Legal
Data Processing Agreement
Last updated: July 13, 2026 — draft pending attorney review, not yet counter-signed.
This Data Processing Agreement ("DPA") governs Exemption Ledger's processing of Customer Data — exemption certificates, buyer records, and related documents Customer uploads to the Service — as described in the Terms of Service. It does not govern the separate personal data covered by the Privacy Policy (accounts, website visitors).
1. Roles
To the extent the California Consumer Privacy Act (CCPA) applies, the parties acknowledge that Exemption Ledger acts as a Service Provider receiving Personal Data to provide the Service. Exemption Ledger will not sell or share Personal Data, nor retain, use, or disclose it for any purpose other than providing the Service.
2. Subprocessors
Exemption Ledger uses the subprocessors listed on the Subprocessors page to provide the Service. That page is the authoritative, current list; Customer will be notified of material additions before they take effect.
3. AI Processing (Anthropic)
Exemption Ledger utilizes Anthropic, Inc. (via its commercial API) as a subprocessor exclusively for automated text extraction from uploaded certificates. Under our commercial agreement with Anthropic: Customer Data is not used to train Anthropic's foundation AI models; data is processed under the retention terms of Anthropic's commercial API; and processing is strictly limited to extracting structured fields required for the Service.
4. Data Residency
Exemption Ledger stores and processes all Customer Data exclusively within the United States.
5. Security
Exemption Ledger applies row-level, organization-scoped access control to all Customer Data and encrypts stored credentials for connected accounting/ERP systems. See our Subprocessors page for the systems involved in storage and processing.
6. Breach Notification
In the event of a confirmed security incident involving Customer Data, Exemption Ledger will notify Customer without undue delay, and in no event later than forty-eight (48) hours after discovery, with reasonable details regarding the nature of the incident, the data affected, and remediation steps.
This page is a working draft based on the Common Paper Standard Data Processing Agreement and has not yet been reviewed by counsel or counter-signed by any customer. Enterprise customers requiring a mutually-executed DPA should contact legal@exemptionledger.com.