Skip to main content
Hate Ledger

Data Processing Addendum

For customers who need GDPR / UK-GDPR processor terms in place with Hate Ledger.

Last updated · July 9, 2026Maintained by Hate Ledgerservices@hateledger.com

This Data Processing Addendum ("DPA") supplements the Hate Ledger Terms of Service and applies when Hate Ledger processes Personal Data on behalf of a Customer as a Processor, as defined in the EU General Data Protection Regulation and the UK GDPR.

1. Roles

Customer acts as the Controller of Personal Data submitted to Hate Ledger. Hate Ledger acts as the Processor and will only process Personal Data on documented instructions from Customer, including the Terms of Service.

2. Scope and purpose

Processing is limited to what is necessary to provide the accounting, reporting, and communications features of the Service. Categories of data: business identifying data, transaction metadata, employee names and compensation amounts (if uploaded), and communication preferences.

3. Sub-processors

Hate Ledger uses vetted sub-processors listed on our Subprocessors page. Customer authorises these sub-processors and will be notified of material changes before they take effect.

4. International transfers

Where Personal Data is transferred outside the EEA or UK, the transfer relies on the Standard Contractual Clauses (Module 2 or 3 as applicable) and, for UK data, the UK International Data Transfer Addendum.

5. Security

Hate Ledger implements the technical and organisational measures described on our Security page, including encryption in transit and at rest, tenant isolation via row-level security, and least-privilege access controls.

6. Data subject rights and assistance

Hate Ledger provides tools in the app for account owners to export and delete their data. For requests we cannot fulfil through those tools, contact services@hateledger.com.

7. Breach notification

Hate Ledger will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer's data.

8. Deletion

On termination, Customer data is deleted within 30 days unless retention is required by law.

9. Countersigning

Customers who require a countersigned DPA on company letterhead may email services@hateledger.com.


This page is app-owned editable content maintained by Hate Ledger to answer common questions about the service. It is not an independent certification. For anything binding or company-specific, email services@hateledger.com.