Data Processing Addendum
Last updated: July 17, 2026
Effective date: July 17, 2026
This addendum forms part of the Terms of Service between TMH Consulting, Inc. and the company using Paidsley ("Customer"). It governs personal information Paidsley processes on Customer's behalf.
Roles
Customer is the business. Paidsley is a service provider as defined by California Civil Code §1798.140(ag). Customer decides what is collected and why; Paidsley processes only on Customer's documented instructions.
Purpose limitation
- Paidsley will not sell or share personal information.
- Paidsley will not retain, use, or disclose personal information for any purpose other than performing the services, or as otherwise permitted by the CPRA.
- Paidsley will not retain, use, or disclose personal information outside the direct business relationship with Customer.
- Paidsley will not combine personal information received from Customer with personal information from any other source, except as the CPRA permits.
- Paidsley certifies that it understands these restrictions and will comply with them.
Categories processed
See the "From employees" list in our Privacy Notice. It includes sensitive personal information (precise geolocation at punches; last four digits of a Social Security number).
Subprocessors
| Name | What they do | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Twilio | SMS delivery (login codes and notifications) | United States |
| Resend | Transactional email | United States |
| OpenAI | Speech-to-text for voice clock-in | United States |
| Anthropic | Reading receipts and interpreting voice requests | United States |
| n8n Cloud | Workflow processing | European Union |
| Lovable | Application hosting | United States |
| Cloudflare | DNS and network | United States |
Paidsley will give Customer notice before adding a subprocessor, and each subprocessor is bound by terms at least as protective as these.
Security
Encryption in transit and at rest; row-level tenant isolation enforced in the database so one company cannot read another's data; role-based access with pay and personal details masked from the assistant role at the database layer; and an append-only punch record with an audit trail.
Assisting with consumer requests
Paidsley will help Customer respond to requests to know, delete, correct, opt out, or limit - including by forwarding any request it receives directly from Customer's employee.
Security incidents
Paidsley will notify Customer without undue delay after becoming aware of a breach of security leading to unlawful destruction, loss, alteration, or disclosure of Customer's personal information, and will share what it knows so Customer can meet its own obligations.
Audit
Customer may take reasonable and appropriate steps to ensure Paidsley uses personal information consistently with Customer's obligations, and may stop and remediate unauthorized use.
Deletion and return
On termination, Customer may export data for 30 days, after which Paidsley deletes it, except where law requires retention. Customer has its own record-keeping duties (California requires employers to keep time records for at least three years) and is responsible for exporting what it needs.
