Legal
Data Processing Addendum
This addendum governs AccountingKit's processing of personal data on your behalf. It is incorporated into the Terms of Service and applies automatically — you do not need to sign a separate copy unless your procurement process requires one.
Roles and scope
This Data Processing Addendum forms part of the Terms of Service between AccountingKit (Processor) and the customer organization (Controller). It applies wherever AccountingKit processes personal data on the Controller's behalf in the course of providing the service.
In this addendum, personal data, processing, controller, processor, data subject, and supervisory authority have the meanings given in the EU General Data Protection Regulation. Equivalent concepts in the UK GDPR, India's Digital Personal Data Protection Act, and comparable laws are read accordingly.
Where AccountingKit acts as a controller in its own right — for console account records and website visitors — the Privacy Policy applies instead of this addendum.
If you need a signed copy on your own paper, or with your entity named in the header, write to privacy@accountingkit.dev and we will execute one.
Processing instructions
AccountingKit processes personal data only on the Controller's documented instructions. The Controller's instructions are: the Terms of Service, this addendum, the configuration chosen in the developer console, and the API calls and workflow definitions the Controller issues. Nothing else instructs us.
AccountingKit will tell the Controller if, in its opinion, an instruction infringes data protection law, and may pause that processing until the instruction is resolved. AccountingKit will not process the personal data for its own purposes, will not sell it, and will not use it to train machine-learning models.
Where law requires processing beyond the Controller's instructions, AccountingKit will inform the Controller before processing unless that law prohibits the notice on important grounds of public interest.
Record of processing
This is the Article 28(3) description of the processing, and the Annex I record.
| Item | Detail |
|---|---|
| Subject matter | Providing a unified accounting API and durable workflow execution against the Controller's connected accounting system |
| Duration | The term of the Terms of Service, plus the deletion period described below |
| Nature and purpose | Authenticating to the accounting provider; reading, normalizing, creating, and updating accounting records; executing multi-step operations with retries and replay; delivering signed webhooks; recording usage for billing; and storing data where the connection's retention mode permits it |
| Categories of data subject | The Controller's customers, suppliers, contacts, and employees, as represented in the connected accounting organization; and the Controller's own console users |
| Categories of personal data | Names, business and personal contact details, postal addresses, tax identifiers, bank account details where the provider exposes them, transaction and invoice content, payment records, and provider record identifiers |
| Special category data | None is required or requested by the service. The Controller should not send it. If the Controller's accounting records contain it, it is processed only as opaque record content |
| Frequency | Continuous, triggered by the Controller's API calls, scheduled synchronization, and provider webhooks |
| Retention | Zero-retention connections: no accounting record data is stored. Cached connections:30 days from the last sync, then cleared. See the retention schedule |
Personnel
AccountingKit limits access to personal data to personnel who need it to operate the service or to support the Controller. Those personnel are bound by written confidentiality obligations that survive the end of their engagement, and their access is removed when it is no longer needed. Production access is granted through individually attributable accounts, not shared credentials.
Security measures
AccountingKit implements the technical and organizational measures below, which form the Annex II record. They are the measures actually in place, not aspirations.
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS on every external connection, with HSTS enforced on every public origin |
| Encryption at rest | Provider OAuth credentials and raw provider payloads sealed with AES-256-GCM envelope encryption under a Google Cloud KMS key held in europe-west3 (Frankfurt, Germany); database and disk encryption at the platform layer |
| Credential handling | API keys stored as HMAC-SHA256 hashes under a server-side pepper and never recoverable in plaintext; runtime secrets held in Google Secret Manager, never in source control |
| Tenant isolation | Every tenant-owned query proves organization ownership in SQL, with composite foreign keys enforcing it at the schema level. Organization, environment, and provider-tenant claims supplied by a client are never trusted |
| Access control | Role-scoped console access per organization; environment-scoped API keys separating test from live; one-time key reveal with immediate revocation |
| Data minimization | Per-connection zero-retention mode that writes no accounting record data; time-boxed expiry with a scheduled clearing job for cached data |
| Integrity | Idempotency required on mutations; durable operations persisting step state, attempts, leases, and terminal errors; a transactional outbox committed with the work; signed outbound webhooks and verified inbound provider webhooks |
| Logging and accountability | Audit events recording actor, action, target, and request identifier. Secrets, tokens, authorization codes, raw webhook bodies, and API keys are never logged |
| Resilience | Managed PostgreSQL with automated backups and point-in-time recovery; stateless API instances; retries, leases, and dead-letter state that surface failure rather than hide it |
| Secure development | Version control with reviewed changes, typed public contracts validated at the HTTP boundary, automated test and build gates, and dependency updates |
Subprocessors
The Controller gives general written authorization for AccountingKit to engage subprocessors. The current list is published at accountingkit.dev/subprocessors and forms part of this addendum.
AccountingKit imposes data protection obligations on each subprocessor that are no less protective than those in this addendum, and remains fully liable to the Controller for its subprocessors' performance.
AccountingKit will give at least 30 days' notice before adding or replacing a subprocessor, by email to account contacts and by updating the published list. The Controller may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the affected part of the service and receive a pro-rata refund of prepaid, unused fees.
Data subject requests
Taking into account the nature of the processing, AccountingKit assists the Controller in responding to requests to exercise data subject rights. The service's API lets the Controller read, correct, and delete records directly, which is usually the fastest route.
If a data subject contacts AccountingKit directly about data processed on the Controller's behalf, AccountingKit will not respond substantively. It will forward the request to the Controller without undue delay and direct the data subject to the Controller.
Personal data breach notification
AccountingKit notifies the Controller without undue delay, and in any event within72 hours of becoming aware of a personal data breach affecting the Controller's data. The notice will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent that information is available, with updates as the investigation proceeds.
AccountingKit does not notify supervisory authorities or data subjects on the Controller's behalf unless the Controller instructs it in writing, since the assessment and the obligation are the Controller's.
Assistance and audits
AccountingKit assists the Controller with data protection impact assessments and prior consultations with supervisory authorities, so far as the Controller reasonably requires it and the information is available to AccountingKit.
AccountingKit makes available the information necessary to demonstrate compliance with Article 28, and will answer reasonable security questionnaires by email. The security measures above, the subprocessor list, and the security page are published precisely so that this can usually be satisfied without a bespoke process. Where a supervisory authority requires more, or where the published material genuinely does not answer the question, the parties will agree a proportionate way to close the gap that does not expose other customers' data or AccountingKit's production secrets.
International transfers
Accounting data is processed in europe-west3 (Frankfurt, Germany) and rests in the European Union. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the transfer relies on the European Commission's Standard Contractual Clauses of 4 June 2021, with the UK International Data Transfer Addendum and the Swiss amendments applied where relevant. Those clauses are incorporated into this addendum by reference.
For those clauses: Module Two applies where the Controller is a controller, Module Three where the Controller is itself a processor. The Controller is the data exporter and AccountingKit is the data importer. The optional docking clause applies. The governing law and forum are those stated in the Terms of Service, and where the clauses require a member state, Ireland. Annex I is the record of processing above; Annex II is the security measures; Annex III is the subprocessor list.
Return and deletion
The Controller can export its data through the API at any time during the term. On termination, AccountingKit deletes the Controller's personal data within thirty days, except where law requires retention — principally billing records, which are kept for the statutory period and remain subject to this addendum until deleted.
Deleting an organization cascades through the database to its environments, connections, accounting records, and operations. Backups roll off on their own schedule and are not restored into the live system.
Precedence and liability
Where this addendum conflicts with the Terms of Service on the processing of personal data, this addendum controls. Where it conflicts with the Standard Contractual Clauses, the clauses control. Each party's liability under this addendum is subject to the limitations in the Terms of Service, except where data protection law does not permit that limitation.