This Data Processing Addendum ("DPA") supplements the Sefro Terms of Service between the customer ("Controller") and Call The IT Dude LLC d/b/a Sefro ("Processor").
For personal data that Controller submits to the Service (for example, buyer name, email, and EIN on exemption certificates, and addresses in calculation requests), Controller is the controller and Sefro is the processor. Sefro processes such data only on Controller's documented instructions, which include use of the Service as described in the documentation.
Controller authorizes the subprocessors listed below and in the Privacy Policy. Sefro will give notice of new subprocessors and allow a reasonable objection period.
| Subprocessor | Purpose | Location |
|---|---|---|
| Railway | Application hosting and managed PostgreSQL | United States |
| Stripe | Payment processing | United States |
| Cloudflare | DNS, WAF and edge network | Global (US-operated) |
Personnel authorized to process personal data are bound by confidentiality.
Sefro maintains technical and organizational measures appropriate to the risk, including: API keys stored only as hashes, TLS in transit, restricted production access, payment data isolated to Stripe, audit logging of administrative actions, and dependency vulnerability scanning in continuous integration. See our Security & Trust page.
Sefro will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller's data, and will cooperate in good faith on investigation and notification.
Taking into account the nature of processing, Sefro will assist Controller in responding to data-subject requests and in meeting its security and breach obligations.
On termination, or on Controller's request, Sefro will delete or return personal data, subject to retention required by law. Routine retention windows are described in the Privacy Policy.
Sefro will make available information reasonably necessary to demonstrate compliance with this DPA, including third-party reports where available (e.g., a future SOC 2 report).
Where applicable, the parties will rely on a lawful transfer mechanism (e.g., Standard Contractual Clauses) for transfers of personal data out of the EEA/UK.
← Back to Sefro