Define every data boundary.
Follow the data your relationship needs, from collection and processing to retention, export and an orderly exit.
Map the minimum necessary exchange.
The data map names the source, purpose, recipient, authority, environment and lifecycle for each field. Synthetic evaluation data is preferred. Do not assume a provider, accounting platform or model processor receives every category just because it is part of the architecture.
| Category | Typical purpose | Review boundary |
|---|---|---|
| Identity / membership | Authenticate and authorize the selected actor. | Minimize identity transfer; verify provisioning and offboarding. |
| Merchant and financial records | Orders, invoices, outcomes, receipts and reconciliation. | Organization isolation; asset/reference scope; approved recipient. |
| Uploaded receipts / documents | Extraction draft and human review. | Review model/provider transfer, retention and human confirmation. |
| Provider evidence | Authenticate outcomes and resolve differences. | Share redacted evidence only; exclude credentials. |
| Audit / diagnostics | Trace authorized actions and investigate failures. | Approved access, retention and redaction policy. |
Retention is a reviewed policy, not a guess.
This edition does not establish a per-category retention schedule, deletion-completion SLA, hosting-residency guarantee or approved subprocessor register. A privacy review must obtain the current operational register and signed terms for the selected processing. Technical deletion of an account is not proof that financial records, audit history and backups have all been erased.
- For each category: purpose, owner, retention trigger/duration, deletion method and exceptions.
- For each processor: service, transferred fields, region, terms, subprocessors and change process.
- For backups: access, encryption evidence, expiration and tested restore/deletion implications.
Plan export and exit before onboarding.
Agree on authorized export formats, record coverage, date/time/asset semantics, reconciliation of final outstanding items, disconnection and revocation. The reviewed payment list is bounded and is not a complete export API. A CSV route exists for authorized business users; it does not establish every portability or deletion obligation. Required legal terms and deadlines need the parties’ review.