This document is written for Skaith’s current U.S. business service. It does not turn an audit result into legal advice or guarantee a supplier credit.
1. Scope and roles
This addendum applies to personal information in Customer Content that Skaith processes to provide the service. Customer is the controller, business, or equivalent party that determines the purpose and means of processing. Skaith is the processor, service provider, contractor, or equivalent party acting on Customer’s documented instructions. Terms used by applicable privacy law have the meanings given by that law.
2. Processing details
- Subject matter and purpose: secure document intake, storage, screening, extraction, contract-to-invoice comparison, evidence display, reporting, customer-authorized recovery workflows, support, and security.
- Duration: the term of Customer’s use plus the documented retention and deletion period.
- Data subjects: Customer personnel, account users, wearers or employees named in records, supplier personnel, contacts, and other individuals appearing in Customer Content.
- Data types: identifiers, professional and employment-related details, service locations, vendor account data, transaction and invoice details, communications, and other information Customer chooses to submit, excluding restricted data prohibited by the Terms.
3. Customer instructions
The Terms, product configuration, and Customer’s authorized actions are documented instructions. Skaith will process Customer personal information only on those instructions, including transfers needed to provide the service, unless law requires otherwise. If legally permitted, Skaith will notify Customer of a required processing instruction. Skaith will inform Customer if an instruction appears to violate applicable privacy law and may pause that processing.
4. Skaith obligations
- Ensure people authorized to process Customer personal information are bound by confidentiality obligations.
- Maintain appropriate technical and organizational safeguards described in the Security section of the Privacy Policy and repository security documentation applicable to the live service.
- Taking into account the nature of processing, reasonably assist Customer with verified data-subject requests, security assessments, breach obligations, and required regulator consultations.
- Maintain records reasonably sufficient to demonstrate the obligations in this addendum and provide relevant information on written request, subject to confidentiality and security limits.
5. Subprocessors
Customer gives general authorization for the subprocessors listed on the current subprocessor page. Skaith will require each subprocessor to protect Customer personal information consistently with its role and applicable law. Skaith remains responsible for its obligations under this addendum when a subprocessor processes Customer personal information on its behalf.
We will update the list before adding a provider that materially expands Customer Content processing. Customer may object on reasonable data-protection grounds by contacting support within 15 days. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may end the affected service.
6. Security incidents
Skaith will notify Customer without undue delay after confirming unauthorized acquisition of or access to Customer personal information in Skaith’s control, as required by applicable law. Notice will include available information reasonably needed for Customer’s obligations and will be updated as the investigation develops. Notice is not an admission of fault or liability.
Customer is responsible for incidents caused by its accounts, instructions, systems, forwarding rules, or failure to use available controls, except to the extent caused by Skaith’s breach of this addendum.
7. Return and deletion
During the service term, Customer can access or export available records through product features. On a valid deletion request or termination, Skaith will delete or render inaccessible Customer personal information from active systems according to product behavior and the selected retention policy, unless law requires retention. Residual protected versions and backups are isolated from ordinary use and removed under their lifecycle. Skaith may retain minimal records needed for security, fraud prevention, legal claims, and compliance.
8. U.S. state privacy terms
Skaith will not sell or share Customer personal information; retain, use, or disclose it outside the specific business purposes in the agreement or as otherwise permitted by law; combine it with personal information received from another person except as permitted to provide the service; or use it for cross-context behavioral advertising. Customer may take reasonable steps to verify compliance. Skaith will notify Customer if it can no longer meet an applicable obligation and will cooperate with reasonable steps to stop and remediate unauthorized use.
9. International transfers
The current public service is intended for U.S. businesses and does not include European Commission Standard Contractual Clauses, a UK addendum, or another international transfer mechanism. Customer must not use the service for regulated international transfers unless the parties first sign the required terms.
10. Review and audit
No more than once annually, unless required after a confirmed incident or by a regulator, Customer may request available security and compliance information relevant to the service. If that information is insufficient, the parties may agree to a narrowly scoped independent review that avoids other customers’ data, source code, vulnerability details, and operational disruption. Customer bears its costs unless the review identifies a material breach by Skaith.
11. Priority and liability
This addendum controls over conflicting Terms only for its subject matter. The liability limits and dispute provisions in the Terms apply to this addendum except where privacy law prohibits them.
