MRRaudit Terms of Service
Last Updated: September 1, 2026 · Includes the Data Processing Addendum
1. The Terms
These Terms of Service (the “Terms”) govern access to and use of mrraudit.com (the “Service” or “MRRaudit”). By accessing or using the Service, you (“User,” “you,” or “your”) agree to be bound by these Terms. If you are entering into these Terms on behalf of a company or other legal entity, you represent that you have the authority to bind that entity, in which case “you” refers to that entity.
2. Owner of MRRaudit
MRRaudit is owned and operated by ChartMogul GmbH & Co. KG, a company registered in Germany with its registered office at c/o WeWork, Kemperplatz 1, 10785 Berlin, Germany (“Owner,” “we,” “us,” or “our”).
3. Information About MRRaudit
MRRaudit is a software service that analyzes billing and subscription data, including data from Stripe and ChartMogul, to identify potential discrepancies, anomalies, and opportunities for further review, and to generate related summaries and recommendations (collectively, “Audit Results”). MRRaudit may use artificial intelligence to assist in generating Audit Results.
4. Age Eligibility
You must be at least 18 years old, or the age of legal majority in your jurisdiction, to use the Service.
5. Customer Data
You retain all ownership rights in the data you upload to, or make available through, the Service (“Customer Data”). You grant Owner a non-exclusive, worldwide license to access, process, transmit, store, and otherwise use Customer Data solely as necessary to provide, operate, maintain, support, secure, and improve the Service, including generating Audit Results. You represent and warrant that you have all rights and consents necessary to provide Customer Data to MRRaudit, including any rights required to connect third-party accounts such as Stripe or ChartMogul.
6. User Obligations
You agree to use the Service only for lawful purposes and in accordance with these Terms. You are solely responsible for the accuracy and completeness of the data you provide or connect, and you acknowledge that incomplete or inaccurate source data may affect the accuracy of Audit Results.
7. Forbidden Use
You may not: (a) use the Service in violation of any applicable law or regulation; (b) attempt to gain unauthorized access to the Service, other accounts or users’ data, or related systems; (c) interfere with or disrupt the integrity, operation, or performance of the Service; (d) upload malicious code or content; (e) reverse engineer or attempt to extract the source code of the Service, except as permitted by law; (f) use the Service in a manner that infringes the rights of others; or (g) use the Service to build a competing product.
8. Third-Party Services
The Service may access data from third-party services, including Stripe and ChartMogul (each, a “Third-Party Service”). By connecting a Third-Party Service, you authorize MRRaudit to access and process the data made available through that connection, consistent with the permissions you grant.
Where a Third-Party Service is provided by a party other than Owner (such as Stripe), your use of that service is governed solely by that provider’s own terms and privacy policies, and Owner is not responsible for its availability, accuracy, security, or performance.
ChartMogul is provided by Owner under separate terms of service (the “ChartMogul Terms”). Nothing in this Section limits or modifies Owner’s obligations to you under the ChartMogul Terms with respect to the ChartMogul service itself. This Section governs only MRRaudit’s access to and use of data obtained through your ChartMogul connection for purposes of providing the Service.
If you do not already have a ChartMogul account, MRRaudit may create a temporary ChartMogul account on your behalf and transmit your Customer Data to it solely to generate Audit Results, using our own internal integration rather than a connection you separately authorize. Any such account and the Customer Data within it will be automatically deleted within approximately seven days of completion of the relevant audit. In this scenario, Owner processes Customer Data through the ChartMogul platform solely for the purpose of providing the Service. The ChartMogul platform is not acting as an independent Third-Party Service, and the ChartMogul Terms described above do not apply. Any Customer Data transmitted to ChartMogul under this paragraph that has not already been deleted will otherwise be deleted or returned in accordance with Section 11 upon termination of these Terms, except where retention is required by law.
8.1 AI Integrations
MRRaudit may use artificial intelligence, including third-party AI models, to help generate Audit Results (including summaries, recommendations, and other outputs). The Service is hosted on Amazon Web Services (AWS), and AI features are powered by foundation models accessed through Amazon Bedrock, an AWS service. We may change the AI models or providers we use, or move AI processing into our own infrastructure, from time to time.
See Section 9 for important information about how to use Audit Results, including those generated using artificial intelligence.
9. Audit Results Disclaimer
Audit Results, including any discrepancies, anomalies, findings, recommendations, summaries, or other output generated by the Service, whether or not generated using artificial intelligence, identify potential issues based solely on the data made available to MRRaudit at the time of analysis. Audit Results, including any AI-generated findings, do not constitute accounting, legal, tax, or financial advice, and are not a substitute for professional judgment. You remain solely responsible for independently reviewing, validating, and acting (or not acting) upon any Audit Results. Owner does not guarantee that Audit Results are complete, accurate, or free of error, particularly where source data is missing, incomplete, or inaccurate.
10. Company Name and Feedback
You grant Owner the right to identify you as a customer and use your company name and logo in customer lists and marketing materials, unless you notify us otherwise. If you provide suggestions, ideas, enhancement requests, recommendations, or other feedback regarding the Service, you grant Owner a worldwide, perpetual, irrevocable, royalty-free license to use, modify, and incorporate that feedback into the Service and other products without restriction or obligation to you.
11. Term and Termination
These Terms remain in effect until terminated by you or Owner.
You may stop using the Service or otherwise terminate these Terms at any time.
Owner may suspend or terminate your access to the Service, or terminate these Terms, at any time, with or without notice, including where, for example, you breach these Terms, your use of the Service presents a security, legal, or operational risk, we discontinue the Service, or for any other business reason.
Upon termination, your right to use the Service ends. We will delete or return Customer Data in accordance with our Privacy Policy, except where retention is required by law.
12. Usage Data and Anonymous Data
We may collect data about how the Service is used (“Usage Data”) and may create aggregated or de-identified data from Customer Data that cannot reasonably be used to identify you (“Anonymous Data”). We may use Usage Data and Anonymous Data to operate, improve, and promote the Service.
13. Confidentiality
Each party agrees to protect the other party's confidential information using reasonable care and to use such information only as necessary to perform under these Terms.
This obligation does not apply to information that is publicly available, independently developed, lawfully obtained from a third party, or required to be disclosed by law.
14. Intellectual Property Rights
Owner retains all right, title, and interest in and to the Service, including all related software, technology, trademarks, documentation, and other intellectual property. Subject to these Terms, Owner grants you a limited, non-exclusive, non-transferable, revocable license to access and use the Service during the term of these Terms, solely for your internal business purposes.
15. Privacy Policy
Our collection and use of personal data in connection with the Service is described in our Privacy Policy and Data Processing Addendum, which are incorporated into these Terms by reference.
16. Availability
We will use commercially reasonable efforts to provide the Service but do not guarantee uninterrupted, error-free, or bug-free operation. The Service may evolve over time, and we may add, modify, suspend, or discontinue features or functionality from time to time. We may temporarily suspend the Service for maintenance, security, operational reasons, or to deploy updates.
17. Service Provided “As Is” and Limitation of Liability
The Service, including all Audit Results, is provided “as is” and “as available,” without warranties of any kind, whether express, implied, or statutory, including warranties of merchantability, fitness for a particular purpose, title, and non-infringement.
To the maximum extent permitted by law, Owner will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenue, data, or goodwill, arising out of or related to these Terms or the Service, even if advised of the possibility of such damages.
Owner’s total aggregate liability arising out of or relating to these Terms or the Service will not exceed the fees you paid to Owner in the twelve (12) months preceding the event giving rise to the claim (or, if you have not paid any fees, one hundred U.S. dollars (USD $100)).
Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law.
18. Indemnity
You agree to indemnify and hold Owner harmless from any claims, damages, liabilities, and expenses (including reasonable legal fees) arising out of your breach of these Terms, your misuse of the Service, or your violation of any applicable law or third-party right.
19. Changes to These Terms
We may update these Terms from time to time by posting a notice on the Service or our website. Material changes will take effect on the date posted, or such later date as we specify. Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated Terms.
20. Assignment of Contract
You may not assign or transfer these Terms without our prior written consent. We may assign these Terms in connection with a merger, acquisition, or sale of assets, or otherwise without restriction.
21. Contacts
Questions about these Terms may be directed to support@chartmogul.com.
22. Severability
If any provision of these Terms is found unenforceable, the remaining provisions will remain in full force and effect, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable.
23. Governing Law and Jurisdiction
These Terms are governed by the laws of Ireland, without regard to its conflict of laws principles. The courts of Ireland will have exclusive jurisdiction over any dispute arising out of or relating to these Terms, except where mandatory consumer protection law provides otherwise.
24. Definitions
“Audit Results” means the discrepancies, anomalies, findings, recommendations, summaries, and other output generated by the Service, whether or not generated using artificial intelligence.
“Customer Data” means any data, content, or information you upload to or connect through the Service.
“Service” means the MRRaudit software application and related services.
“Third-Party Service” means any third-party application, integration, or service connected to or used with the Service, including Stripe and ChartMogul.
25. Construction
Headings are for convenience only and do not affect interpretation. “Including” means “including without limitation.” References to “law” include any amendments or replacements of that law.
Data Processing Addendum
This Data Processing Addendum ("Addendum") is incorporated into and forms an integral part of the Terms of Service ("Terms") between User (as defined in the Terms) and ChartMogul GmbH & Co. KG, with registered offices at c/o WeWork, Kemperplatz 1, 10785 Berlin, Germany ("Owner") (each a "party" and together the "parties"), and is effective upon incorporation into the Terms. This Addendum on the processing of personal data on behalf of a controller in accordance with Article 28(3) GDPR applies to any processing of personal data by Owner in its capacity as processor on behalf of User in connection with the Service.
To the extent User is a "business" subject to California Civil Code § 1798.100 et seq. (the "CCPA"), § 8 of this Addendum also sets out additional obligations under the CCPA.
§ 1 Interpretation
(1) In this Addendum:
"CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act;
"Data" means any personal data comprised within Customer Data or Audit Results (each as defined in the Terms) that Owner processes on behalf of User in connection with the Service, as further described in Exhibit 1;
"Data Protection Acts" means the Data Protection Acts 1988–2018 of Ireland;
"Data Protection Law" means all legislation and regulations relating to the protection of personal data, including the Data Protection Acts, the GDPR, and all other statutory instruments, guidance, or codes of practice issued by a competent data protection authority;
"GDPR" means the General Data Protection Regulation (Regulation (EU) 2016/679);
"List of Subprocessors" means the list of subprocessors with which Owner engages in connection with the Service, as set out in our Privacy Policy, as may be amended, supplemented, or substituted by Owner from time to time in accordance with § 5 of this Addendum;
"Permitted Third Party Service Provider" means a subprocessor on the List of Subprocessors or otherwise approved by User from time to time;
"Personnel" means those employees, agents, or contractors of Owner to whom disclosure of Data is necessary for the provision of the Service and who are appropriately trained in and committed to data security and confidentiality; and
"Service" and "Terms" have the meanings given to them in the Terms.
(2) Construction: in this Addendum, unless the contrary intention is stated, (a) "controller," "processor," "data subject," "personal data," "processing," and "appropriate technical and organisational measures" have the meanings given in Data Protection Law; (b) the singular includes the plural and vice versa; (c) "including" means comprising, but not by way of limitation; (d) a reference to any agreement, document, or law includes that item as amended, supplemented, or replaced from time to time; and (e) "writing" includes any electronic mode of representing or reproducing words in visible form.
§ 2 Personal Data Types and Processing Purposes
(1) The parties agree that, for the purposes of Data Protection Law and in relation to the Data: (a) User is the controller and Owner is the processor; (b) User remains responsible for its own compliance obligations as controller, including securing a lawful basis for the processing of the Data and for the instructions it gives to Owner; and (c) Exhibit 1 describes the subject matter, nature, and purpose of the processing, and the categories of Data and data subjects.
(2) User will not provide to Owner any information falling within "special categories of data" under Data Protection Law, and Owner will not be liable for any losses arising from its processing of special categories of personal data provided to it in breach of this clause.
(3) The term of this Addendum is the term of the provision of the Service, plus any period of retention required for backup, disaster recovery, or other purposes as described in our Privacy Policy.
§ 3 Scope of Application
(1) User's instructions regarding the processing of the Data consist, initially, of those necessary for the provision of the Service as set out in the Terms. User may request modification of those instructions in writing; such requests relate strictly to the processing of Data and do not include ordinary customer support requests.
§ 4 Owner's Obligations
(1) Owner will: (a) except as required by law, or as necessary for the provision, maintenance, security, and improvement of the Service, only process Data in accordance with User's documented instructions, the nature and purpose set out in Exhibit 1, and to the minimum extent necessary to provide the Service; (b) carry out any processing in compliance with Data Protection Law; (c) inform User promptly if, in Owner's opinion, an instruction infringes Data Protection Law; and (d) disclose Data only to Personnel for whom such disclosure is necessary, and ensure they are bound by confidentiality and security obligations consistent with this Addendum.
(2) Owner will keep the Data confidential and will not disclose it to third parties except as authorized by User, this Addendum, or the Terms, or as required by Data Protection Law, other applicable law, or a competent regulator (including the Data Protection Commission of Ireland and the Berlin Commissioner for Data Protection and Freedom of Information). Where legally required to disclose Data, Owner will, where permitted, notify User and give User an opportunity to object.
(3) Owner will provide reasonable assistance to User, at User's reasonable expense, with User's compliance obligations under Data Protection Law, including in relation to data subject rights and data protection impact assessments, taking into account the nature of the processing and information available to Owner.
(4) Owner will implement appropriate technical and organizational security measures to protect Data against accidental or unauthorized loss, destruction, alteration, disclosure, or access, consistent with our Privacy Policy, and will ensure Personnel are aware of and comply with those measures.
(5) Owner will notify User without undue delay after becoming aware of any unauthorized access to, or unauthorized use, alteration, disclosure, or loss of, Data (a "data breach"), and will take prompt action to investigate the cause and, at User's reasonable expense, assist User in complying with its obligations under Articles 32–36 GDPR.
(6) Owner will notify User promptly of any data subject request or complaint relating to the Data, and will not respond to it except on User's written instructions, unless required by law. Owner will, at User's reasonable expense, assist User by appropriate technical and organizational measures to fulfil User's obligation to respond to such requests.
(7) On reasonable written request and at least 14 calendar days' notice (or 72 hours' notice where User reasonably believes a data breach has occurred), Owner will make available information reasonably necessary to demonstrate compliance with this Addendum, and will permit and contribute to an audit conducted by User or its mandated auditor, subject to confidentiality and reasonable limits on frequency and scope.
(8) Upon termination of the Service, Owner will delete or return Data in accordance with the Terms and Privacy Policy, except where retention is required by law, and will provide written confirmation of deletion upon request.
§ 5 Permitted Third Party Service Providers
(1) Owner may subcontract processing of Data to Permitted Third Party Service Providers, remaining responsible for their acts and omissions as if they were its own.
(2) Owner may add or replace Permitted Third Party Service Providers, provided User is given an opportunity to object within 14 calendar days of notice of the change. User's sole remedy in case of a reasonable, unresolved objection is to terminate the Service as it relates to the affected processing, effective before the new or replacement provider is engaged.
(3) Where a Permitted Third Party Service Provider's access to Data constitutes an international transfer, User authorizes Owner to put in place appropriate transfer mechanisms, including standard contractual clauses, consistent with our Privacy Policy, and Owner will make the relevant transfer instrument available to User on request.
§ 6 User's Representations and Warranties
(1) User represents and warrants, on a continuing basis, that: (a) it has a valid lawful basis, including any required consents, for the processing of the Data contemplated by the Service; (b) it has complied with its own obligations in respect of the Data; and (c) Owner's processing of the Data as contemplated by the Terms and this Addendum will not infringe the rights of any person under Data Protection Law.
§ 7 Liability
(1) Each party's liability arising out of or in relation to the processing of Data under this Addendum is subject to the limitation of liability provisions in Section 17 of the Terms.
§ 8 California Consumer Privacy Act
(1) Where User is a "business" under the CCPA, this § 8 applies in addition to §§ 1–7 with respect to Data relating to "consumers" or "households" under the CCPA.
(2) References to "Data" in this Addendum also include "personal information" as defined in the CCPA, and references to "processor" also mean Owner acting as a "service provider" as defined in the CCPA.
(3) As a service provider, Owner will not retain, use, disclose, or sell Data for any purpose other than providing the Service, as instructed by User, or as otherwise permitted by the CCPA.
(4) Owner will not disclose Data to any third party except a Permitted Third Party Service Provider bound by terms consistent with this Addendum.
§ 9 General
(1) If any provision of this Addendum is invalid or unenforceable, the remainder will remain in effect, and the invalid provision will be replaced with one that most closely reflects its intent.
(2) This Addendum survives termination of the Terms to the extent necessary to give effect to its terms.
(3) This Addendum and the Terms constitute the entire agreement between the parties regarding Owner's processing of Data as a processor on behalf of User. In case of conflict between this Addendum and the Terms regarding the processing of Data, this Addendum controls.
(4) Owner may update this Addendum from time to time, provided such updates do not violate Data Protection Law or adversely affect the security of Data or User's rights.
(5) By agreeing to the Terms, the parties are deemed to have duly executed this Addendum as of the effective date of the Terms.
Exhibit 1 — Details of Processing
Types of Data:
- Name and email address (of User's own customers or subscribers, where contained in Customer Data);
- Billing, subscription, invoice, and payment history, and other transaction data connected via Stripe or ChartMogul, or uploaded via CSV (see Note 1);
- Discrepancies, findings, and other content generated as part of Audit Results, to the extent they reference an identifiable individual.
Note 1: This does not include sensitive payment information such as full card numbers, expiry dates, CVC codes, or bank account details.
Categories of data subjects: Customers and subscribers of User whose data is contained within Customer Data.
Nature of the processing: Any operation performed on personal data, whether or not by automated means, including collection, storage, analysis, alteration, retrieval, disclosure, or erasure.
Purpose of the processing: Analyzing Customer Data, including using artificial intelligence, to generate Audit Results as described in the Terms.
Permitted Third Party Service Providers: See our Privacy Policy.