Skip to content

Data Protection Addendum

Last updated: August 7, 2026

This Data Processing Addendum (“DPA”) forms part of and is incorporated by reference into the agreement between the parties governing Customer’s use of the Cartwheel platform and services (the “Agreement”), whether by online terms of service, an Order Form, or a separately negotiated agreement. It is entered into between the customer identified in the Agreement (“Customer”) and [Cartwheel legal entity name] (“Cartwheel”). Each is a “party” and together the “parties.”

This DPA governs Cartwheel’s Processing of Personal Data on Customer’s behalf in connection with the Services. If there is a conflict between this DPA and the rest of the Agreement on the subject of data protection, this DPA controls. Where the parties have signed a negotiated agreement, that agreement’s data-protection terms prevail over this DPA to the extent of any conflict.

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement.

“Applicable Data Protection Laws” means the data-protection and privacy laws applicable to the Processing of Personal Data under the Agreement in North America, including, as applicable: in the United States, the California Consumer Privacy Act as amended (“CCPA”) and comparable state privacy laws; in Canada, the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and comparable provincial laws, including Quebec’s Law 25; and in Mexico, the Federal Law on the Protection of Personal Data Held by Private Parties (“LFPDPPP”).

“Controller” means the party that determines the purposes and means of Processing — equivalent to a “Business” (CCPA), an “organization” (PIPEDA), or a “responsable” (LFPDPPP). “Processor” means the party that Processes Personal Data on the Controller’s behalf — equivalent to a “Service Provider” (CCPA) or an “encargado” (LFPDPPP).

“Personal Data” means information relating to an identified or identifiable individual that Cartwheel Processes on Customer’s behalf under the Agreement. “Processing” means any operation performed on Personal Data. “Data Subject” means the individual to whom Personal Data relates.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

“Services” means the Cartwheel accounts-receivable automation platform and related services provided under the Agreement.

“Sub-processor” means a third party engaged by Cartwheel to Process Personal Data in connection with the Services.

2. Roles and scope

2.1  As between the parties, Customer is the Controller of the Personal Data (or, where Customer is itself a Processor for its own clients, the Processor), and Cartwheel acts as Processor on Customer’s behalf.

2.2  This DPA applies only to Cartwheel’s Processing of Personal Data as a Processor. It does not apply to data for which Cartwheel is an independent Controller (such as Cartwheel’s own account and business records), which is governed by the Cartwheel Privacy Policy.

2.3  The nature, purpose, and duration of the Processing, and the categories of Data Subjects and Personal Data, are described in the Annex.

3. Cartwheel’s obligations

3.1 Instructions. Cartwheel will Process Personal Data only to provide, secure, and support the Services and on Customer’s documented instructions, which include this DPA, the Agreement, and Customer’s use and configuration of the Services. Cartwheel will not Process Personal Data for its own purposes.

3.2 No sale; service-provider commitment. Cartwheel will not sell or share Personal Data, and will not retain, use, or disclose it for any purpose other than providing the Services or as permitted by Applicable Data Protection Laws. Cartwheel acts as a “Service Provider” under the CCPA and an equivalent Processor under other Applicable Data Protection Laws.

3.3 No AI or model training. Cartwheel does not use Personal Data to train, fine-tune, or develop artificial-intelligence or machine-learning models, and does not disclose Personal Data to any third-party AI or large-language-model service.

3.4 Confidentiality. Cartwheel ensures that personnel authorized to Process Personal Data are bound by confidentiality obligations and access Personal Data only as needed to perform the Services.

3.5 Customer responsibility. Customer is responsible for the accuracy and legality of the Personal Data it provides and for having the legal basis to provide it and to authorize the Processing described here, including giving any required notices to and obtaining any required consents from Data Subjects.

4. Security

Cartwheel maintains a written information-security program with administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, loss, or disclosure. The program is aligned with the SOC 2 and ISO/IEC 27001 security frameworks. Current security information is available on Cartwheel’s Trust Center at trust.cartwheel.io. A summary of measures is set out in the Annex. Security measures may evolve, provided Cartwheel does not materially reduce the overall level of protection during the term.

5. Sub-processors

5.1  Customer authorizes Cartwheel to engage Sub-processors to Process Personal Data in connection with the Services. The current list of Sub-processors is available on Cartwheel’s Trust Center at trust.cartwheel.io.

5.2  Cartwheel imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for each Sub-processor’s performance.

5.3  Cartwheel will make notice of new Sub-processors available through its Trust Center and to customers who subscribe there for updates, before the new Sub-processor begins Processing Personal Data. If Customer has a reasonable, data-protection-based objection, the parties will work in good faith to resolve it; if they cannot, Customer may terminate the affected Services as its exclusive remedy.

6. Assistance

6.1  Taking into account the nature of the Processing, Cartwheel provides reasonable assistance — including functionality within the Services — to help Customer respond to Data Subject requests to exercise their rights under Applicable Data Protection Laws. If Cartwheel receives such a request directly, it will forward it to Customer and not respond except on Customer’s instruction, unless legally required.

6.2  Cartwheel provides reasonable assistance, taking into account the information available to it, with Customer’s privacy or risk assessments relating to the Processing.

7. Personal Data Breach

Cartwheel will notify Customer without undue delay, and no later than seventy-two (72) hours, after confirming a Personal Data Breach affecting Personal Data. The notice will describe, to the extent known, the nature of the breach and the measures taken to address it, and Cartwheel will reasonably cooperate to help Customer meet its own notification obligations. Notification is not an acknowledgment of fault or liability.

8. Location of Processing (North America)

8.1  Cartwheel provides the Services from, and Processes and stores Personal Data in, the United States. Customer instructs Cartwheel that Personal Data originating in Canada or Mexico will be transferred to and Processed in the United States to provide the Services.

8.2  Cartwheel maintains a level of protection for Personal Data comparable to that required under Applicable Data Protection Laws wherever it is Processed, and provides reasonable assistance with Customer’s related transparency, notice, and consent obligations. If the parties later agree that Cartwheel will Process Personal Data subject to the laws of a jurisdiction outside North America (such as the EU or UK), the parties will put an appropriate transfer mechanism in place at that time.

9. Audit

Cartwheel will make available information reasonably necessary to demonstrate compliance with this DPA, which Customer agrees may be satisfied through Cartwheel’s Trust Center and its third-party audit reports and certifications, made available under confidentiality on request. Where those are insufficient or where Applicable Data Protection Laws require, Customer may audit Cartwheel’s compliance no more than once in any twelve-month period (or following a Personal Data Breach) on reasonable prior written notice, during business hours, subject to confidentiality, and without disrupting Cartwheel’s operations or compromising other customers’ data.

10. Return and deletion

On expiration or termination of the Agreement, Cartwheel will, on Customer’s request, make Personal Data available for export in a commercially usable format for thirty (30) days, and will delete remaining copies within sixty (60) days thereafter, except for copies retained in routine backups (deleted on a rolling basis in the ordinary course) or as required by law.

11. Liability and general

Each party’s liability under this DPA is subject to the limitations of liability in the Agreement, except where Applicable Data Protection Laws do not permit such limitation. This DPA takes effect with the Agreement and continues while Cartwheel Processes Personal Data. It is governed by the governing-law terms of the Agreement. If any provision is unenforceable, the rest remains in effect.

Annex — Description of Processing and Security Measures

Nature and purpose. Cartwheel Processes Personal Data to provide accounts-receivable automation for staffing organizations, including generating and delivering invoices, collecting and processing payments, sending payment reminders, applying and reconciling payments with Customer’s systems, operating the client portal, and providing dashboards and reporting.

Duration. For the term of the Agreement, plus the export and deletion periods in Section 10.

Categories of Data Subjects. Customer’s personnel and authorized users; the billing and accounts-payable contacts of Customer’s clients; and other individuals whose information appears in Customer’s accounts-receivable records, in the United States, Canada, and Mexico as applicable.

Categories of Personal Data. Business contact details (name, business email, phone, address, role); account and portal data (username, authentication data, activity logs); and financial and transactional data (invoice and payment detail, balances, remittance and bank/payment information used to collect and remit funds). Payment card data is handled by Cartwheel’s payment-processing Sub-processor; Cartwheel does not store full payment card numbers. The Services are not intended to Process sensitive personal information or government identifiers (such as Social Security, Social Insurance, or national ID numbers), and Customer will not submit such data except as expressly agreed.

Security measures. Cartwheel’s measures include: encryption of Personal Data in transit and at rest; role-based access controls, least-privilege access, and multi-factor authentication for administrative and production access; network and application security controls and a secure development process; monitoring and logging of access to production systems; regular backups and a business-continuity and disaster-recovery program; personnel confidentiality obligations and security training; security assessment of Sub-processors; no use of Personal Data for AI or model training; and a documented incident-response process supporting the breach-notification commitment in Section 7. Current details are available on Cartwheel’s Trust Center at trust.cartwheel.io.

Sub-processors

The current list of Sub-processors is available on Cartwheel’s Trust Center at trust.cartwheel.io. As of the date above, they are:

Sub-processor Purpose Location
Amazon Web Services, Inc. Cloud infrastructure hosting and data storage United States
Cloudflare, Inc. Network security, DNS, and content delivery United States
Datadog, Inc. System monitoring and logging United States
Mailgun (Sinch) Outbound email delivery United States
Stripe, Inc. Payment processing and payouts United States
Pylon Customer support operations United States