Data Processing Addendum

Last updated: July 28, 2026
This is Sefro's standard DPA, available for review during enterprise procurement. To execute a signed copy, contact [email protected]. It supplements, and is governed by, the Terms of Service.

This Data Processing Addendum ("DPA") supplements the Sefro Terms of Service between the customer ("Controller") and Call The IT Dude LLC d/b/a Sefro ("Processor").

1. Roles

For personal data that Controller submits to the Service (for example, buyer name, email, and EIN on exemption certificates, and addresses in calculation requests), Controller is the controller and Sefro is the processor. Sefro processes such data only on Controller's documented instructions, which include use of the Service as described in the documentation.

2. Subprocessors

Controller authorizes the subprocessors listed below and in the Privacy Policy. Sefro will give notice of new subprocessors and allow a reasonable objection period.

SubprocessorPurposeLocation
RailwayApplication hosting and managed PostgreSQLUnited States
StripePayment processingUnited States
CloudflareDNS, WAF and edge networkGlobal (US-operated)

3. Confidentiality

Personnel authorized to process personal data are bound by confidentiality.

4. Security

Sefro maintains technical and organizational measures appropriate to the risk, including: API keys stored only as hashes, TLS in transit, restricted production access, payment data isolated to Stripe, audit logging of administrative actions, and dependency vulnerability scanning in continuous integration. See our Security & Trust page.

5. Personal data breach

Sefro will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller's data, and will cooperate in good faith on investigation and notification.

6. Assistance

Taking into account the nature of processing, Sefro will assist Controller in responding to data-subject requests and in meeting its security and breach obligations.

7. Return and deletion

On termination, or on Controller's request, Sefro will delete or return personal data, subject to retention required by law. Routine retention windows are described in the Privacy Policy.

8. Audit

Sefro will make available information reasonably necessary to demonstrate compliance with this DPA, including third-party reports where available (e.g., a future SOC 2 report).

9. International transfers

Where applicable, the parties will rely on a lawful transfer mechanism (e.g., Standard Contractual Clauses) for transfers of personal data out of the EEA/UK.

← Back to Sefro