Effective Date: July 14, 2026
This forms part of the Terms of Service and governs Journey.tax's processing of personal data and tax return information that a firm ("Firm") submits to the Service.
We process Firm and client data solely to provide the Service to the Firm and on the Firm's documented instructions. We will not use or disclose tax return information except as necessary to provide the Service or as the Firm directs, consistent with § 7216. We will not use client data for our own marketing, analytics unrelated to the Service, or to train third-party AI models.
The Service may send documents the Firm uploads to a third-party AI provider for optical character recognition and data extraction. We commit that:
We engage the following subprocessors to provide the Service. We will maintain this list and give the Firm advance notice before adding or replacing a subprocessor, and will bind each to data-protection obligations no less protective than this Addendum.
| Subprocessor | Function | Location |
|---|---|---|
| Supabase | Cloud hosting and database | United States |
| OpenAI | AI-assisted client summary generation | United States |
| Resend | Transactional email | United States |
| Twilio | SMS notifications | United States |
Note: OCR document processing (CLARUS) is currently inactive. This list will be updated when OCR functionality is activated. Firms will receive advance notice of any subprocessor changes.
We maintain an information security program with administrative, technical, and physical safeguards consistent with the FTC Safeguards Rule and IRS Publication 4557, including encryption in transit and at rest, role-based access controls, multi-factor authentication for administrative access, time-limited signed URLs for document access, logging, and monitoring.
To support the Firm's own Safeguards Rule vendor-oversight duties, we will provide, on reasonable request, summary information about our security practices, subprocessors, and relevant certifications or assessments.
We will notify the Firm of a confirmed personal-data or tax-return-information breach affecting the Firm's data without undue delay, and no later than 72 hours after we confirm it, including the nature of the incident, the data involved, and the steps taken, to the extent known.
On termination or on the Firm's request, we will make the Firm's data available for export for 30 days, after which we will delete or return it within 60 days, except for copies we are required by law to retain or that exist in routine backups, which are deleted on their normal cycle.
We process Firm and client data in the United States and will not transfer it outside the United States without the Firm's instruction and any additional § 7216 consents that such transfer would require.
Both parties will comply with applicable data-protection and tax-confidentiality laws, including GLBA, the FTC Safeguards Rule, and IRC § 7216/§ 6713.
Journey.tax is operated by Secord Fintech Inc., 8470 Enterprise Cir, Lakewood Ranch, FL 34202 · 727-362-6858 · admin@journey.tax