Last Updated: February 17, 2026
GDPR Article 28 Compliant | For Enterprise and Professional Customers
This Data Processing Agreement ("DPA") forms part of the service agreement between you (the "Customer" or "Data Controller") and Splitifi, LLC ("Splitifi" or "Data Processor"). This DPA governs the processing of Personal Data by Splitifi on behalf of the Customer in compliance with applicable data protection laws, including the GDPR, CCPA, and other privacy regulations.
Terms used in this DPA have the meanings set forth below. Capitalized terms not defined herein shall have the meanings given in the GDPR or the Service Agreement.
Personal Data
Any information relating to an identified or identifiable natural person processed by Splitifi on behalf of the Customer through the Service.
Data Controller
The Customer, who determines the purposes and means of the processing of Personal Data.
Data Processor
Splitifi, which processes Personal Data on behalf of the Customer.
Sub-processor
Any third party engaged by Splitifi to process Personal Data on behalf of the Customer.
Data Subject
An identified or identifiable natural person to whom Personal Data relates.
Processing
Any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, erasure, or destruction.
Supervisory Authority
An independent public authority established by a Member State to monitor and enforce GDPR compliance.
Splitifi shall process Personal Data only:
| Aspect | Description |
|---|---|
| Nature | Storage, organization, retrieval, analysis, and transmission of case-related data |
| Purpose | Provide divorce and family law case management, financial analysis, document generation, and collaboration tools |
| Duration | For the term of the Service Agreement and retention period as specified |
Splitifi shall:
Splitifi shall ensure that:
Splitifi implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
The Customer authorizes Splitifi to engage sub-processors to process Personal Data, subject to the conditions set forth in this DPA.
| Sub-processor | Service | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting and infrastructure | USA |
| Payment Provider | Payment processing | USA |
| SendGrid | Email delivery | USA |
| AI Service Providers (OpenAI, Anthropic, Google) | AI processing | USA |
Splitifi shall:
Splitifi will provide at least 30 days' notice before adding or replacing sub-processors. The Customer may object to a new sub-processor on reasonable grounds relating to data protection. If the Customer objects and Splitifi cannot accommodate the objection, either party may terminate the affected Service.
Splitifi shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection laws, including:
If Splitifi receives a Data Subject request directly, Splitifi will promptly forward it to the Customer. The Customer is responsible for responding to Data Subject requests. Splitifi will provide reasonable assistance as needed.
Splitifi shall notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach affecting Customer data.
The notification shall include, to the extent possible:
Splitifi shall cooperate with the Customer and provide reasonable assistance in investigating, mitigating, and remediating the breach.
To the extent that Personal Data is transferred outside the EEA or UK, Splitifi shall ensure that appropriate safeguards are in place, including:
Splitifi implements supplementary measures to ensure adequate protection for transferred Personal Data, including encryption, access controls, and contractual protections.
Splitifi shall make available to the Customer information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
Splitifi maintains SOC 2 compliance and other relevant security certifications. Copies of current certifications and audit reports can be provided upon request subject to confidentiality requirements.
Upon termination of the Service Agreement, Splitifi shall, at the Customer's choice:
Splitifi may retain Personal Data to the extent required by applicable law or regulation, provided that Splitifi ensures the confidentiality of such Personal Data and processes it only for legal compliance purposes.
Upon request, Splitifi will provide written certification that all Personal Data has been returned or deleted as instructed.
Each party's liability under this DPA shall be subject to the limitations and exclusions of liability set forth in the Service Agreement, except as prohibited by applicable data protection law.
Splitifi shall indemnify and hold harmless the Customer against losses, damages, costs, and expenses arising from Splitifi's breach of this DPA, except to the extent caused by Customer's instructions or actions.
This DPA shall commence on the effective date of the Service Agreement and continue until termination of the Service Agreement or until all Personal Data has been deleted or returned, whichever is later.
Provisions regarding confidentiality, deletion/return of data, liability, and indemnification shall survive termination of this DPA.
This DPA shall be governed by the same governing law as the Service Agreement.
If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.
Splitifi may update this DPA to reflect changes in data protection laws or processing operations. Material changes will be communicated to customers with at least 30 days' notice.
In the event of conflict between this DPA and the Service Agreement, this DPA shall prevail to the extent of the conflict.
For questions regarding this DPA or to exercise your rights:
Data Protection Officer:dpo@splitifi.io
Legal Department:legal@splitifi.io
Privacy Team:privacy@splitifi.io
For enterprise agreements and custom DPA terms, please contact our sales team.