Legal
Data Processing Addendum
Last updated: September 5, 2026 · Draft for counsel review
This addendum applies when HeyRoca processes personal data on behalf of a subscribing firm in connection with the staff app and client portal. It supplements the Terms of Service and Privacy Policy. It is a public draft, not a substitute for an attorney-reviewed contract. Questions: [email protected].
Roles
The firm is the controller (or similar role under applicable privacy law) of client and staff personal data it enters into the service. HeyRoca is the processor of that customer data. HeyRoca is an independent controller of account, billing, and security data needed to operate the platform.
Instructions
We process customer data only to provide, secure, and support the service, as described in the Terms, Privacy Policy, and documented product features, and as otherwise agreed in writing. The firm is responsible for the lawfulness of the data it uploads and for notices to its clients.
Confidentiality and personnel
We limit access to customer data to personnel who need it to operate the service and who are bound by confidentiality obligations. We do not claim background-check or certification programs that we have not completed.
Security
Technical and organizational measures currently in use are described on the Security page, including TLS in transit, encryption of tax IDs at rest, private object storage, staff and portal MFA, and authenticated downloads. We will notify the firm without undue delay if we confirm a security incident affecting that firm’s customer data.
Subprocessors
We use the following subprocessors to run the service:
- Stripe — firm subscriptions and client invoice payments
- Resend — transactional email
- Cloudflare R2 — private document object storage
- Managed PostgreSQL — primary application database
We remain responsible for subprocessors we engage. Material changes to this list will be reflected on this page or the Security page.
Assistance, deletion, and return
We will assist the firm with reasonable requests related to data-subject rights, security, and incident response, taking into account the nature of the processing. On request after the subscription ends, or earlier if the firm asks, we will delete or return customer data unless law requires retention. Email [email protected] to start a deletion request.
International processing
The service is operated for U.S. firms. Infrastructure may process data in the United States. Specific transfer mechanisms, if required, should be confirmed with counsel before relying on this draft for cross-border transfers.
Contact
Security and privacy contact: [email protected]