Legal Center
Data Processing Addendum
Contract terms for eligible processing of customer-provided personal data.
- Effective Date
- August 3, 2026
- Last Revised
- August 3, 2026
- Version
- 1.0
1. What This Addendum Is
This Data Processing Addendum applies where Diversified Check Studio processes personal data on behalf of a customer that is subject to a data protection law requiring such terms, including the General Data Protection Regulation, the United Kingdom GDPR, and comparable state or national laws.
It forms part of the Terms and Conditions between the customer and Diversified Check Studio. Where this addendum conflicts with the Terms and Conditions on the processing of personal data, this addendum controls.
2. Definitions
Controller, processor, data subject, personal data, processing, and supervisory authority have the meanings given in applicable data protection law. Customer Personal Data means personal data contained in customer content that we process on the customer's behalf. Subprocessor means a third party engaged by us to process Customer Personal Data.
3. Roles of the Parties
For Customer Personal Data, the customer is the controller and Diversified Check Studio is the processor.
For account registration data, billing data, license records, security logs, and communications with us, Diversified Check Studio acts as a controller for its own legitimate business purposes, as described in the Privacy Policy.
4. Subject Matter, Nature, and Purpose
The subject matter is the provision of check design and check printing software. The nature and purpose of processing is hosting, storing, securing, transmitting, and displaying customer content so the customer can design, authorize, and print checks and administer its account.
Processing continues for the duration of the agreement, plus any retention period described in the Data Retention and Deletion Policy.
5. Categories of Data Subjects and Data
Data subjects may include the customer's administrators and users, authorized signatories, approvers, and payees.
Customer Personal Data may include names, business names, email addresses, postal addresses, telephone numbers, role and permission assignments, signature images, bank routing and account numbers for accounts the customer controls, payee names and addresses, check amounts and memos, and activity logs.
6. Customer Instructions
We process Customer Personal Data only on the documented instructions of the customer, which are given through the agreement, this addendum, and the customer's use of the software's features and settings.
We will inform the customer if, in our opinion, an instruction infringes applicable data protection law, unless we are legally prohibited from doing so. If we are required by law to process beyond the customer's instructions, we will inform the customer of that requirement unless prohibited.
7. Customer Responsibilities
The customer is responsible for the lawfulness of the personal data it provides, for having a valid legal basis for processing, for providing required notices to data subjects, for the accuracy of the data entered, and for configuring user access appropriately.
The customer must not submit special categories of personal data beyond what the software is designed to handle.
8. Confidentiality
We ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate guidance on their responsibilities.
9. Security Measures
We implement appropriate technical and organizational measures, described in the Security Overview, including encryption in transit and at rest, application-level encryption of sensitive values, account-scoped row level security, role based access control, authentication controls including optional two-factor authentication, private storage of uploaded assets, audit logging, and access limited to those who need it.
Measures may be updated over time provided they do not materially reduce the level of protection.
10. Subprocessors
The customer provides general authorization for us to engage subprocessors. The current categories are described in the Subprocessors and Service Providers document.
Each subprocessor is bound by written terms that impose data protection obligations no less protective than those in this addendum, and we remain responsible for their performance.
We will provide notice of a new subprocessor that processes Customer Personal Data by updating that document. Customers may subscribe to notice by contacting us. A customer may object on reasonable data protection grounds within thirty days of notice, and we will work in good faith to provide an alternative. If no reasonable alternative exists, the customer may terminate the affected service.
11. Assistance With Data Subject Rights
The software gives customers direct access to view, correct, export, and delete records within their account, which allows most rights requests to be handled by the customer.
Where a data subject contacts us directly regarding Customer Personal Data, we will refer that person to the customer. We will provide reasonable assistance to the customer in responding to access, correction, deletion, restriction, portability, and objection requests, taking into account the nature of the processing.
12. Assistance With Compliance Obligations
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with data protection impact assessments, prior consultation with supervisory authorities, and security obligations.
13. Personal Data Breach
We will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to us, including the nature of the breach, the categories and approximate number of records involved where known, the likely consequences, and the measures taken or proposed.
Notification is not an acknowledgement of fault or liability.
14. Deletion and Return
On termination or expiry, the customer may export its data using the export tools in the software during any wind-down period described in the Data Retention and Deletion Policy.
After that period we will delete Customer Personal Data, except where retention is required by law or is necessary to establish, exercise, or defend legal claims. Data in routine backups is deleted in accordance with the backup cycle.
15. Audits
On reasonable written request, and no more than once in any twelve month period unless required by a supervisory authority, we will make available information reasonably necessary to demonstrate compliance with this addendum. Where an on-site audit is legally required, the parties will agree in advance on scope, timing, confidentiality, and cost, and the audit must not compromise the security or privacy of other customers.
16. International Transfers
Processing occurs primarily in the United States. Where Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country without an adequacy decision, the transfer is governed by the European Commission Standard Contractual Clauses, and the United Kingdom International Data Transfer Addendum where applicable, which are incorporated into this addendum by reference.
For those clauses, the customer is the data exporter and Diversified Check Studio is the data importer, Module Two applies where the customer is a controller, Module Three applies where the customer is itself a processor, the governing law and forum are those specified in the clauses for the relevant jurisdiction, and the descriptions in sections 4, 5, 9, and 10 of this addendum populate the corresponding annexes.
17. Liability
The liability provisions of the Terms and Conditions apply to this addendum. Nothing here limits liability that cannot be limited under applicable data protection law.
18. Order of Precedence and Term
This addendum takes effect when the customer accepts the Terms and Conditions and remains in effect for as long as we process Customer Personal Data.
19. How to Execute a Signed Copy
This addendum applies automatically without signature. A customer that requires a countersigned copy for its records may request one using the contact information below.
20. Contact
Data protection questions and addendum requests may be directed to:
Diversified Check Studio
A product of Diversified SaaS, Inc.
Diversified SaaS, Inc. is a wholly owned subsidiary of Diversified Universal LLC.
6212 US Highway 6, Suite 184
Portage, IN 46368-5057
Email: legal@choosediversified.com
Phone: 1 (833) 990-7297
WhatsApp: 1 (833) 990-7297