Customer Onboarding and Due Diligence

1. Purpose and Scope

This document describes how DataChimp Labs onboards customers, the information we collect, the agreements we execute, and the due diligence checks we perform. It is published to support customer, partner, and regulator inquiries -- particularly those focused on role-scoping under the proposed Consumer Financial Protection Bureau (CFPB) Dodd-Frank Section 1033 rulemaking on personal financial data rights.

2. Business Model and Role

DataChimp Labs is a business-to-business (B2B) software-as-a-service platform. Our direct customers are businesses — healthcare organizations, financial services firms, and regulated commercial entities — who use our platform to serve their own end users.

Under the proposed CFPB Section 1033 framework:

  • Our direct customers hold the consumer relationship and are the entities providing the consumer product or service that uses open-banking data.
  • DataChimp Labs is a service provider to those customers. We provide platform infrastructure, security, and integrations (including Plaid) under a chain of contracts that flow consumer-protection obligations through to our customers.

DataChimp Labs does not currently offer a direct-to-consumer product. Future consumer-facing offerings, if launched, will be evaluated and disclosed separately under the applicable regulatory framework at that time.

3. Customer Onboarding Process

3.1 Sales qualification

Prospective customers are qualified against our sanctioned target market: entity type, industry vertical, data-handling profile, jurisdiction, and intended use of the platform. We decline engagements that fall outside our sanctioned use cases or that lack a lawful basis for the data flows involved.

3.2 Information collected during onboarding

Prior to production access, we collect and verify:

  • Legal business name, incorporation jurisdiction, and registered address.
  • EIN or equivalent tax identifier.
  • Authorized signatory identity, title, and government-issued ID for verification.
  • Beneficial-owner and control-person disclosures where applicable.
  • Business wallet or corporate financial account details for screening (see §3.4).
  • Nature of business, industry classification, and a written description of the consumer-facing product or service the customer will operate using our platform.
  • Applicable licenses or registrations (e.g., state financial-services licenses, HIPAA covered-entity attestation, state department of health registration for healthcare customers).
  • Customer’s data-handling posture (security questionnaire) for customers who will process PHI, financial account data, or other sensitive categories.

3.3 Agreements executed prior to production access

Every customer signs, at minimum:

  • A Master Services Agreement (MSA) or equivalent commercial contract governing use of the platform.
  • A Data Processing Addendum (DPA) for GDPR, UK GDPR, and CCPA/CPRA compliance where applicable.
  • A Business Associate Agreement (BAA) where protected health information will be processed (HIPAA).
  • Where open-banking data flows are in scope, flow-down terms incorporating Plaid End User Services Agreement obligations, prohibiting unauthorized secondary use, and requiring the customer to obtain consumer authorization before initiating any account connection.

3.4 Due diligence checks

For every customer, we perform the following before production access is granted:

  • OFAC and U.S. Treasury sanctions screening against the entity, its authorized signatories, and any beneficial-owner or control-person disclosed during onboarding. Screening covers the OFAC Specially Designated Nationals (SDN) list, the Consolidated Sanctions List, and U.S. Treasury restricted-party lists.
  • Politically Exposed Persons (PEP) screening against names, government-issued IDs, and business wallets or corporate financial account identifiers. We do not onboard customers or signatories identified as restricted or as politically connected persons falling outside our accepted-risk criteria.
  • Adverse-media screening proportionate to the customer’s risk profile.
  • Regulatory-license verification where the customer’s business requires one (state financial-services licenses, healthcare registrations, etc.).
  • Security-posture review for customers who will process PHI or sensitive financial data — a questionnaire covering their own administrative, physical, and technical safeguards, with follow-up clarification where responses fall short of DataChimp Labs’ minimum expectations.

Onboarding due diligence outcomes, including screening results, are retained in the customer file and reviewed as part of the annual customer re-review cycle (§3.7).

3.5 Consumer-authorization posture (Section 1033)

Because DataChimp Labs is a service provider to our customer (not the entity holding the consumer relationship), our customer is contractually required to:

  • Present an authorization flow to the consumer that clearly discloses what financial data will be accessed, for what purpose, and for how long.
  • Obtain the consumer’s affirmative authorization before initiating any Plaid connection.
  • Honor consumer revocation requests and propagate them to DataChimp Labs within a defined contractual timeframe.
  • Refrain from initiating any secondary use of consumer financial data beyond the disclosed authorized purpose.

We enforce these requirements contractually and, where technically feasible, in-product — for example, our platform requires the customer to attest consumer authorization before an account-connection API call is initiated.

3.6 Ongoing customer monitoring

After onboarding, we monitor customer usage for anomalous patterns indicative of consumer-harm risk, including but not limited to:

  • Bulk enumeration or unusual connection-volume spikes.
  • Off-scope API endpoint usage.
  • Disproportionate consumer coverage relative to the customer’s disclosed business.
  • Patterns suggesting circumvention of the consumer-authorization requirement.

We reserve, and exercise where warranted, contractual rights to require remediation, suspend access, or terminate for a customer’s breach of the authorization terms or the data-use restrictions in the MSA / DPA / BAA.

3.7 Annual re-review and change management

  • Annual re-review. All active customers are re-screened annually against sanctions and PEP lists. High-risk customers (financial services, cross-border data flows, or customers whose usage patterns warrant closer attention) receive a more thorough re-review including refreshed license verification and updated security posture.
  • Material-change triggers. A material change to a customer’s use case, data flows, entity structure (M&A, change of control), or beneficial ownership triggers a re-review of the applicable agreements and due diligence file before continued production access.

4. Summary — Section 1033 Role Statement

For the avoidance of doubt under the proposed Section 1033 framework:

  • Direct customers of DataChimp Labs hold the consumer relationship and are the entities providing the consumer product or service that uses open-banking data.
  • Direct customers hold the consumer-authorization obligation and are contractually required to obtain, honor, and propagate consumer authorizations and revocations.
  • DataChimp Labs is a service provider to those customers, offering platform infrastructure under a chain of contracts (MSA, DPA, BAA where applicable) with flow-down obligations to protect the consumer.

5. Contact

Additional evidence — including sanctioned use-case list, template agreements, sample due diligence file, and screening service references — is available under NDA.

6. Approval and Version History

Version Date Author Change
1.0 2026-09-02 DataChimp Labs — Security Initial published version.

Copyright © 2026 DataChimp Labs. Public Trust Center.