Data Processing Addendum
Effective date: 2026-10-08
Purpose and roles
This Data Processing Addendum (DPA) applies when a business customer uses getcsbill to store personal data in customer, invoice, work order, payment, expense, or accounting records. The business customer is the controller or business that determines the purposes of processing; CS Network and Security LLC is the processor or service provider acting on documented instructions in the Terms and the customer's use of the service.
Processing details
The subject is business operations and invoicing. The duration is the account term plus the limited retention period described in the Privacy Policy. Data may include names, business contact details, addresses, invoice details, service notes, payment status, and other information the customer chooses to enter. The customer must not submit card security codes, government identifiers, health data, or other sensitive data unless a separate written agreement allows it.
Instructions and confidentiality
We process customer records only to provide, secure, maintain, and support getcsbill, comply with law, and follow the customer's documented instructions. Personnel and providers with access are subject to confidentiality obligations. We do not sell customer records or use them for targeted advertising.
Subprocessors and international transfers
The customer authorizes the infrastructure and delivery providers identified in the Privacy Policy, including OpenAI Sites/Cloudflare, Stripe, Resend, and Square when the customer connects Square. We may replace or add providers when necessary to operate the service and will update the Privacy Policy when processing practices materially change. Processing may occur in the United States and other locations where providers operate.
Security, incidents, and assistance
We maintain reasonable technical and organizational safeguards appropriate to the service, including encryption in transit, hashed passwords, access controls, rate limits, tenant isolation, validation, protected administrative access, and encrypted optional provider credentials. We will notify the customer without undue delay after confirming a security incident affecting its records when required by law and will provide reasonable information needed for the customer's response.
Requests, return, and deletion
We will provide reasonable assistance for authenticated access, correction, export, deletion, and security requests. At the customer's request after account termination, we will delete or return records subject to legal retention, backup-cycle limits, fraud prevention, billing records, and dispute preservation. The customer remains responsible for responding to its own customers and for confirming that its instructions are lawful.
Audits and precedence
We will make available reasonable information about our safeguards and cooperate with a proportionate, non-disruptive assessment subject to confidentiality and security restrictions. If this DPA conflicts with the Terms for processing personal data, this DPA controls only for that conflict. Contact csosa@csnetworkandsecurity.com to request a signed copy or discuss requirements that need a negotiated agreement.