Data Processing Addendum
How we process personal data from your Stripe and Google accounts on your behalf.
Version 1.0 · Last updated 6 October 2026
1. Roles
For customer data read from a founder’s connected accounts, the founder is the controller and ThreeCommas is the processor. For account data, ThreeCommas is the controller under the Privacy Policy. This addendum forms part of the Terms and applies where UK GDPR, EU GDPR or similar laws apply.
2. Processing on instructions
We process customer data only to calculate verified metrics, attribute revenue to partners under signed agreements and produce statements, and as otherwise instructed in writing, unless the law requires otherwise.
3. Security measures
- Read-only access to Stripe enforced by restricted keys and a GET-only client; OAuth scopes limited to read-only Google APIs.
- AES-256-GCM encryption of credentials with versioned keys and rotation; TLS in transit; encrypted storage at rest by our providers.
- Pseudonymisation: customer emails stored only as one-way hashes and domains; no names or addresses.
- Role-based access, admin actions audited, least privilege for staff, multi-factor authentication for admins.
- Backups with point-in-time recovery; incident response procedures.
4. Subprocessors
Neon (database, EU/US), Vercel (hosting and private file storage), Clerk (authentication), Resend (email), Stripe (payments). We give 30 days’ notice of new subprocessors by email; you may object, and if we cannot address the objection you may terminate.
5. Breach notice
We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations.
6. Assistance and audits
We help you respond to data-subject requests and with impact assessments, and make available information needed to show compliance, including a security questionnaire on request.
7. Deletion
On disconnect we delete credentials immediately. On account closure we delete customer data within 30 days, except where financial records must be kept by law, which are then kept only for that purpose.
8. Transfers
Transfers outside the UK or EEA use the UK International Data Transfer Addendum or the EU Standard Contractual Clauses (module 2 or 3 as applicable).