DigitDigit
Product
MRP SOFTWARE
Inventory management
Keep stock accurate across every location and stage.
Purchase order management
Create and track POs without emails or spreadsheets.
Warehouse management
Automate receiving, storage, and fulfillment.
Traceability
Track everything from supplier to shipment without guesswork.
MANUFACTURING ERP
Bill of materials
Build, edit, and version your BOMs with full flexibility.
Production scheduling
Plan and adjust work orders without walking the floor.
Shop floor control
See what's running, what's late, and what's next.
Serial number tracking
Follow every item from build to delivery.
CRM
Sales order management
Handle quotes, orders, and fulfillment all in one place.
Customer portals
Give customers live order updates, invoices, and shipment details.
Pipeline management
Track deals from first contact to close with less admin in between.
Price lists
Set flexible, automated pricing for every customer or product line.
INTEGRATIONS
QuickBooks Online
Xero
NetSuite
QuickBooks Desktop
Shopify
WooCommerce
Amazon
eBay
All features
↗
Simply capable. Learn what Digit can do.
MCP
↗
Ask questions and take action from AI assistants.
API
↗
Build custom integrations with our GraphQL API.
All integrations
↗
Connect Digit to the tools you already use.
Industries
Food & beverage
Plastics & rubber
Distribution
Packaging
Cosmetics & beauty
Chemicals
Apparel
Recycling
Furniture & woodworking
Electronics
All Industries
↗
Digit empowers companies of all sizes
Pricing
Resources
Case studies
Blog
Learning center
Onboarding
Company
About us
Careers
Contact us
In the news
Sign inTalk to SalesStart Demo
LEGAL

Data Processing Agreement

Last Modified: June 26, 2026

BY INDICATING ACCEPTANCE OF THIS AGREEMENT OR ACCESSING OR USING ANY DIGIT SERVICES, CUSTOMER IS ACCEPTING ALL OF THE TERMS AND CONDITIONS OF THIS AGREEMENT. CUSTOMER AGREES THAT THIS AGREEMENT IS ENFORCEABLE LIKE ANY WRITTEN AGREEMENT SIGNED BY CUSTOMER.

Pursuant to the Terms of Service (“Agreement”) between the entity or person placing the order for or accessing Digit’s Services on behalf of itself and its affiliates (“Customer”) and Digit Technologies Inc. (“Vendor”) (each a “Party”; collectively the “Parties”), and in furtherance of obligations under applicable U.S. federal and state privacy laws and their implementing regulations, as amended or superseded from time to time, that apply generally to the processing of Customer Personal Information (“Privacy Laws”), the Parties hereby adopt this Data Processing Addendum (“Addendum” or “DPA”) for so long as Vendor maintains and processes Customer Personal Information on behalf of Customer. This Addendum prevails over any conflicting terms of the Agreement.

1. Definitions.

For the purposes of this Addendum--

The capitalized terms used in this Addendum and not otherwise defined in this Addendum shall have the definitions given to the same or similar terms set forth in the applicable Privacy Laws.

“Customer Personal Information” means Personal Information provided by Customer to, or which is collected on behalf of Customer by, Vendor to provide services to Customer pursuant to the Agreement. For the avoidance of doubt, Customer Personal Information does not include Personal Information that has been Deidentified or Aggregated.

“Customer-Connected AI Provider” means a third-party artificial intelligence tool, agent, or assistant (for example Claude, ChatGPT, or Microsoft Copilot) that Customer or its authorized users connect to the Services using Customer’s own credentials, including through the Model Context Protocol or comparable means.

2. Scope, Roles, and Termination.

2.1Applicability - This Addendum applies only to Vendor’s Processing of Customer Personal Information for the nature, purposes, and duration set forth in Appendix A.

2.2Roles of the Parties - For the purposes of the Agreement and this Addendum, Customer is the Party responsible for determining the purposes and means of Processing Customer Personal Information and appoints Vendor to Process Customer Personal Information on behalf of Customer for the limited and specific purposes set forth in Appendix A.

2.3Obligations at Termination - Upon termination of the Agreement, except as set forth therein or herein, Vendor will discontinue Processing and destroy or return Customer Personal Information in its or its subcontractors and sub-processors possession without undue delay. Vendor may retain Customer Personal Information to the extent required by law but only to the extent and for such period as required by such law and always provided that Vendor shall ensure the confidentiality of all such Customer Personal Information.

3. Compliance.

3.1Compliance with Obligations - In addition to the representations and warranties set forth in the Agreement, Vendor, its employees, agents, subcontractors, and sub-processors (a) shall comply with the obligations of the Privacy Laws, (b) shall provide the level of privacy protection required by the Privacy Laws, (c) shall provide Customer with all reasonably-requested assistance to enable Customer to fulfill its own obligations under the Privacy Laws, and (d) understand and shall comply with this Addendum.

3.2Compliance Assurance - Customer has the right to take reasonable and appropriate steps to ensure that Vendor uses Customer Personal Information consistent with Customer’s obligations under the Privacy Laws.

3.3Compliance Remediation - Vendor shall promptly notify Customer after determining that it can no longer meet its obligations under the Privacy Laws. Upon receiving notice from Vendor in accordance with this subsection, Customer may direct Vendor to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Information.

4. Security.

4.1Vendor shall implement and maintain no less than reasonable security procedures and practices, appropriate to the nature of the information, to protect Customer Personal Information from unauthorized access, destruction, use, or disclosure (“Security Incident”) and to preserve the security and confidentiality of Consumer Personal Information in accordance with the Privacy Laws.

4.2Upon becoming aware of a Security Incident, Vendor shall notify Customer without undue delay and shall provide timely updates and information relating to the Security Incident as it becomes known or as is reasonably requested by Customer.

5. Restrictions on Processing.

5.1Limitations on Processing - Vendor will Process Customer Personal Information solely as instructed in the Agreement and this Addendum. Except as expressly permitted by the Privacy Laws, Vendor is prohibited from (i) Selling or Sharing Customer Personal Information, (ii) retaining, using, or disclosing Customer Personal Information for any purpose other than for the specific purpose of performing the Services specified in Appendix A, (iii) retaining, using, or disclosing Customer Personal Information outside of the direct business relationship between the Parties, and (iv) combining Customer Personal Information with Personal Information obtained from, or on behalf of, sources other than Customer.

5.2Subcontractors; Sub-processors – Vendor’s current subcontractors and sub-processors are set forth in Appendix B. Vendor shall notify Customer of any intended changes concerning the addition or replacement of subcontractors or sub-processors. Further, Vendor shall ensure that Vendor’s subcontractors or sub-processors who Process Customer Personal Information on Vendor’s behalf agree in writing to the same or equivalent restrictions and requirements that apply to Vendor in this Addendum and the Agreement with respect to Customer Personal Information, as well as to comply with the Privacy Laws.

5.3Customer-Connected AI Providers – As an optional, separately elected add-on feature, the Services permit Customer and its authorized users to connect third-party artificial intelligence tools, agents, or assistants (for example Claude, ChatGPT, or Microsoft Copilot) to the Services using Customer’s own credentials, including through the Model Context Protocol (“MCP”) or comparable means (“Customer-Connected AI Providers”). This capability is not enabled by default and is not available to all Customers. Where Customer or its users elect to activate and use a Customer-Connected AI Provider, that provider acts at Customer’s direction and on Customer’s behalf and is not a sub-processor of Vendor under this Addendum. Customer is responsible for its use of any Customer-Connected AI Provider, for the instructions and data its users transmit to that provider, and for its own compliance, and that provider’s compliance, with the applicable provider terms and the Privacy Laws.

6. Consumer Rights.

6.1Vendor shall provide commercially reasonable assistance to Customer for the fulfillment of Customer’s obligations to respond to Privacy Laws-related Consumer rights requests regarding Customer Personal Information.

6.2Where applicable, Vendor shall enable Customer to comply with any Consumer request made pursuant to the Privacy Laws or, if necessary, Customer shall inform Vendor of any Consumer request made pursuant to the Privacy Laws that they must comply with and Customer shall provide Vendor with the information necessary for Vendor to comply with the request.

6.3Vendor shall not be required to delete any Customer Personal Information to comply with a Consumer’s request directed by Customer if retaining such information is specifically permitted by the Privacy Laws, in which case Vendor shall not use Customer Personal Information retained for any other purpose than provided for by that exception.

7. Sale of Information.

7.1The Parties acknowledge and agree that the exchange of Personal Information between the Parties does not form part of any monetary or other valuable consideration exchanged between the Parties with respect to the Agreement or this Addendum.

7.2Vendor will not (i) Sell or Share Customer Personal Information; (ii) retain, use, or disclose Customer Personal Information for any purpose other than the specific purpose of performing its obligations under the Agreement, including retaining, using, or disclosing the Customer Personal Information for a commercial purpose other than fulfilling its obligations under the Agreement;

8. Deidentified Information.

8.1Vendor shall: (i) take reasonable measures to ensure that Deidentified information derived from Customer Personal Information cannot be associated with a Consumer or household; (ii) publicly commit to maintain and use Deidentified information in Deidentified form and not to attempt to reidentify the Deidentified information, except as permitted by applicable Privacy Laws; and (iii) contractually obligate any recipients of the Deidentified information to comply with all provisions of this paragraph.

9. Changes to Applicable Laws.

9.1The Parties agree to cooperate in good faith to enter into additional terms to address any modifications, amendments, or updates to applicable statutes, regulations or other laws pertaining to privacy and information security, including, where applicable, the Privacy Laws.

10. Notifications.

10.1Customer will send all notifications, requests and instructions under this DPA to Company’s Data Protection Officer via email to help@digit-software.com. Vendor will send all notifications under this DPA to Customer’s contact indicated in the applicable ordering documentation.

11. Applicable law and jurisdiction.

11.1This Addendum is governed by and construed in accordance with the internal laws of the State of Delaware without giving effect to any choice or conflict of law provision or rule that would require or permit the application of the laws of any jurisdiction other than those of the State of Delaware. Any disputes relating to this Addendum will be subject to the exclusive jurisdiction of the federal courts of the United States or the courts of the State of Georgia, in each case located in the County of Walker, United States of America.

12. Modification of this DPA.

12.1This DPA may only be modified by a written amendment signed by both Vendor and Customer.

13. Invalidity and severability.

13.1If any provision of this DPA is found by any court or administrative body of a competent jurisdiction to be invalid or unenforceable, then the invalidity or unenforceability of such provision does not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.

Appendix A to Exhibit A - Processing Details

Nature and Purpose(s) of the Processing

  • To provide cloud inventory and manufacturing software for Customer
  • To provide the optional artificial intelligence features of the Services where elected by Customer, including the in-product onboarding assistant, document data extraction (for example optical character recognition of uploaded files and PDFs), and where Customer separately activates it, connectivity that allows Customer to use Customer-Connected AI Providers with the Services
  • To create Deidentified or Aggregate information using Customer Personal Information for the purpose of improving Vendor’s AI-powered product and as otherwise permitted by the Agreement
  • Debugging to identify and repair errors
  • Undertaking activities to verify or maintain the quality or safety of the Services
  • Complying with legal obligations

Customer Personal Information will be processed as necessary for Vendor to provide Services described in the Agreement.

Types of Customer Personal Information Subject to Processing

  • Names, addresses, contact information, identifiers, and any other information Customer’s users choose to provide to Vendor

Duration of Processing

  • For the duration of the Agreement, provided that Vendor may retain any Deidentified or Aggregate information indefinitely

Appendix B to Exhibit A - Sub-processor Details

To support delivery of Vendor’s services, Vendor may engage and use third parties as sub-processors to Process certain Customer Personal Information. This Appendix B provides information about the identity, location, and role of each sub-processor.

NameLocationPurpose
Clerk.comEU/USUser authentication and session management
Customer.ioEU/USSending transactional emails from the product on behalf of users
Rutter.comEU/USUniversal API to connect with accounting platforms (QuickBooks, Xero, Sage) and e-commerce platforms
Heroku (Salesforce)USApplication hosting platform on which the Digit product runs; all Customer Data processed by the application passes through Heroku infrastructure
AWS (S3)USObject storage for images and files uploaded by users
New RelicUSApplication performance monitoring and log management; processes application logs which may include indirect identifiers such as customer and organization IDs and IP addresses
SentryUSError tracking and telemetry; processes application logs and error reports which may include indirect identifiers such as customer and organization IDs and IP addresses
Slack.comUSSends automated alerts and reporting messages from the application to Digit's internal Slack workspace
Intercom.comUSIn-product chat and customer support widget for users to communicate with Digit from within the application
Segment.ioUSCustomer data platform used to load and route analytics and tracking events within the application
CSVBoxUS/EUIn-product import wizard used to facilitate customer data imports into the platform
SvixUSWebhook delivery infrastructure; transmits Customer Data payloads to Customer-designated webhook endpoints
Tiger Data / TimescaleUSTimescaleDB storage used for time-series and operational data
OpenAIUSPowers the in-product onboarding assistant and document data extraction (for example optical character recognition of uploaded files); processes Customer content submitted to these features
Anthropic (Claude)USUsed for AI model evaluation and may power certain AI Features; processes Customer content submitted to those features
AI-assisted data preparation tools (including but not limited to Google Gemini, Claude, and similar generative AI services)US/EUUsed by Digit staff to clean, reformat, and prepare Customer Data for import during onboarding. Data is processed at Digit staff direction. The specific tool used may vary by onboarding engagement.

For the avoidance of doubt, Customer-Connected AI Providers (as defined in Section 5.3) are not Vendor sub-processors. They are connected and used by Customer with Customer’s own credentials and act at Customer’s direction.

Ready to see what your operations could look like?

Explore Digit or book a call. In 15 minutes, you’ll know if it’s right for you.

Start DemoTalk to Sales

The next-gen ERP for makers and doers

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Features
Sales order managementShop floor controlMRP SoftwareManufacturing ERPPurchase order managementInventory managementProduction schedulingCRM
Industries
Food & beverage
Plastics & rubber
Distribution
Packaging
Cosmetics & beauty
Chemicals
Apparel
Recycling
Furniture & woodworking
Integrations
Webhooks
MCP
API
eBay
Amazon
WooCommerce
Shopify
NetSuite
Xero
Sage Intacct
Resources
BlogCase studiesIn the newsLearning centerOnboarding
Company
About usCareersContact us
Legal
Privacy PolicyData Processing AgreementTerms of ServicePartner Terms
digit
digit
digit
digit
digit
digit