Data Processing Addendum
Effective: August 29, 2026
This Data Processing Addendum ("DPA") describes how Empire Innovations, LLC, an Idaho limited liability company("Empire," "we," "us"), processes Customer Data on behalf of a customer ("Customer," "you") in connection with TenkeyBridge. It applies automatically to every Customer, and its terms are incorporated into our Terms of Service by reference; the defined terms used here have the meaning given to them there.
1. Roles
For personal data contained in Customer Data, Customer is the controller and Empire is the processor. Customer determines the purposes and means of processing that personal data — what QuickBooks entities it stores, which of its own users and end-customers appear in it, and how long it keeps it in its own systems. Empire processes it only to provide the Service, as described in this DPA, and does not determine the purposes or means of that processing on its own.
2. Processing on documented instructions
Empire processes Customer Data only on Customer's documented instructions, which consist of the Terms, this DPA, and Customer's use of the Service's ordinary API functionality (the requests Customer's integration sends and the responses the Service returns). Empire does not process Customer Data for any other purpose, and does not use it to train any model. Empire will inform Customer if it believes an instruction violates applicable data protection law, and, if Customer insists on such an instruction, Empire may suspend performance of it.
3. Confidentiality
Empire limits access to Customer Data to personnel and subprocessors who need it to provide the Service, and ensures those personnel are subject to confidentiality obligations at least as protective as those in Section 8 of the Terms. Those obligations survive for as long as the personnel or subprocessor retains access to Customer Data.
4. Security measures
Empire maintains technical and organizational measures appropriate to the nature of Customer Data, including:
- encryption in transit via TLS for all traffic to and from the Service;
- company-file contents passing through the gateway only in transit, to serve the specific API request being made, and never stored at rest by the Service;
- credentials TenkeyBridge issues to Customer — API keys, OAuth client secrets, and access and refresh tokens — stored as one-way hashes, never in plaintext;
- least-privilege access to production systems and data;
- an outbound-only Windows agent running on Customer's own machine, which dials out to the Service and never accepts inbound connections; and
- request logs limited to metadata (method, path, status, latency, realm id, entity, and error code) — never request or response bodies — retained for 30 days.
5. Subprocessors
Empire uses the subprocessors listed at tenkeybridge.com/subprocessors to provide the Service, each bound by a written agreement imposing data protection obligations consistent with this DPA. Empire will update that page when it adds or replaces a subprocessor, and will provide notice as described there.
6. Assistance with data subject requests
Empire will provide reasonable assistance to Customer in responding to requests from individuals to exercise their rights under applicable data protection law — access, correction, deletion, or portability requests, for example — to the extent Customer cannot reasonably fulfill the request itself using the Service's ordinary functionality. If Empire receives such a request directly from an individual rather than from Customer, it will redirect the individual to Customer and will not respond to the request itself unless legally required to.
7. Deletion or return on termination
On termination of the Terms, Empire will delete or return account and organization data within 30 days after the account or organization is closed, or sooner if Customer asks, except where applicable law requires Empire to retain it (such as billing records, which are kept as required by applicable tax and accounting law). Because company-file contents are not stored at rest by the Service in the first place, this section primarily concerns account, organization, and service metadata.
8. Audits
On reasonable written request, no more than once per year, Empire will provide Customer with a written summary of the security measures described in Section 4, to help Customer verify Empire's compliance with this DPA. Empire is an early-stage company and does not currently hold a third-party security certification; this DPA describes the concrete measures Empire has in place rather than referring to one.
9. Incorporation & governing law
This DPA is incorporated into, and forms part of, the Terms. It is governed by the same law and venue as the Terms, set out in Section 16 of the Terms. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls.
Contact
For a signed DPA or SCCs, email legal@tenkeybridge.com. For any other question about this DPA, email legal@tenkeybridge.com or privacy@tenkeybridge.com.