Skip to content

GoRefer Trust Center

Data Processing Agreement

Updated September 2026

This page summarizes data-processing topics to review when requesting a GoRefer DPA. The terms that apply are those in the agreement actually executed with your firm. Request available terms, transfer provisions and review of your use case through the Trust Portal.

GDPR Art. 28
Transfer terms on request
Privacy terms on request

DPA Availability by Plan

Updated September 2026

Growth Plan

  • Standard GoRefer DPA

  • Review scope against GDPR Article 28

  • Request applicable transfer terms

  • Confirm applicable UK transfer provisions

  • Request via Trust Portal

Scale Plan

  • Request applicable DPA and privacy terms

  • Discuss any BAA requirement before sharing protected health information

  • Confirm review timing with our team

  • Route legal questions through the Trust Portal

  • Request via Trust Portal

Enterprise Plan

  • Custom DPA negotiation supported

  • Legal review and redlines accepted

  • Discuss any BAA requirement with our team

  • Confirm supported execution options

  • Dedicated Customer Success contact

Key DPA Clauses Summary

Updated September 2026

The following summarizes topics and published policy positions to review with the agreement. The authoritative provisions are those actually executed with your firm; request confirmation of scope, notice periods and audit rights.

Subject Matter & Duration

GoRefer processes personal data on behalf of the customer (the Controller) solely to provide the GoRefer platform services. Processing continues for the duration of the subscription agreement.

Nature and Purpose of Processing

Storage and retrieval of tax referral and commission management data; AI-assisted workflow processing; transactional email delivery; analytics.

Categories of Data Subjects

Tax professionals, their clients, and administrative staff within the customer's firm.

Categories of Personal Data

Identity data, contact information, professional credentials, tax client records (including PII), authentication data, usage logs.

Controller Instructions

GoRefer processes personal data only on documented instructions from the customer. Instructions provided via product configuration, API calls, and account settings.

Sub-processor Management

GoRefer maintains a list of authorized sub-processors. New sub-processors are notified 30 days in advance. Customers may object in writing.

Security Measures (Art. 32 GDPR)

Supported sensitive-field encryption, HTTPS, authentication and role controls, as described on the Security page. Details of storage, security testing and monitoring are available on request.

Data Subject Rights Assistance

GoRefer provides mechanisms and reasonable assistance to enable customers to respond to data subject rights requests (access, erasure, portability, restriction).

Data Breach Notification

GoRefer notifies customers without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach affecting their data.

Return / Deletion on Termination

Return and deletion of personal data are governed by the executed agreement and applicable legal obligations. Contact privacy@gorefer.io to confirm export access, data scope and deletion completion; account cancellation does not automatically purge all records.

Audit Rights

Customers may request audit information (questionnaires, certifications) once per year. On-site audits require 30 days notice and cost reimbursement.

International Transfers

Confirm the applicable EEA and UK transfer mechanisms, parties and service scope in the executed agreement.

Standard Contractual Clauses (SCCs)

Updated September 2026

2021 EU SCCs (Controller-to-Processor)

Ask which transfer mechanism applies to your data, including whether the 2021 EU Standard Contractual Clauses and the appropriate module are incorporated. Request applicable transfer-impact and UK-transfer documentation rather than assuming every provider agreement includes it.

Request Your DPA

Updated September 2026

Request the available DPA through the Trust Portal and confirm execution with your firm. Enterprise customers needing to negotiate custom terms should contact their account manager or email legal@gorefer.io.