GoRefer Trust Center
Data Processing Agreement
Updated September 2026
This page summarizes data-processing topics to review when requesting a GoRefer DPA. The terms that apply are those in the agreement actually executed with your firm. Request available terms, transfer provisions and review of your use case through the Trust Portal.
DPA Availability by Plan
Updated September 2026
Growth Plan
Standard GoRefer DPA
Review scope against GDPR Article 28
Request applicable transfer terms
Confirm applicable UK transfer provisions
Request via Trust Portal
Scale Plan
Request applicable DPA and privacy terms
Discuss any BAA requirement before sharing protected health information
Confirm review timing with our team
Route legal questions through the Trust Portal
Request via Trust Portal
Enterprise Plan
Custom DPA negotiation supported
Legal review and redlines accepted
Discuss any BAA requirement with our team
Confirm supported execution options
Dedicated Customer Success contact
Key DPA Clauses Summary
Updated September 2026
The following summarizes topics and published policy positions to review with the agreement. The authoritative provisions are those actually executed with your firm; request confirmation of scope, notice periods and audit rights.
Subject Matter & Duration
GoRefer processes personal data on behalf of the customer (the Controller) solely to provide the GoRefer platform services. Processing continues for the duration of the subscription agreement.
Nature and Purpose of Processing
Storage and retrieval of tax referral and commission management data; AI-assisted workflow processing; transactional email delivery; analytics.
Categories of Data Subjects
Tax professionals, their clients, and administrative staff within the customer's firm.
Categories of Personal Data
Identity data, contact information, professional credentials, tax client records (including PII), authentication data, usage logs.
Controller Instructions
GoRefer processes personal data only on documented instructions from the customer. Instructions provided via product configuration, API calls, and account settings.
Sub-processor Management
GoRefer maintains a list of authorized sub-processors. New sub-processors are notified 30 days in advance. Customers may object in writing.
Security Measures (Art. 32 GDPR)
Supported sensitive-field encryption, HTTPS, authentication and role controls, as described on the Security page. Details of storage, security testing and monitoring are available on request.
Data Subject Rights Assistance
GoRefer provides mechanisms and reasonable assistance to enable customers to respond to data subject rights requests (access, erasure, portability, restriction).
Data Breach Notification
GoRefer notifies customers without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach affecting their data.
Return / Deletion on Termination
Return and deletion of personal data are governed by the executed agreement and applicable legal obligations. Contact privacy@gorefer.io to confirm export access, data scope and deletion completion; account cancellation does not automatically purge all records.
Audit Rights
Customers may request audit information (questionnaires, certifications) once per year. On-site audits require 30 days notice and cost reimbursement.
International Transfers
Confirm the applicable EEA and UK transfer mechanisms, parties and service scope in the executed agreement.
Standard Contractual Clauses (SCCs)
Updated September 2026
2021 EU SCCs (Controller-to-Processor)
Ask which transfer mechanism applies to your data, including whether the 2021 EU Standard Contractual Clauses and the appropriate module are incorporated. Request applicable transfer-impact and UK-transfer documentation rather than assuming every provider agreement includes it.
Request Your DPA
Updated September 2026
Request the available DPA through the Trust Portal and confirm execution with your firm. Enterprise customers needing to negotiate custom terms should contact their account manager or email legal@gorefer.io.