Legal
Data Processing Agreement
Data-processing terms for Customer Personal Data handled through AccountMade.
Effective: August 25, 2026 Version: 2026.08.25
This DPA is between the AccountMade customer ("Customer") and The Plain Works Co.,Ltd., business registration number 293-87-03653, at 901-C32 126, Wolbong-ro, Seobuk-gu, Cheonan-si, Chungcheongnam-do, Republic of Korea ("Processor"). JINYONG KIM is Processor's Privacy Lead.
1. Scope and roles
This DPA forms part of the AccountMade Terms or other agreement (the "Agreement") when Processor handles personal data contained in Customer Content on Customer's behalf ("Customer Personal Data"). Customer is the controller or business; Processor is the processor or service provider. Each party independently controls account, business-contact, billing, and relationship data it collects for its own purposes.
The Service is offered only to business customers in the United States and Canada, excluding Quebec, and is not currently offered or targeted in the EU, EEA, or UK. This DPA does not incorporate EU or UK standard contractual clauses. The parties must execute an appropriate addendum before intentionally extending covered processing to a territory that requires it.
2. Instructions and purpose limitation
Processor will process Customer Personal Data only to provide, secure, support, and improve the Service in accordance with the Agreement, Customer's configuration and use, and written instructions sent to legal@accountmade.com. Processor will notify Customer if an instruction appears unlawful, unless prohibited from doing so.
Processor will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship; combine it with personal data received from another source except as legally permitted to provide the Service; use it for cross-context behavioral advertising; or use it to train general-purpose AI models.
3. Customer responsibilities
Customer will provide lawful instructions, required notices and consents, and only data needed for the Service. Customer will not submit restricted data identified in the Terms without a separate written approval. Customer is responsible for data-subject responses, workspace permissions, connected systems, public links, and determining whether the Service is suitable for its legal obligations.
4. Processor obligations
Processor will:
- ensure personnel with access are bound by confidentiality;
- maintain the measures in Annex II and the Security Overview;
- assist Customer, considering the nature of processing, with verified privacy-right requests, security assessments, breach response, and legally required impact assessments;
- maintain records reasonably necessary to demonstrate compliance;
- notify Customer of a legally binding government demand where permitted and challenge disproportionate demands when reasonable;
- delete or return Customer Personal Data as described in Section 8; and
- notify Customer if Processor can no longer meet applicable service-provider or processor restrictions and allow reasonable steps to stop and remediate unauthorized use.
5. Subprocessors
Customer gives general authorization for the providers listed at /legal/subprocessors. Processor will impose written data-protection obligations appropriate to their processing and remains responsible for their performance to the extent required by applicable law.
Processor will provide at least 30 days' notice before a new subprocessor materially processes Customer Personal Data, except an urgent replacement may receive shorter notice for security, legal compliance, availability, or continuity. Customer may object on reasonable data-protection grounds within 14 days. The parties will seek a practical solution; if none exists, Customer may terminate the affected feature and receive a prorated refund of prepaid unused fees for that feature.
6. Security incidents
Processor will notify Customer without undue delay after confirming unauthorized access to or acquisition, alteration, loss, or destruction of Customer Personal Data for which notice is legally required. Notice will include available information about nature, likely consequences, affected data, and mitigation. Processor's notice is not an admission of fault. Customer is responsible for its own legally required notices, with Processor's reasonable assistance.
7. Privacy requests and audits
Processor will promptly route a request concerning Customer Personal Data to Customer unless authorized to respond. Customer may use product controls first. On reasonable written request no more than annually, Processor will provide then-current security and compliance information. If that is insufficient and law requires more, Customer may conduct a narrowly scoped audit through an independent, confidential auditor during business hours, without accessing another customer's data and at Customer's expense. Additional audits are allowed after a material incident or regulator request.
8. Return, deletion, and retention
During the term, Customer may export available Customer Content. After an authenticated deletion request, a 14-day cancellation window applies before scheduled deletion. Deleted workspace content may remain in trash up to 30 days and in isolated backups up to 35 additional days. Security logs are normally retained 90 days; support records 24 months; billing and tax records 5 years. Legal holds, fraud prevention, disputes, and mandatory law may require limited longer retention. Retained data remains protected and is deleted when the exception ends.
9. Cross-border processing
Customer authorizes processing in the Republic of Korea, the United States, and locations used by listed subprocessors. Processor will use contracts and technical and organizational measures appropriate to the transfer. For Canadian personal information, Processor will provide reasonable information about foreign processing and assist Customer with transparency obligations. Korean PIPA outsourcing and overseas-transfer notices are addressed through this DPA, the Privacy Policy, and the Subprocessors page to the extent applicable.
10. U.S. state privacy terms
Where Customer Personal Data is subject to the CCPA/CPRA or an analogous U.S. state law, Processor acts as Customer's service provider or processor and accepts the purpose limitations, no-sale/no-sharing restrictions, confidentiality, security, assistance, audit, deletion, and compliance-remediation obligations required for that role. The processing is for the limited and specified business purposes in Annex I.
11. Liability, term, and precedence
The Agreement's liability limits apply to this DPA to the maximum extent permitted by law. This DPA continues while Processor processes Customer Personal Data. If this DPA conflicts with the Agreement on personal-data processing, this DPA controls. Changes require a written agreement, except Processor may update subprocessors and operational details under the notice process above.
Annex I — Processing details
| Item | Detail |
|---|---|
| Subject | Providing AccountMade and customer-configured AI, integrations, sharing, support, and security |
| Duration | Agreement term plus the deletion and backup periods in Section 8 |
| Nature | Collection, storage, organization, retrieval, transmission, generation, analysis, support, restriction, and deletion |
| Business purposes | Hosting, authentication, collaboration, content generation/evaluation, integrations, support, security, fraud prevention, and customer-requested exports |
| Data subjects | Customer personnel, prospects, customers, partners, vendors, and other people represented in Customer Content |
| Data categories | Business contact details, account identifiers, CRM fields, source documents, prompts, claims, questionnaire data, generated output, usage and audit metadata |
| Restricted data | Not permitted unless separately approved in writing |
| Frequency | Continuous or customer-initiated during Service use |
Annex II — Technical and organizational measures
- role-based workspace access and least-privilege administrative access;
- managed authentication, secret storage, and credential rotation procedures;
- TLS in transit and provider-managed encryption at rest;
- tenant identifiers and authorization checks for Customer Content;
- logging, alerting, rate limits, abuse controls, and incident procedures;
- backups and tested recovery appropriate to the Service, subject to published retention;
- vendor review and contractual data-protection terms;
- commercial AI API accounts, no-training restrictions, minimum-necessary prompts, and provider retention controls;
- secure development review, dependency monitoring, and vulnerability response; and
- deletion workflows, access reviews, and personnel confidentiality.
Annex III — Contact
The Plain Works Co.,Ltd.
Business registration number: 293-87-03653
901-C32 126, Wolbong-ro, Seobuk-gu, Cheonan-si, Chungcheongnam-do, Republic of Korea
Privacy and DPA: legal@accountmade.com
Privacy Lead: JINYONG KIM
This DPA is accepted with the Agreement. A countersigned copy may be requested at legal@accountmade.com.