Data Processing Agreement

Last Updated: February 17, 2026

GDPR Article 28 Compliant | For Enterprise and Professional Customers

Purpose of This Agreement

This Data Processing Agreement ("DPA") forms part of the service agreement between you (the "Customer" or "Data Controller") and Splitifi, LLC ("Splitifi" or "Data Processor"). This DPA governs the processing of Personal Data by Splitifi on behalf of the Customer in compliance with applicable data protection laws, including the GDPR, CCPA, and other privacy regulations.

1. Definitions and Interpretation

1.1 Definitions

Terms used in this DPA have the meanings set forth below. Capitalized terms not defined herein shall have the meanings given in the GDPR or the Service Agreement.

Personal Data

Any information relating to an identified or identifiable natural person processed by Splitifi on behalf of the Customer through the Service.

Data Controller

The Customer, who determines the purposes and means of the processing of Personal Data.

Data Processor

Splitifi, which processes Personal Data on behalf of the Customer.

Sub-processor

Any third party engaged by Splitifi to process Personal Data on behalf of the Customer.

Data Subject

An identified or identifiable natural person to whom Personal Data relates.

Processing

Any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, erasure, or destruction.

Supervisory Authority

An independent public authority established by a Member State to monitor and enforce GDPR compliance.

2. Processing of Personal Data

2.1 Scope and Purpose

Splitifi shall process Personal Data only:

  • On documented instructions from the Customer
  • For the purpose of providing the Service as described in the Service Agreement
  • In accordance with applicable data protection laws
  • As necessary to comply with legal obligations

2.2 Nature and Purpose of Processing

AspectDescription
NatureStorage, organization, retrieval, analysis, and transmission of case-related data
PurposeProvide divorce and family law case management, financial analysis, document generation, and collaboration tools
DurationFor the term of the Service Agreement and retention period as specified

2.3 Categories of Data Subjects

  • Divorce litigants and parties to family law proceedings
  • Attorneys and legal professionals
  • Judicial officers and court personnel
  • Mediators, CDFAs, and other family law professionals
  • Customer employees and authorized users
  • Minor children (limited information as required for case purposes)

2.4 Categories of Personal Data

  • Identification data (name, address, date of birth, Social Security number)
  • Contact information (email, phone number)
  • Financial information (income, assets, debts, account details)
  • Employment information (employer, salary, benefits)
  • Family information (marriage details, children, custody arrangements)
  • Legal case information (court filings, settlement proposals, agreements)
  • Professional credentials (bar number, license information)
  • Communication data (messages, case notes, uploaded documents)

3. Splitifi's Obligations as Data Processor

3.1 Processing Instructions

Splitifi shall:

  • Process Personal Data only on documented instructions from the Customer
  • Immediately inform the Customer if, in Splitifi's opinion, an instruction infringes applicable data protection law
  • Not process Personal Data for purposes other than those instructed by the Customer
  • Not disclose Personal Data to third parties without Customer authorization (except as required by law)

3.2 Confidentiality

Splitifi shall ensure that:

  • Persons authorized to process Personal Data are bound by confidentiality obligations
  • Access to Personal Data is limited to personnel who need access to perform their duties
  • All personnel receive appropriate training on data protection and security
  • Confidentiality obligations survive termination of employment or engagement

3.3 Security Measures

Splitifi implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Technical Measures

  • • Encryption of data in transit (TLS 1.2+)
  • • Encryption of data at rest (AES-256)
  • • Multi-factor authentication
  • • Regular security updates and patches
  • • Intrusion detection systems
  • • Firewall protection
  • • Secure backup systems

Organizational Measures

  • • Access controls and authorization
  • • Security awareness training
  • • Incident response procedures
  • • Regular security audits
  • • Vendor management program
  • • Data protection policies
  • • Business continuity planning

4. Sub-processors

4.1 Authorization

The Customer authorizes Splitifi to engage sub-processors to process Personal Data, subject to the conditions set forth in this DPA.

4.2 Current Sub-processors

Sub-processorServiceLocation
Amazon Web ServicesCloud hosting and infrastructureUSA
Payment ProviderPayment processingUSA
SendGridEmail deliveryUSA
AI Service Providers (OpenAI, Anthropic, Google)AI processingUSA

4.3 Sub-processor Obligations

Splitifi shall:

  • Impose data protection obligations on sub-processors equivalent to those in this DPA
  • Ensure sub-processors provide appropriate security measures
  • Remain fully liable to the Customer for sub-processor performance
  • Conduct due diligence on sub-processors before engagement

4.4 Changes to Sub-processors

Splitifi will provide at least 30 days' notice before adding or replacing sub-processors. The Customer may object to a new sub-processor on reasonable grounds relating to data protection. If the Customer objects and Splitifi cannot accommodate the objection, either party may terminate the affected Service.

5. Data Subject Rights

5.1 Assistance with Requests

Splitifi shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection laws, including:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object

5.2 Process for Requests

If Splitifi receives a Data Subject request directly, Splitifi will promptly forward it to the Customer. The Customer is responsible for responding to Data Subject requests. Splitifi will provide reasonable assistance as needed.

6. Personal Data Breaches

6.1 Notification

Splitifi shall notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach affecting Customer data.

6.2 Breach Details

The notification shall include, to the extent possible:

  • Description of the nature of the breach
  • Categories and approximate number of Data Subjects affected
  • Categories and approximate number of Personal Data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Contact point for further information

6.3 Cooperation

Splitifi shall cooperate with the Customer and provide reasonable assistance in investigating, mitigating, and remediating the breach.

7. International Data Transfers

7.1 Transfer Mechanisms

To the extent that Personal Data is transferred outside the EEA or UK, Splitifi shall ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions where applicable
  • Other legally recognized transfer mechanisms

7.2 Additional Protections

Splitifi implements supplementary measures to ensure adequate protection for transferred Personal Data, including encryption, access controls, and contractual protections.

8. Audits and Compliance

8.1 Audit Rights

Splitifi shall make available to the Customer information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

8.2 Audit Process

  • Customer must provide at least 30 days' advance notice
  • Audits limited to once per year unless required by law or following a breach
  • Audits conducted during business hours with minimal disruption
  • Customer responsible for costs of audit unless compliance issues found
  • Auditors must execute appropriate confidentiality agreements

8.3 Certifications and Reports

Splitifi maintains SOC 2 compliance and other relevant security certifications. Copies of current certifications and audit reports can be provided upon request subject to confidentiality requirements.

9. Deletion and Return of Personal Data

9.1 Upon Termination

Upon termination of the Service Agreement, Splitifi shall, at the Customer's choice:

  • Return all Personal Data to the Customer in a commonly used, machine-readable format
  • Securely delete all Personal Data from Splitifi's systems

9.2 Exceptions

Splitifi may retain Personal Data to the extent required by applicable law or regulation, provided that Splitifi ensures the confidentiality of such Personal Data and processes it only for legal compliance purposes.

9.3 Certification

Upon request, Splitifi will provide written certification that all Personal Data has been returned or deleted as instructed.

10. Liability and Indemnification

10.1 Liability

Each party's liability under this DPA shall be subject to the limitations and exclusions of liability set forth in the Service Agreement, except as prohibited by applicable data protection law.

10.2 Indemnification

Splitifi shall indemnify and hold harmless the Customer against losses, damages, costs, and expenses arising from Splitifi's breach of this DPA, except to the extent caused by Customer's instructions or actions.

11. Term and Termination

11.1 Term

This DPA shall commence on the effective date of the Service Agreement and continue until termination of the Service Agreement or until all Personal Data has been deleted or returned, whichever is later.

11.2 Survival

Provisions regarding confidentiality, deletion/return of data, liability, and indemnification shall survive termination of this DPA.

12. General Provisions

12.1 Governing Law

This DPA shall be governed by the same governing law as the Service Agreement.

12.2 Severability

If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.

12.3 Amendments

Splitifi may update this DPA to reflect changes in data protection laws or processing operations. Material changes will be communicated to customers with at least 30 days' notice.

12.4 Order of Precedence

In the event of conflict between this DPA and the Service Agreement, this DPA shall prevail to the extent of the conflict.

13. Contact Information

For questions regarding this DPA or to exercise your rights:

Data Protection Officer:dpo@splitifi.io

Legal Department:legal@splitifi.io

Privacy Team:privacy@splitifi.io

Enterprise Customers

For enterprise agreements and custom DPA terms, please contact our sales team.

enterprise@splitifi.io