Data Processing Agreement

Last updated 19 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Abbika LLC ("Cribble", the processor) and the customer (the controller, or — where the customer is a bookkeeping or accounting practice acting for its clients — another processor). It applies whenever Cribble processes personal data contained in the customer's documents on the customer's behalf.

1. Scope of processing

  • Subject matter: receiving, storing, classifying, and extracting structured data from financial documents submitted by the customer, and delivering results to the customer and its connected integrations.
  • Duration: the term of the customer's subscription, plus the retention and deletion periods in the Data Retention Policy.
  • Categories of data: names, contact details, bank account and payment details, and transaction data of the customer's suppliers, customers, and employees, as contained in submitted documents.
  • Data subjects: the customer's suppliers, customers, employees, and other persons appearing in submitted documents.

2. Instructions

Cribble processes personal data only on the customer's documented instructions — which are given by using the service (submitting documents, configuring retention, connecting integrations, requesting deletion or export) — unless processing is required by law, in which case Cribble will inform the customer unless the law prohibits it. Cribble will also inform the customer if, in its opinion, an instruction infringes applicable data protection law.

3. Confidentiality and security

Persons authorized to process the data are bound by confidentiality obligations. Cribble implements appropriate technical and organizational measures, including: encryption in transit and at rest, application-layer AES-256-GCM encryption of integration credentials, per-workspace data isolation, role-based access control with server-side authorization checks on every action, and Zero Data Retention on AI model calls via Cloudflare's AI Gateway.

4. Subprocessors

The customer gives general written authorization for the subprocessors listed on Cribble's Subprocessors page. Cribble will update that page at least 30 days before adding or replacing a subprocessor; the customer may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve the objection, and the customer may terminate the affected service if it cannot be resolved. Cribble imposes data protection obligations on each subprocessor equivalent to those in this DPA and remains liable for their performance.

5. Data subject requests

Taking into account the nature of the processing, Cribble assists the customer with data subject requests through the service's built-in tools (review, correction, deletion, and export of document data). If a data subject contacts Cribble directly about data processed on a customer's behalf, Cribble will direct them to the customer and will not respond on the customer's behalf except on the customer's instruction or where legally required. Cribble will also provide reasonable assistance with the customer's data protection impact assessments and prior consultations with supervisory authorities, insofar as they relate to processing under this DPA and the necessary information is available to Cribble.

6. Personal data breach

Cribble will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, and will provide the information reasonably needed for the customer to meet its own notification obligations.

7. Deletion and return

On termination of the subscription, or earlier on the customer's instruction, Cribble deletes the customer's personal data in accordance with the Data Retention Policy (workspace deletion with a 7-day grace window; automatic deletion 90 days after a subscription ends). Before deletion, the customer can obtain its data through the service or by request to privacy@cribble.co. Cribble may retain data only where and as long as the law requires.

8. Audits

Cribble makes available the information reasonably necessary to demonstrate compliance with this DPA, and allows for audits — normally satisfied by Cribble's documentation, subprocessor list, and security descriptions — conducted no more than once per year on reasonable notice, at the customer's expense, and without access to other customers' data.

9. International transfers

Where the processing involves a transfer of personal data protected by EU, UK, or Swiss data protection law to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two: controller to processor, or Module Three: processor to processor, as applicable), and the UK International Data Transfer Addendum, into this DPA by reference, with Cribble as data importer and the customer as data exporter. For data protected by Swiss data protection law, the Standard Contractual Clauses apply with the adaptations required by Swiss law. Transfers to subprocessors are safeguarded by equivalent clauses in Cribble's agreements with them.

10. Precedence and contact

If this DPA conflicts with the Terms of Service, this DPA prevails for data protection matters. Questions and signed copies: privacy@cribble.co.