Skip to content

Legal

Data Processing Addendum

The data protection terms between Bancroft and the advisory firms that license the platform. Written for the compliance file: roles, instructions, security measures, subprocessors, and incident notification.

Summary for compliance review

The Advisor Firm is the controller; Bancroft is the processor. Bancroft does not sell Personal Data, does not use it for advertising, and does not train AI models on it. Security incidents are reported to the Advisor Firm within 72 hours, the timeline the SEC's amended Regulation S-P expects of service providers. All processing occurs in the United States. Current providers are listed on the subprocessors page. A countersigned copy is available on request.

1. Scope and Roles of the Parties

This Data Processing Addendum (the "Addendum") supplements and forms part of the agreement between Bancroft Systems LLC ("Bancroft") and the advisory firm that has licensed the Bancroft platform (the "Advisor Firm") governing the Advisor Firm's use of the platform (the "Agreement"). It applies to Bancroft's processing of Personal Data on behalf of the Advisor Firm.

"Personal Data" means information relating to an identified or identifiable natural person that the Advisor Firm or its end users submit to the platform, including account details, household and family information, financial and asset information, beneficiary and fiduciary designations, healthcare-related preferences captured in advance directives, and documents generated or stored through the platform.

For Personal Data submitted through the platform by the Advisor Firm or its clients, the Advisor Firm is the controller (and, where the Advisor Firm is subject to the Gramm-Leach-Bliley Act, the financial institution) and Bancroft is the processor (or service provider). The Advisor Firm determines the purposes and means of processing; Bancroft processes only as described in this Addendum and the Agreement.

Bancroft acts as a controller with respect to a limited category of data it determines the purposes of on its own: Advisor Firm account and billing records, platform usage and security telemetry, and support correspondence. That processing is described in the Privacy Policy rather than governed by this Addendum.

Where this Addendum conflicts with the Agreement or the Disclosures and Terms with respect to the processing of Personal Data, this Addendum controls.

2. Instructions for Processing

Bancroft shall process Personal Data only (a) to provide, maintain, secure, and support the platform in accordance with the Agreement, (b) in accordance with the Advisor Firm's documented lawful instructions, including instructions given through the ordinary use and configuration of the platform, and (c) as required by applicable law, in which case Bancroft will inform the Advisor Firm of the legal requirement before processing unless prohibited from doing so by that law.

Bancroft shall not sell Personal Data, shall not share it for cross-context behavioral advertising, and shall not retain, use, or disclose it for any purpose other than performing the services, including for its own commercial purposes or outside the direct business relationship with the Advisor Firm.

Bancroft shall not use Personal Data to train, fine-tune, or otherwise develop machine learning or artificial intelligence models. Where an optional in-product AI feature is used, the content submitted to that feature is processed only to return the requested output, is subject to contractual prohibitions on provider training and retention, and is identified in the subprocessor list.

Bancroft shall promptly inform the Advisor Firm if, in its opinion, an instruction infringes applicable data protection law.

3. Confidentiality of Personnel

Bancroft shall ensure that personnel authorized to process Personal Data are bound by an obligation of confidentiality, receive access only on a need-to-know basis for a defined operational purpose, and have that access revoked when it is no longer required.

Administrative access to production systems is limited, individually attributed, and logged. Where Bancroft personnel access an Advisor Firm or client account for support purposes, that access is time-limited, recorded in an audit trail, and attributable to the individual who performed it.

4. Security Measures

Bancroft shall implement and maintain technical and organizational measures appropriate to the risk, designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures in place as of the date of this Addendum include:

Encryption of Personal Data in transit using industry-standard transport security, and encryption at rest at the storage layer. Content stored in the platform's encrypted vault feature is additionally protected with envelope encryption using AES-256-GCM, with per-item data encryption keys wrapped by a master key that supports rotation.

Access controls including role-based authorization, session expiration, session revocation, account lockout after repeated failed authentication attempts, and support for time-based one-time-password multi-factor authentication on all accounts.

A tamper-evident audit trail covering authentication events, administrative actions, permission and role changes, document generation and release, and access to sensitive records, retained under a documented retention floor.

Application-layer protections including rate limiting on state-changing endpoints, a content security policy, secrets management, dependency monitoring, and continuous error and anomaly monitoring.

Segregation of Advisor Firm data through tenant-scoped authorization enforced on every request, and database-level row security on tables exposed to any external interface.

Bancroft aligns its control environment to the SOC 2 Trust Services Criteria. As of the date of this Addendum, Bancroft has not completed a SOC 2 Type II examination and no report is available; Bancroft will not represent otherwise. Bancroft may update its security measures over time provided the updates do not materially reduce the overall level of protection.

5. Subprocessors

The Advisor Firm provides general authorization for Bancroft to engage subprocessors to process Personal Data in connection with the platform. The current list of subprocessors, including each provider's purpose, the categories of data processed, and the processing location, is published at usebancroft.com/subprocessors and is incorporated into this Addendum by reference.

Bancroft shall impose on each subprocessor data protection obligations that are substantially equivalent to those in this Addendum, and remains fully liable to the Advisor Firm for the performance of each subprocessor's obligations.

Bancroft shall update the published subprocessor list before a new subprocessor begins processing Personal Data. Advisor Firms who have requested notice will receive it at the email address they designate. The Advisor Firm may object to a new subprocessor on reasonable data protection grounds within thirty (30) days of notice, in which case the parties shall discuss a commercially reasonable accommodation in good faith; if none is available, the Advisor Firm may terminate the affected services without penalty for the remainder of the then-current term.

6. Security Incident Notification

Bancroft shall notify the Advisor Firm of any confirmed Security Incident affecting Personal Data without undue delay and in any event no later than seventy-two (72) hours after Bancroft becomes aware of it. "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Bancroft or its subprocessors.

This seventy-two hour commitment is set to support Advisor Firms that are investment advisers subject to the Securities and Exchange Commission's Regulation S-P, as amended, which requires covered institutions to establish written policies obligating service providers to notify them of a breach in security as soon as possible and no later than seventy-two hours after becoming aware of it, so the Advisor Firm can meet its own customer-notification obligations.

The notification shall describe, to the extent known at the time and updated as the investigation progresses: the nature of the incident, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken or proposed to address it, and a contact point for further information. Bancroft shall not delay notification in order to complete its investigation.

Bancroft shall reasonably cooperate with the Advisor Firm in the Advisor Firm's investigation, remediation, and any regulatory or individual notification the Advisor Firm determines is required. Bancroft shall not notify any regulator or individual on the Advisor Firm's behalf, or identify the Advisor Firm publicly in connection with an incident, without the Advisor Firm's prior written consent unless required by law.

Bancroft maintains a documented incident response process covering detection, escalation, containment, remediation, and post-incident review.

7. Assistance to the Advisor Firm

Taking into account the nature of the processing, Bancroft shall provide reasonable assistance to the Advisor Firm in fulfilling the Advisor Firm's obligations to respond to requests from individuals to access, correct, delete, port, or restrict the processing of their Personal Data.

The platform provides self-service functionality through which the Advisor Firm can access, correct, export, and delete household and client data directly. Where a request cannot be fulfilled through that functionality, Bancroft shall assist on reasonable request.

If Bancroft receives a request directly from an individual whose Personal Data it processes on behalf of an Advisor Firm, Bancroft shall not respond substantively to the request except to acknowledge receipt and direct the individual to the Advisor Firm, and shall inform the Advisor Firm of the request without undue delay.

Bancroft shall provide the Advisor Firm with information reasonably necessary to demonstrate compliance with this Addendum and to support the Advisor Firm's data protection impact assessments and service provider due diligence, including responses to security questionnaires.

8. Government and Third-Party Requests

If Bancroft receives a subpoena, court order, warrant, or other legally binding demand from a government authority or third party for Personal Data processed on behalf of an Advisor Firm, Bancroft shall, unless legally prohibited: notify the Advisor Firm without undue delay so that the Advisor Firm may seek a protective order or other appropriate remedy; disclose only the minimum data legally required; and, where the demand appears unlawful or overbroad, challenge it or require the requesting party to seek the data directly from the Advisor Firm.

9. Return and Deletion of Data

The Advisor Firm may export or delete household and client data at any time during the term through platform functionality.

On termination or expiration of the Agreement, Bancroft shall, at the Advisor Firm's election, make Personal Data available for export or delete it. Absent a written election, Bancroft shall retain the data for a wind-down period of thirty (30) days following termination to allow for export, after which it shall be deleted from active systems. Data in encrypted backups is purged on the ordinary backup rotation cycle.

Bancroft may retain Personal Data to the extent required by applicable law, and shall retain audit and compliance records as described in the Privacy Policy. Retained data remains subject to the confidentiality and security obligations of this Addendum for as long as it is held.

10. Processing Location

Bancroft processes and stores Personal Data in the United States. Bancroft does not transfer Personal Data outside the United States in the ordinary course of operating the platform. The processing location for each subprocessor is identified on the subprocessor list.

11. Liability, Term, and Order of Precedence

This Addendum takes effect on the effective date of the Agreement and continues for as long as Bancroft processes Personal Data on behalf of the Advisor Firm. The obligations in Sections 3, 4, 6, 8, and 9 survive termination for as long as Bancroft retains Personal Data.

Each party's liability under this Addendum is subject to the limitations and exclusions of liability set out in the Agreement and the Disclosures and Terms.

Except as amended by this Addendum, the Agreement and the Disclosures and Terms remain in full force and effect.

12. Acceptance and Execution

An Advisor Firm that has entered into the Agreement and uses the platform to process Personal Data is bound by this Addendum without further action, and may rely on it as the data processing terms between the parties.

Advisor Firms that require a countersigned copy for their compliance files, a version on their own paper, or completion of a vendor due diligence questionnaire may request one by emailing support@usebancroft.com with the subject line "DPA request." Bancroft will provide an executed copy.

Bancroft may update this Addendum to reflect changes in law, the services, or its security measures, provided no update materially reduces the protections afforded to Personal Data. Material changes will be communicated to Advisor Firms by email or in-platform notice, and the revision date below will be updated.

Last updated: August 11, 2026

To request a countersigned copy or complete a vendor due diligence review, contact support@usebancroft.com