauthorized access, loss, misuse, alteration, and disclosure. Current measures are summarized in Schedule 2.

Customer acknowledges that no service can guarantee absolute security and that Customer is responsible for using the Services securely, including protecting credentials, limiting permissions, reviewing document recipients, and safeguarding exported files.

Billable Hub will not be responsible for unauthorized access to or disclosure of Customer Personal Data to the extent caused by Customer’s failure to protect credentials, properly configure permissions or access controls, safeguard exported data, or secure Customer-controlled devices, systems, or integrations, except to the extent caused by Billable Hub’s breach of this DPA or Applicable Data Protection Laws.

7. Subprocessors

Customer authorizes Billable Hub to use Subprocessors to provide the Services, including Customer Personal Data on Customer’s behalf. Current Subprocessors are listed in Schedule 3.

Billable Hub will require Subprocessors to process Customer Personal Data only as needed to provide their services to Billable Hub and to protect Customer Personal Data using appropriate contractual and security obligations.

Billable Hub may update its Subprocessors from time to time. Customer may object to a new Subprocessor by contacting support@billablehub.com within 30 days after the update if Customer has a reasonable data protection concern. Billable Hub will work in good faith to address the concern. If the concern cannot reasonably be resolved, Customer’s sole remedy is to stop using the affected part of the Services or terminate the Services as allowed by the Terms.

8. International Transfers

Customer Personal Data may be processed in the United States and other countries where Billable Hub, its infrastructure providers, or Subprocessors operate. Customer acknowledges that Customer Personal Data may be transferred to and processed in countries other than the country in which Customer or the applicable Data Subject is located.

Where Applicable Data Protection Laws require a transfer mechanism for Customer Personal Data, Billable Hub will implement an appropriate transfer mechanism as required by such laws, which may include applicable Standard Contractual Clauses, the UK International Data Transfer Addendum or other applicable UK transfer mechanism, an adequacy decision, or another legally recognized transfer mechanism.

9. Data Subject Requests

If Billable Hub receives a request from a Data Subject relating to Customer Personal Data for which Customer is responsible, Billable Hub will, where reasonably practicable and legally permitted, direct the requester to Customer or notify Customer of the request. Billable Hub will not independently respond to the substance of such request except as instructed by Customer or as required by Applicable Data Protection Laws.

Billable Hub will provide reasonable assistance to Customer in responding to Data Subject requests, taking into account the nature of the Services and information available to Billable Hub. Customer is responsible for verifying the identity and authority of the requester, determining whether and how to respond to the request, and complying with any applicable response deadlines, except to the extent Applicable Data Protection Laws expressly impose such obligations on Billable Hub. The Services may include self-service tools for account deletion, organization data export, client-facing access, and deletion workflows.

To the extent Customer can fulfill a Data Subject request using functionality available through the Services, Customer will use such functionality before requesting additional assistance from Billable Hub. Billable Hub may charge reasonable fees for assistance that requires material effort beyond the functionality ordinarily provided as part of the Services, to the extent permitted by Applicable Data Protection Laws.

10. Security Incidents

Billable Hub will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. The notice will include information reasonably available to Billable Hub, such as the nature of the incident, affected data categories, likely consequences, mitigation steps, and contact information for follow-up. Where complete information is not reasonably available at the time of the initial notice, Billable Hub may provide information in phases as additional information becomes available.

Billable Hub will take reasonable steps to investigate, contain, mitigate, and remediate a Security Incident within its systems and will reasonably cooperate with Customer in connection with Customer’s response to the Security Incident. Notification of or response to a Security Incident will not be construed as an acknowledgment by Billable Hub of fault or liability.

Customer is responsible for determining whether a Security Incident requires notice to regulators, Data Subjects, customers, or others, unless Applicable Data Protection Laws require Billable Hub to provide a specific notice directly.

Unsuccessful security events, routine scans, blocked attacks, spam, phishing attempts, rate-limit events, and other events that do not result in unauthorized access to Customer Personal Data are not Security Incidents under this DPA. Billable Hub has no obligation to notify Customer of such events.

11. Return and Deletion

During the term, Customer may use available export features to retrieve Customer Data. Customer is responsible for exporting any Customer Data it wishes to retain before termination or deletion of its account or organization. After termination, account deletion, or organization deletion, Billable Hub will delete or anonymize Customer Personal Data within a commercially reasonable period in accordance with Billable Hub’s then-current data retention and deletion procedures, except to the extent retention is required or permitted by Applicable Data Protection Laws or this DPA.

Some information may be retained for a longer period where reasonably necessary for legal, tax, accounting, billing, security, fraud prevention, abuse reporting, audit log, dispute resolution, backup, or other lawful purposes. Any Customer Personal Data retained pursuant to this paragraph will remain subject to the applicable confidentiality and security obligations of this DPA and will not be processed for any other purpose except as permitted or required by law. Organization deletion may include a soft-deletion period before final cleanup so authorized users can export data and recover from accidental deletion. Customer Personal Data contained in backups, logs, archives, or other systems that are not reasonably capable of immediate deletion may be retained until deleted or overwritten in accordance with Billable Hub’s ordinary retention and backup cycles, provided that such data remains protected in accordance with this DPA and is not restored or otherwise processed except as necessary for security, disaster recovery, legal compliance, or other legitimate operational purposes.

12. Assistance and Compliance

Taking into account the nature of the processing and information available to Billable Hub, Billable Hub will provide reasonable assistance to Customer with:

Billable Hub may charge reasonable fees for assistance that is not available through standard self-service tools or ordinary support.

13. Audits

Billable Hub will make available information reasonably necessary to demonstrate compliance with this DPA, such as this DPA, the Privacy Policy, Subprocessor information, and security summaries.

If Applicable Data Protection Laws require additional audit rights, Customer may request an audit no more than once per year, on reasonable written notice, during normal business hours, and subject to reasonable confidentiality, security, and scope limits. Audits may not disrupt the Services or expose other customers’ data, trade secrets, confidential security information, or systems beyond what is required by law.

14. Government and Third-Party Requests

If Billable Hub receives a legally binding request for Customer Personal Data from a government, court, law enforcement agency, or similar authority, Billable Hub will notify Customer unless legally prohibited. Billable Hub may comply with legally valid requests and may challenge requests where appropriate.

15. U.S. State Privacy Laws

Where Customer Personal Data is subject to an Applicable Data Protection Law of a U.S. state, Billable Hub will process Customer Personal Data as a service provider, processor, contractor, or equivalent role to the extent applicable to Billable Hub’s processing of such Customer Personal Data on behalf of Customer. Billable Hub will not (a) sell Customer Personal Data or share Customer Personal Data for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws, (b) retain, use, or disclose Customer Personal Data outside the direct business relationship between Billable Hub and Customer or for any purpose other than the specific purposes described in this DPA or otherwise permitted by Applicable Data Protection Laws, or (c) combine Customer Personal Data received from or on behalf of Customer with personal data received from another person or collected from Billable Hub’s own interactions with a Data Subject, except as permitted by Applicable Data Protection Laws.** Billable Hub will process Customer Personal Data only for the limited and specified purposes described in this DPA and the Agreement and in accordance with Customer’s documented instructions. Billable Hub will provide the same level of privacy protection for Customer Personal Data as required of service providers, contractors, processors, or equivalent recipients under Applicable Data Protection Laws.

If Billable Hub determines that it can no longer meet its obligations under this Section 15, it will notify Customer as required by Applicable Data Protection Laws. Customer may take reasonable and appropriate steps to help ensure that Billable Hub processes Customer Personal Data in a manner consistent with Customer’s obligations under Applicable Data Protection Laws and, where required by such laws, to stop and remediate unauthorized processing of Customer Personal Data.

16. Order of Precedence

If there is a conflict between this DPA and the Terms, this DPA controls only for the processing of Customer Personal Data. The Terms control for all other matters. If Customer has a separately signed agreement with Billable Hub, that signed agreement controls to the extent it expressly conflicts with this DPA.

17. AI-Assisted Processing

Customer instructs Billable Hub to process Customer Personal Data through AI-assisted features when Customer or Customer’s users invoke, configure, or use those features. AI-assisted processing may include AI Input such as help questions, AI Context, time-entry notes, expense descriptions, invoice or estimate notes and footers, balance-update messages, dispute replies, estimate question replies, custom notification HTML, client/project/organization context, line items, document metadata, and other Customer Data relevant to the feature.

AI-assisted features may be routed through Vercel AI Gateway and selected third-party AI model providers identified as Subprocessors in accordance with Section 7. Billable Hub does not use Customer Personal Data to train its own general-purpose AI models or permit Customer Personal Data to be used to train third-party general-purpose AI models, except at Customer’s express direction.
Billable Hub will configure its AI providers and AI gateway services, where commercially and technically available, to limit the retention and secondary use of Customer Personal Data and will require AI providers processing Customer Personal Data on Billable Hub’s behalf to process such data only as necessary to provide the applicable AI-assisted features or as otherwise permitted under this DPA and Applicable Data Protection Laws.

Customer controls whether and how its users use AI-assisted features and is responsible for determining whether Customer Personal Data is appropriate to submit to such features. Customer and its users must not submit Prohibited Data to AI-assisted features and should avoid submitting sensitive or highly confidential information unless reasonably necessary for the intended use and permitted under this DPA.

AI Output may be inaccurate, incomplete, outdated, offensive, duplicative, non-unique, or unsuitable for Customer’s purpose. Customer remains responsible for human review and for determining whether AI Output is appropriate for Customer’s business, legal, tax, accounting, billing, compliance, or client communications needs. Customer should not rely on AI Output as a substitute for professional advice or human judgment and is responsible for reviewing AI Output before using, communicating, or acting upon it. Billable Hub does not warrant that AI Output will be accurate, complete, unique, or suitable for any particular purpose.

18. Contact

Privacy and data processing questions: support@billablehub.com
General support: support@billablehub.com
Mail: Billable Hub, Weatherford, TX

Schedule 1: Processing Details

Subject Matter

Billable Hub provides business software for time tracking, project and job tracking, client management, expenses, estimates, invoicing, recurring billing workflows, reporting, exports, organization permissions, secure document access, AI-assisted writing and review, help assistance, and related operations.

Duration

Billable Hub processes Customer Personal Data for the term of Customer’s use of the Services and for any additional period described in the Terms, Privacy Policy, product deletion workflows, backup cycles, legal retention requirements, or this DPA.

Nature and Purpose of Processing

The processing includes collection, recording, organization, structuring, storage, hosting, transmission, retrieval, viewing, use, disclosure to configured recipients, restriction, export, deletion, anonymization, AI Gateway routing, AI model inference, AI usage reporting, and related operations needed to provide and secure the Services.

Categories of Data Subjects

Customer Personal Data may relate to:

Categories of Customer Personal Data

Customer Personal Data may include:

Sensitive Data

The Services are not designed for processing special categories of personal data or highly sensitive information. Customer may choose to include sensitive information in free-text fields, notes, attachments, support messages, uploaded files, or AI prompts, and Customer is responsible for ensuring that this processing is lawful and appropriate.

Schedule 2: Technical and Organizational Measures

Billable Hub’s current safeguards may include:

Schedule 3: Subprocessors

Billable Hub currently uses the following Subprocessors and service providers to provide the Services:

Subprocessor or categoryPurposeCustomer Personal Data processedLocation/transfer basis
ClerkAuthentication, account identity, profile, session, email verification, MFA, passkeys, and social sign-in where enabledUser identity, email address, profile information, authentication identifiers, session metadata, profile image dataUnited States/global infrastructure; provider DPA and transfer mechanisms where applicable
VercelApplication hosting, serverless runtime, static site hosting, logging, Vercel Analytics, BotID/security services, Workflows, Vercel Blob file storage, AI Gateway routing, and AI usage reportingApplication data, files, attachments, logs, IP addresses, user agents, diagnostics, website analytics, AI Input and AI Output routed through Gateway, AI usage metricsUnited States/global infrastructure; provider DPA and transfer mechanisms where applicable
Vercel AI Gateway model providers, including OpenAI when configuredAI model inference for Smart Rewrite, Tone Monitor, Smart Review, Help Assistant, and related AI-assisted featuresPrompts, selected Customer Data, AI Context, AI Output, feature metadata, model/provider metadata, usage metadataProvider and location depend on the configured model and Gateway route; legal should confirm current production model providers and provider-specific terms
Neon or configured PostgreSQL providerPostgreSQL database hostingApplication database records, including Customer Data stored in the ServicesRegion depends on database configuration; provider DPA and transfer mechanisms where applicable
StripePayment processing, subscription billing, checkout, customer portal, invoicing-related billing metadata, refunds, fraud prevention, and payment-related complianceBilling contact data, customer identifiers, subscription metadata, transaction metadata, payment method metadata; full card numbers are handled by StripeUnited States/global infrastructure; provider DPA and transfer mechanisms where applicable; Stripe may also act as an independent controller for some payment activities
Amazon Web Services / SES SMTPTransactional email delivery and related email infrastructureEmail addresses, invoice and estimate email content, OTP and notification messages, support or system emails, delivery metadataUnited States/global infrastructure; provider DPA and transfer mechanisms where applicable
Slack / SalesforceInternal support, help, abuse-report, and operational notifications where usedSupport request metadata, help request content, abuse report metadata, operational alerts, limited account or organization context included in notificationsUnited States/global infrastructure; provider DPA and transfer mechanisms where applicable
Google or other social identity providers selected through ClerkOptional OAuth or social sign-inIdentity provider profile data, email, avatar, authentication metadataUser-selected third-party service; provider terms and privacy notices may apply

Billable Hub may add, replace, or remove Subprocessors as the Services evolve. Material updates will be reflected on this page or another public legal page.