1. Roles and instructions
For client, contact, work-entry, and invoice content entered by a customer, the customer generally acts as controller and the RetainerMeter operator acts as processor where data-protection law uses those roles. Processing is limited to documented instructions in the service agreement and lawful instructions subsequently provided. RetainerMeter separately acts as controller for its own account, consent, security, payment, tax, and business-administration records where appropriate.
2. Subject matter and duration
Processing supports a single-user cloud workspace for retainer tracking, burn calculation, invoice rendering/export, user-directed invoice email delivery, portable backup, authentication, billing status, lifecycle retention, and verified Desktop linking. Invoice email delivery processes the selected PDF and saved recipients through the declared email subprocessor only after the customer's confirmed instruction. Processing continues while the account is active and through the documented grace/retention period, subject to deletion and legally required records.
3. Data and people
Potential data includes consultant identity/contact settings, client identity and address, time entries, work descriptions, invoice line items, tax/payment text, invoice status/history, and a consultant logo. Data subjects may include the customer, the customer's clients and contacts, and individuals mentioned in work or invoice records. Customers should not upload special-category or highly sensitive data unless expressly supported and lawfully arranged.
4. Processor commitments
RetainerMeter will keep authorized personnel and providers subject to confidentiality, apply appropriate technical and organizational measures, reasonably assist with rights requests and impact assessments where applicable, notify the customer of a confirmed personal-data breach without undue delay where required, delete or return workspace data at the end of service subject to the retention schedule, and process workspace data only on documented instructions unless applicable law requires otherwise.
5. Security measures
Measures include segregated account-scoped queries; hashed sessions and one-time codes; secure cookies; CSRF, Origin, rate, size, and schema controls; revision conflicts; output escaping; least-content operational logging; controlled production access; backups and restore procedures; and incident/release review. RetainerMeter does not represent Web as end-to-end encrypted.
6. Subprocessors
The current subprocessors are listed in the subprocessor notice. RetainerMeter will require providers to protect personal data consistently with the service and will provide change notice and an objection route where required by applicable law or this addendum.
7. International transfers
The customer database is configured in the EU, but providers and support/payment operations may involve other locations. Transfers are handled under the providers' applicable terms and transfer mechanisms. RetainerMeter does not promise EU-only processing.
8. Deletion and return
Portable export remains available during full and read-only access. Active workspace content is deleted according to the lifecycle or verified deletion request. Provider residual backups follow provider expiry and are not customer-restorable. Separate controller records are retained only for documented legal/business purposes.