parımPrivacy policy →
Legal

Data Processing Agreement

Last updated: July 4, 2026 · Effective on account creation

1. Parties and scope

This Data Processing Agreement ("DPA") is entered into between Pariom ("Pariom," "Processor") and the entity that has accepted Pariom's Terms of Service ("Customer," "Controller"). This DPA governs Pariom's processing of Personal Data on behalf of the Customer in connection with the Pariom services.

2. Data Pariom processes

Pariom processes the following categories of data on Customer's behalf:

  • Metric values, check configurations, and reconciliation history (cases, rulings, definitions)
  • Database or warehouse connection credentials provided for reconciliation checks (encrypted at rest)
  • Trial balance and general ledger data from connected accounting systems, for the memo tool
  • Account codes, vendor names, and transaction metadata (not line-item detail)
  • User account information (name, email, role) for authentication
  • Usage logs for audit and support purposes

Pariom does not process customer end-user data, payment card numbers, Social Security numbers, or health records.

3. Processing purposes

Pariom processes Customer data solely to provide the Pariom services, including: running reconciliation checks, generating variance memos, drafting AI diagnostic briefs, answering natural-language queries, and providing technical support. Pariom does not use Customer data to train models or for any purpose beyond service delivery.

4. Security measures

Pariom implements the following technical and organizational measures: AES-256-GCM encryption of connection credentials at rest, TLS 1.3 in transit, row-level security enforced on every database table so each Customer can only access their own data, restriction of reconciliation queries to a single read-only SELECT, and blocking of outbound connections to private or internal network ranges. Infrastructure is built on Vercel and Supabase (AWS-hosted).

5. Sub-processors

Pariom uses the sub-processors listed at pariom.ai/legal/subprocessors. Pariom will provide 30 days' notice before adding new sub-processors. Customer may object to a new sub-processor within that window; Pariom will make reasonable efforts to accommodate the objection or allow Customer to terminate without penalty.

6. Data subject rights

To the extent Customer's employees or end-users exercise data subject rights under GDPR, CCPA, or applicable law, Pariom will assist Customer in fulfilling those requests within 30 days. Requests should be directed to security@pariom.ai.

7. Data deletion

Upon termination or Customer request, Pariom will delete all Customer data within 30 days and confirm by email. This includes all derived data, model outputs, and cached trial balance data.

8. Governing law

This DPA is governed by the laws of the State of Delaware, United States. For EU/UK customers, the Standard Contractual Clauses (Module 2: Controller to Processor) are available on request and will govern to the extent applicable law requires them.

Questions about this DPA or to request a signed copy: security@pariom.ai