Version 1.1, effective September 2, 2026. This Addendum forms part of the Wallace Understudy Terms of Service and is signable as a standalone exhibit. Capitalized terms not defined here have the meanings given in the Terms of Service. Wallace Understudy was formerly marketed as Wallace Succession; documents signed under that name refer to the same service.
Most vendor data addenda begin by conceding that the vendor holds the customer's client data and then describe how it will be protected. This one does not, because the premise is different.
Wallace Understudy is built so that client data never reaches Wallace. This Addendum first states that architecture as a binding commitment, then applies service provider and processor protections to the narrow categories of information Wallace does hold, and finally provides the specific undertakings that regulated buyers need in order to satisfy their own obligations without going back to their clients.
The commercial point, stated plainly.
Because Wallace does not receive Client Data, a subscribing firm should not need to obtain client consent, issue a client-facing disclosure, or secure any third party's approval as a condition of using the Services. Wallace will never make any of those a condition of service. Each firm must still reach its own conclusion under its own professional rules. This Addendum is designed to give a firm's counsel and compliance officer what they need to reach that conclusion quickly.
(a) Customer Data. Firm Documents, De-identified Patterns, Meeting Content, Practice Memory items, interview answers, Playbook content, queries, chats, source settings, and Output associated with Customer's account, together with Personal Information about Users and Subjects.
(b) Client Data. Information concerning Customer's own clients, customers, matters, engagements, or projects, including personal information, financial records, transaction and custodial data, tax return information, privileged material, and client communications. Client Data is not Customer Data and is not received by Wallace.
(c) Personal Information. Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable natural person, as defined under applicable U.S. privacy law, including "personal information," "personal data," and "nonpublic personal information."
(d) Security Incident. A confirmed unauthorized access to, acquisition of, use of, or disclosure of Customer Data in Wallace's possession or control. Unsuccessful attempts, pings, scans, and routine failed log-ins are not Security Incidents and are not individually reportable.
(e) Roles. Customer is the business, controller, and owner of Customer Data. Wallace is a service provider and processor with respect to Customer Data and acts only on Customer's documented instructions. Wallace is an independent business and controller only as to its own account registration, billing, support, marketing, and Service Telemetry records, and only for the limited purposes stated in the Privacy Policy.
(a) On-device processing. Wallace warrants that the Services are engineered so that client data files supplied for capture are read and analyzed by code executing in the User's browser on the User's device, and that the contents of those files are not transmitted to, received by, or persisted on Wallace-controlled infrastructure. For a file layout the Services do not recognize, the column headings alone may be transmitted so that a mapping can be suggested; cell contents are not. Meeting and call transcripts supplied by a Subject are pseudonymized on the Subject's device, with names, account identifiers, and balances replaced before any transmission, and the transcript itself is not persisted by Wallace. Where Customer elects to enable Practice Memory, the pseudonymized version is retained as a Customer-visible, individually deletable item.
(b) Non-receipt of Client Data. Wallace does not request, require, receive, store, process, or have access to Client Data. Wallace has no technical means of retrieving Client Data from Customer's environment and will not build one.
(c) The re-identification key. The key that would permit a De-identified Pattern to be linked to an identified individual is generated and retained exclusively on the User's device and is not transmitted to Wallace. Wallace does not hold, request, escrow, or have any means of reconstructing it, and it is technically inaccessible to Wallace. Because that key exists, Wallace describes the patterns as de-identified rather than anonymized, and treats them as Customer Data under this Addendum.
(d) No re-identification. Wallace will not attempt to re-identify any individual from De-identified Patterns, will not permit any subprocessor to do so, and will contractually prohibit it. Wallace maintains a documented assessment of re-identification risk for the de-identification scheme, refreshes it at least annually, and will make its conclusions available to Customer on request under confidentiality.
(e) No unilateral change. Wallace will not modify the Services in a way that causes Client Data to be transmitted to or stored by Wallace without at least sixty (60) days' prior written notice to Customer, which may terminate without penalty and receive a pro rata refund. Wallace will not represent that a change is immaterial where its effect is to move processing off the device.
(f) Verification. On request, Wallace will provide a data-flow diagram identifying every path by which data leaves the User's device, an inventory of network destinations contacted by the client-side application, and, once available, a third-party attestation of the on-device boundary. Customer may verify egress behavior in its own environment using standard network inspection tools, and Wallace's Terms of Service do not prohibit doing so.
The architecture protects Customer only if Customer respects it. Customer will not upload Client Data as a Firm Document and will not enter client names, account numbers, tax identification numbers, or other direct client identifiers into the chat, research, or interview interfaces. Wallace will make available administrative controls and, where technically feasible, automated detection to assist Customer in enforcing this internally. Information Customer supplies in breach of this Section is handled under Sections 3 through 9 like any other Customer Data, but the commitments in Section 2 will not have applied to it.
(a) Documented instructions. Wallace processes Customer Data only on Customer's documented instructions, which consist of this Addendum, the Terms of Service, the applicable Order Form, and Customer's use of the Services' configuration options. Wallace will notify Customer if it believes an instruction violates applicable law.
(b) Enumerated business purposes. The specific business purposes for which Customer discloses Customer Data to Wallace, and the only purposes for which Wallace may process it, are: (i) distilling Firm Documents and pseudonymized Meeting Content into candidate items for the Subject's confirmation, and compiling, updating, and version-controlling the Playbook; (ii) running validation against De-identified Patterns and presenting the results; (iii) operating the chat and research interfaces, grading checks, generating onboarding tracks, operating the continuity console, and routing questions to the Subject; (iv) maintaining Practice Memory where Customer has enabled it; (v) provisioning, authenticating, and administering Users, seats, and continuity partner access; (vi) providing technical support requested by Customer; (vii) detecting, preventing, investigating, and responding to security incidents, fraud, and abuse; (viii) maintaining audit and access logs; (ix) billing and collection; and (x) complying with legal obligations. No other purpose is authorized.
(c) Prohibited processing. Wallace will not: (i) sell or share Customer Data, as "sell" and "share" are defined in California Civil Code sections 1798.140(ad) and (ah); (ii) retain, use, or disclose Customer Data for any purpose other than the business purposes enumerated above, including any commercial purpose not specified; (iii) retain, use, or disclose Customer Data outside the direct business relationship between Wallace and Customer; (iv) combine Customer Data with personal information received from or on behalf of any other person, or collected from its own interactions with any consumer, except as expressly permitted by applicable law to detect security incidents or resist malicious action; or (v) use Customer Data to train, fine-tune, evaluate, benchmark, or improve any artificial intelligence or machine learning model, whether in identified, de-identified, or aggregated form.
(d) Cross-customer prohibition. Wallace will not use Customer Data to build or improve services provided to any other person, and will not create cross-firm comparisons, industry benchmarks, or peer cohorts from Customer Data. Where Wallace uses information to improve the Services, it will do so only from Service Telemetry as defined in Section 3(e).
(e) Service Telemetry. Wallace collects operational data about the software itself: feature usage counts, session and page metrics, error and exception rates, latency and performance measurements, and browser and device type. Wallace does not configure telemetry to capture the substance of Firm Documents, De-identified Patterns, Meeting Content, Practice Memory, Playbook rules, queries, or Output, and will not do so. Telemetry is not Customer Data for purposes of the use restrictions in Section 3(c)(v), and Wallace confirms telemetry does not and will not include tax return information, nonpublic personal information, or privileged material.
(f) Compliance and notice of inability. Wallace will comply with the obligations applicable to a service provider and processor under applicable U.S. privacy law, will provide the same level of privacy protection those laws require of Customer, and will notify Customer promptly if it determines it can no longer meet those obligations.
(g) Confidentiality of personnel. Wallace personnel with access to Customer Data are bound by written confidentiality obligations that survive termination of employment or engagement, are subject to background screening consistent with role sensitivity, and receive privacy and security training at onboarding and annually.
(a) Authorization. Customer authorizes the subprocessors listed in Exhibit B. Wallace will maintain a current list and will give Customer at least thirty (30) days' notice before engaging a new subprocessor that will process Customer Data.
(b) Objection. Customer may object to a new subprocessor within thirty (30) days on reasonable data protection grounds. The parties will work in good faith toward a resolution. If none is reached, Customer may terminate the affected Services and receive a pro rata refund of prepaid, unused fees.
(c) Flow-down and liability. Wallace will impose on each subprocessor written obligations no less protective than this Addendum, including the prohibitions on sale, sharing, secondary use, model training, and re-identification. Wallace remains fully liable to Customer for each subprocessor's performance.
(d) United States only. All processing and storage of Customer Data occurs within the United States. Wallace will not permit access to Customer Data from outside the United States, including by support, engineering, or contractor personnel, without Customer's prior written consent.
Wallace will maintain the administrative, technical, physical, and organizational safeguards described in Exhibit A, which are appropriate to the nature of the information and consistent with the requirements of Regulation S-P, the Federal Trade Commission Safeguards Rule, and California Civil Code section 1798.81.5. Wallace may update Exhibit A but will not materially reduce the overall level of security during a subscription term.
(a) Notification within 72 hours. Wallace will notify Customer of a Security Incident without undue delay and in any event no later than seventy-two (72) hours after Wallace confirms it. Wallace acknowledges that this commitment exists so that Customer can satisfy Regulation S-P, the Safeguards Rule, and state breach notification law, and that Customer is entitled to rely on it.
(b) Contents. The notice will describe, to the extent then known and with updates as more is learned: the nature of the incident, the date or range of dates, the categories and approximate volume of information involved, the individuals or accounts affected, the likely consequences, the containment and remediation steps taken and planned, and a point of contact.
(c) Cooperation. Wallace will investigate, contain, and remediate at its own expense, preserve relevant evidence and logs, and provide the information and assistance Customer reasonably needs to meet its own obligations, including its obligation to notify affected individuals within thirty (30) days under Regulation S-P and within the shortest period any applicable state law requires.
(d) Customer controls downstream notice. Wallace will not notify Customer's clients, Customer's regulators, or any media on Customer's behalf, and will not identify Customer publicly in connection with an incident, without Customer's prior written consent, unless Wallace is independently required by law to do so. Customer controls the content, timing, and method of any notice to its own clients and regulators.
(e) Root cause. Within thirty (30) days of closing an incident, Wallace will provide Customer a written root cause analysis and corrective action plan.
(f) No admission. Notification is not an acknowledgment of fault or liability.
If Wallace receives a subpoena, warrant, court order, civil investigative demand, regulatory request, or other legal process seeking Customer Data, Wallace will, unless legally prohibited: notify Customer promptly and before producing anything; provide Customer a copy of the demand; give Customer a reasonable opportunity to object, move to quash, or seek a protective order; assert applicable privileges and confidentiality protections on Customer's behalf pending resolution; disclose only the minimum required; and reasonably cooperate with Customer's efforts to limit disclosure, at Customer's expense. Where notice is legally prohibited, Wallace will seek to lift the prohibition and will notify Customer as soon as permitted. Wallace will maintain a record of demands received and, to the extent lawful, will report the number received on request.
(a) During the term. Customer may delete any stored Firm Document or Practice Memory item at any time, may erase all twin content from the Services, and may exclude any statement from the Playbook. Chat and research conversations are retained for thirty (30) days. Wallace otherwise retains Customer Data for the subscription term unless Customer directs otherwise.
(b) Export. Customer may export its Playbook and stored Firm Documents at any time during the term and for thirty (30) days after termination, in a documented, machine-readable format, at no charge and without precondition, including by downloading the twin bundle (every Playbook version and its exclusions), which Customer may re-import later. Wallace claims no proprietary or derivative-works interest in the exported material.
(c) Deletion. Following the export window, Wallace will delete Customer Data from active systems within thirty (30) days and from backups on a rolling cycle not exceeding thirty-five (35) days, and will certify deletion in writing on request. Wallace may retain records it is independently required by law to keep, and Service Telemetry, in each case subject to continuing confidentiality obligations and the use restrictions in this Addendum.
(d) Extended retention on instruction. Where Customer is subject to a legal or professional retention obligation, Wallace will, on written instruction, retain the specified categories for the specified period. Wallace's systems support, at minimum: retention and export of inputs, outputs, and configuration records for four (4) years, for firms subject to California employment recordkeeping requirements; retention of records for three (3) years, for firms subject to Colorado automated decision-making recordkeeping; and durable, exportable, tamper-evident records of queries and answers for five (5) or seven (7) years, for firms subject to accounting or audit workpaper retention requirements.
(e) Legal hold. On written notice of a litigation hold, Wallace will suspend deletion of the identified Customer Data until Customer releases the hold.
(f) Assistance with individual rights. Wallace will, at no additional charge, provide the tooling or assistance Customer reasonably needs to respond to a request from a User or Subject to access, correct, delete, or port personal information. If Wallace receives such a request directly, it will not respond substantively on Customer's behalf but will promptly forward it to Customer.
(g) Assistance with assessments and notices. Wallace will provide, at no additional charge and on reasonable notice: information Customer needs for a privacy or data protection impact assessment; documentation of the Services' intended uses, known limitations, categories of data processed, and human review guidance sufficient to support Customer's vendor documentation obligations; and a completed input sheet giving the vendor name, product name, purpose, decision types, and data categories that Customer needs to prepare a workforce notice about the use of artificial intelligence.
(a) Standing package. On request Wallace will provide its current security questionnaire responses, architecture and data-flow documentation, subprocessor list, incident response summary, penetration test summary, and, once obtained, its SOC 2 Type II report or equivalent third-party attestation.
(b) Verification. Customer may, no more than once in any twelve-month period and on thirty (30) days' notice, take reasonable and appropriate steps to verify that Wallace is using Customer Data consistently with its obligations, through written questionnaire, documentary review, or a call with Wallace's security personnel. Where Customer's regulator or professional rules require deeper verification, or following a Security Incident affecting Customer, Customer may conduct or commission an assessment at its own expense, subject to reasonable confidentiality and scheduling terms, and Wallace will not treat that assessment as a breach of its Terms of Service.
(c) Remediation. If verification identifies unauthorized use of Customer Data, Wallace will, on notice, take reasonable and appropriate steps to stop and remediate it.
(d) Regulator access. Where Customer is subject to examination by a governmental or professional regulator with authority over Customer's use of the Services, Wallace will provide the regulator with reasonable access to relevant records and personnel concerning the Services, subject to confidentiality protections.
The following riders apply automatically to Customers in the identified categories. They add to, and do not limit, the rest of this Addendum.
This rider applies where Customer is registered with the Securities and Exchange Commission or a state securities authority as an investment adviser, is a broker-dealer, or is otherwise a "financial institution" under the Gramm-Leach-Bliley Act.
(a) Service provider status. Wallace acknowledges it is a service provider to Customer for purposes of Regulation S-P, 17 C.F.R. Part 248, and will take appropriate measures to protect against unauthorized access to or use of customer information.
(b) 72-hour notice. Wallace will notify Customer as soon as possible and no later than seventy-two (72) hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by Wallace, as required by Regulation S-P.
(c) Volume of nonpublic personal information. Because Wallace does not receive Client Data, the nonpublic personal information of Customer's advisory clients in Wallace's possession is designed to be nil. Wallace will notify Customer if it becomes aware that this is not the case.
(d) Annual certification. On request, and at least annually, Wallace will provide a written certification that it maintains the safeguards in Exhibit A and has secure methods in place to protect information against unauthorized access, in a form Customer can retain in its vendor due diligence file.
(e) Books and records. Wallace will retain and, on request, produce to Customer records relating to the Services that Customer is required to preserve under Rule 204-2 under the Investment Advisers Act, in a format that permits Customer to satisfy its own retention obligations.
(f) No advisory activity. Wallace confirms that the Services do not provide advice regarding securities, do not produce recommendations or analyses concerning any security or category of securities, and do not exercise discretion over or take custody of any client assets. Wallace maintains a product boundary excluding securities-identifying and securities-advisability content from Playbook rules and validation logic. Content retrieved from a Source that Customer has enabled is the publisher's, is cited as such, and is not a recommendation by Wallace.
(g) Governance record. The Services record which Sources Customer has enabled and who changed each setting and when, and Wallace will produce that record on request in support of Customer's own documentation of its use of artificial intelligence.
This rider applies where Customer is a law firm, a legal department, or an entity whose Firm Documents may contain information relating to the representation of a client.
(a) Purpose and agency. Customer engages Wallace to assist Customer's lawyers in the organization and retrieval of Customer's own practice methodology, in support of the rendition of legal services by those lawyers. Wallace acts as an agent of Customer's lawyers for that purpose.
(b) Confidentiality co-extensive with Rule 1.6. Wallace will treat all Customer Data as confidential to the same extent Customer's lawyers are obliged to protect information relating to the representation of a client, and acknowledges that such information may be subject to the attorney-client privilege and the work product doctrine.
(c) No training, no cross-matter access. Wallace does not use Customer Data to train or improve any model, does not permit any subprocessor to do so, maintains per-tenant isolation with no cross-customer retrieval, and supports matter-level access restrictions and ethical walls configured by Customer.
(d) Non-waiver. The parties do not intend any disclosure under this Agreement to waive any privilege or protection. Wallace will assert applicable privileges on Customer's behalf pending resolution if served with legal process, and will give Customer notice before producing anything, as provided in Section 7.
(e) No proprietary claim. Wallace asserts no proprietary or derivative-works right in any information Customer submits or in the Playbook compiled from it, and will return or delete it as provided in Section 8.
(f) Client guideline compliance. On request, Wallace will complete Customer's outside counsel guideline questionnaire and will accept reasonable flow-down of a client-imposed restriction that is consistent with this Addendum, at no additional charge.
(g) Pricing model. The Services are priced as a periodic subscription and not on a per-query, per-matter, or outcome-contingent basis, so that Customer may treat the cost as firm overhead.
(h) No legal services. Wallace does not practice law, does not provide legal advice, and does not exercise independent legal judgment. The Services answer only from rules a lawyer at Customer has authored and signed, and respond that a topic is not covered rather than generate an unsupported answer.
This rider applies where Customer is a certified public accounting firm, an enrolled agent, a tax return preparer, or an entity whose Firm Documents may contain tax return information.
Configuration requirement for tax practices.
Where Customer's practice includes the preparation of tax returns, Customer must operate the Services in the on-device configuration, in which no Firm Document or other material containing tax return information is uploaded to Wallace infrastructure. Wallace will make that configuration available and will confirm it in writing. This is a condition of use, not a recommendation, and it exists because Internal Revenue Code section 7216 makes an unauthorized disclosure or use of tax return information a criminal offense.
(a) Confidentiality by contract. This Addendum constitutes a contractual agreement with a third-party service provider to maintain the confidentiality of confidential client information and to provide reasonable assurance that appropriate procedures are in place to prevent unauthorized release, for purposes of AICPA Code of Professional Conduct interpretation 1.700.040. Customer is therefore not required to obtain specific client consent under that interpretation as a condition of engaging Wallace.
(b) Section 7216. To the extent any tax return information were nonetheless to reach Wallace, Wallace: (i) acts solely as a person under contract with Customer in connection with the programming, maintenance, repair, testing, or procurement of software, and only to the extent necessary to provide the contracted services, within the meaning of Treasury Regulation section 301.7216-2(d)(2); (ii) will not use or disclose tax return information for any purpose other than providing the contracted services, and specifically will not use it for model training, analytics, benchmarking, marketing, or product development; (iii) will not permit access from outside the United States; and (iv) will, on request, supply a consent form meeting the requirements of Revenue Procedure 2013-14 naming Wallace specifically, for Customers whose counsel elects to obtain client consent as a precaution.
(c) FTC Safeguards Rule. Wallace acknowledges that Customer is a financial institution under the Safeguards Rule, 16 C.F.R. Part 314, and that Customer must select and retain service providers capable of maintaining appropriate safeguards. Wallace maintains the safeguards in Exhibit A, including encryption in transit and at rest, multi-factor authentication for information system access, and secure disposal, and will provide the periodic assessment materials Customer needs under section 314.4(f). Wallace's seventy-two hour notice commitment is set so that Customer can meet its own thirty-day Federal Trade Commission notification deadline.
(d) Quality management documentation. On request Wallace will provide a documentation pack describing the Services' intended use, limitations, controls, and monitoring approach, suitable for inclusion in Customer's quality management documentation under Statement on Quality Management Standards No. 1, and for review by a peer reviewer.
(e) Workpaper retention. Where Output informs conclusions on an engagement, Wallace will support durable, exportable, tamper-evident retention of the relevant queries and answers for the period Customer specifies under Section 8(d).
(f) Independence. The Services are a tool Customer operates. Wallace does not perform management functions, does not design or implement systems of internal control for Customer, and does not make decisions on Customer's behalf. Wallace will provide information Customer's independence group requires to evaluate the engagement against nonattest services rules.
This rider applies where Customer is an architecture, engineering, construction, land services, trades, or similar business without a sector privacy regulator.
(a) Trade secrets. Wallace acknowledges that Customer's methodology, bid and pricing histories, vendor relationships, and Playbook are or may be trade secrets; that this Addendum forms part of Customer's reasonable measures to maintain their secrecy; and that Wallace will not use them for any purpose other than providing the Services to Customer. Wallace will not use Customer's methodology to develop, improve, or inform any product or service provided to any other person, including a competitor of Customer.
(b) No responsible charge. The Services do not perform engineering, architecture, surveying, or any other licensed professional service, produce no sealed or stamped work product, and do not relieve any licensed professional of responsible charge. Output is guidance drawn from Customer's own documented methodology.
(c) Flow-down. Where Customer is subject to owner-imposed or government confidentiality obligations, including controlled unclassified information requirements, Wallace will accept reasonable flow-down terms consistent with this Addendum.
(d) Title and settlement services. If Customer provides title, escrow, or settlement services, Customer is a financial institution under the Gramm-Leach-Bliley Act and Rider C, paragraph (c), applies in addition to this rider.
Wallace maintains a written information security program, reviewed at least annually and after any material change, covering the following. Wallace may enhance these measures but will not materially reduce the overall level of protection during a subscription term.
Governance. Written information security program with a named owner. Annual risk assessment. Annual review and update of policies. Documented incident response plan tested at least annually. Documented vendor due diligence and annual re-review of each subprocessor.
Access control. Least-privilege, role-based access. Multi-factor authentication required for all administrative and production access. Unique named accounts, no shared credentials. Access reviewed at least quarterly and revoked within twenty-four hours of role change or departure. Production access limited to named personnel with a documented business need and logged.
Tenant isolation. Row-level security policies scoping every record to a single Customer. No cross-customer retrieval at the application or retrieval layer. Isolation controls tested as part of the release process.
Encryption. TLS 1.2 or higher for all data in transit. AES-256 or equivalent for data at rest, including databases, object storage, and backups. Key management by the platform provider with access restricted to production roles.
Application security. Secure development lifecycle with peer code review. Dependency and vulnerability scanning in the build pipeline. Annual third-party penetration test with remediation of critical and high findings on a defined timeline. Separation of development, staging, and production environments, with no production data in non-production environments.
Logging and monitoring. Centralized logging of authentication, authorization, administrative action, data export, and error events. Alerting on anomalous access patterns and privilege escalation. Log retention of at least twelve months. Logs protected against alteration.
Data handling. On-device processing of client data files and on-device pseudonymization of transcripts as described in Section 2. No offshore access. No production data on personal or unmanaged devices. Secure disposal of media and cryptographic erasure of storage on decommission.
Resilience. Automated encrypted backups with a rolling retention cycle not exceeding thirty-five days. Documented recovery objectives and at least annual restoration testing. Infrastructure hosted with providers maintaining recognized third-party security certifications.
Personnel. Background screening consistent with role sensitivity. Written confidentiality agreements surviving termination. Security and privacy training at onboarding and annually. Documented offboarding checklist including immediate credential revocation.
Endpoints. Full-disk encryption, screen lock, automatic patching, and endpoint protection on all devices with access to production systems or Customer Data.
Certification. Wallace is pursuing SOC 2 Type II. Wallace will notify Customers when the report is available and will provide it under confidentiality on request. Wallace will not represent that it holds a certification it has not obtained.
Current as of September 2, 2026. The authoritative list is this Exhibit as published at wallaceunderstudy.io/legal/data-protection-addendum. Wallace will give at least thirty (30) days' notice before adding a subprocessor that processes Customer Data.
Anthropic PBC. AI model inference Location: United States Data processed: De-identified Patterns, stored Firm Document text, pseudonymized Meeting Content, Practice Memory items where enabled, interview answers, queries. Accessed under commercial terms prohibiting training on customer content, with short retention for trust and safety screening only.
Supabase. Database and authentication Location: United States Data processed: Account data, Firm Documents, Playbooks, De-identified Patterns, Practice Memory where enabled, chats, logs. Row-level security scopes every record to one Customer. Magic-link sign-in; no stored passwords.
Vercel. Application hosting and delivery Location: United States Data processed: Application traffic, request metadata, Service Telemetry. Customer content transits but is not persisted.
Resend. Transactional email Location: United States Data processed: Recipient email address and message content for account, security, billing, and service notices, invitation links, routed-question notifications, and digests.
Stripe. Payment processing Location: United States Data processed: Billing contact, subscription plan, and payment instrument data. Wallace does not store full card numbers.
This Addendum is effective as of the effective date of the Order Form to which it relates, or on the date Customer accepts the Terms of Service, whichever is earlier. It may be executed in counterparts and accepted electronically.
Signature blocks for Wallace Finance Co. and Customer appear in the downloadable version of this Addendum and in each Order Form. A copy of this Addendum in Word format is available on request from support@wallacefinance.io.
Wallace Finance Co., 8 The Grn, Ste B, Dover, DE 19901. Security matters, privacy questions, and legal notices: support@wallacefinance.io.