Skip to content
AccountingKit
WorkflowsAPIUse casesPricingDocs
Log in
WorkflowsAPIUse casesPricingDocsLog in

Legal

Data Processing Addendum

This addendum governs AccountingKit's processing of personal data on your behalf. It is incorporated into the Terms of Service and applies automatically — you do not need to sign a separate copy unless your procurement process requires one.

Version
1.0
Effective
1 September 2026
Questions
privacy@accountingkit.dev

On this page

  1. Roles and scope
  2. Processing instructions
  3. Record of processing
  4. Personnel
  5. Security measures
  6. Subprocessors
  7. Data subject requests
  8. Breach notification
  9. Assistance and audits
  10. International transfers
  11. Return and deletion
  12. Precedence and liability

Roles and scope

This Data Processing Addendum forms part of the Terms of Service between AccountingKit (Processor) and the customer organization (Controller). It applies wherever AccountingKit processes personal data on the Controller's behalf in the course of providing the service.

In this addendum, personal data, processing, controller, processor, data subject, and supervisory authority have the meanings given in the EU General Data Protection Regulation. Equivalent concepts in the UK GDPR, India's Digital Personal Data Protection Act, and comparable laws are read accordingly.

Where AccountingKit acts as a controller in its own right — for console account records and website visitors — the Privacy Policy applies instead of this addendum.

If you need a signed copy on your own paper, or with your entity named in the header, write to privacy@accountingkit.dev and we will execute one.

Processing instructions

AccountingKit processes personal data only on the Controller's documented instructions. The Controller's instructions are: the Terms of Service, this addendum, the configuration chosen in the developer console, and the API calls and workflow definitions the Controller issues. Nothing else instructs us.

AccountingKit will tell the Controller if, in its opinion, an instruction infringes data protection law, and may pause that processing until the instruction is resolved. AccountingKit will not process the personal data for its own purposes, will not sell it, and will not use it to train machine-learning models.

Where law requires processing beyond the Controller's instructions, AccountingKit will inform the Controller before processing unless that law prohibits the notice on important grounds of public interest.

Record of processing

This is the Article 28(3) description of the processing, and the Annex I record.

ItemDetail
Subject matterProviding a unified accounting API and durable workflow execution against the Controller's connected accounting system
Duration The term of the Terms of Service, plus the deletion period described below
Nature and purposeAuthenticating to the accounting provider; reading, normalizing, creating, and updating accounting records; executing multi-step operations with retries and replay; delivering signed webhooks; recording usage for billing; and storing data where the connection's retention mode permits it
Categories of data subjectThe Controller's customers, suppliers, contacts, and employees, as represented in the connected accounting organization; and the Controller's own console users
Categories of personal dataNames, business and personal contact details, postal addresses, tax identifiers, bank account details where the provider exposes them, transaction and invoice content, payment records, and provider record identifiers
Special category dataNone is required or requested by the service. The Controller should not send it. If the Controller's accounting records contain it, it is processed only as opaque record content
FrequencyContinuous, triggered by the Controller's API calls, scheduled synchronization, and provider webhooks
RetentionZero-retention connections: no accounting record data is stored. Cached connections:30 days from the last sync, then cleared. See the retention schedule

Personnel

AccountingKit limits access to personal data to personnel who need it to operate the service or to support the Controller. Those personnel are bound by written confidentiality obligations that survive the end of their engagement, and their access is removed when it is no longer needed. Production access is granted through individually attributable accounts, not shared credentials.

Security measures

AccountingKit implements the technical and organizational measures below, which form the Annex II record. They are the measures actually in place, not aspirations.

MeasureImplementation
Encryption in transitTLS on every external connection, with HSTS enforced on every public origin
Encryption at restProvider OAuth credentials and raw provider payloads sealed with AES-256-GCM envelope encryption under a Google Cloud KMS key held in europe-west3 (Frankfurt, Germany); database and disk encryption at the platform layer
Credential handlingAPI keys stored as HMAC-SHA256 hashes under a server-side pepper and never recoverable in plaintext; runtime secrets held in Google Secret Manager, never in source control
Tenant isolationEvery tenant-owned query proves organization ownership in SQL, with composite foreign keys enforcing it at the schema level. Organization, environment, and provider-tenant claims supplied by a client are never trusted
Access controlRole-scoped console access per organization; environment-scoped API keys separating test from live; one-time key reveal with immediate revocation
Data minimizationPer-connection zero-retention mode that writes no accounting record data; time-boxed expiry with a scheduled clearing job for cached data
IntegrityIdempotency required on mutations; durable operations persisting step state, attempts, leases, and terminal errors; a transactional outbox committed with the work; signed outbound webhooks and verified inbound provider webhooks
Logging and accountabilityAudit events recording actor, action, target, and request identifier. Secrets, tokens, authorization codes, raw webhook bodies, and API keys are never logged
ResilienceManaged PostgreSQL with automated backups and point-in-time recovery; stateless API instances; retries, leases, and dead-letter state that surface failure rather than hide it
Secure developmentVersion control with reviewed changes, typed public contracts validated at the HTTP boundary, automated test and build gates, and dependency updates

Subprocessors

The Controller gives general written authorization for AccountingKit to engage subprocessors. The current list is published at accountingkit.dev/subprocessors and forms part of this addendum.

AccountingKit imposes data protection obligations on each subprocessor that are no less protective than those in this addendum, and remains fully liable to the Controller for its subprocessors' performance.

AccountingKit will give at least 30 days' notice before adding or replacing a subprocessor, by email to account contacts and by updating the published list. The Controller may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the affected part of the service and receive a pro-rata refund of prepaid, unused fees.

Data subject requests

Taking into account the nature of the processing, AccountingKit assists the Controller in responding to requests to exercise data subject rights. The service's API lets the Controller read, correct, and delete records directly, which is usually the fastest route.

If a data subject contacts AccountingKit directly about data processed on the Controller's behalf, AccountingKit will not respond substantively. It will forward the request to the Controller without undue delay and direct the data subject to the Controller.

Personal data breach notification

AccountingKit notifies the Controller without undue delay, and in any event within72 hours of becoming aware of a personal data breach affecting the Controller's data. The notice will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent that information is available, with updates as the investigation proceeds.

AccountingKit does not notify supervisory authorities or data subjects on the Controller's behalf unless the Controller instructs it in writing, since the assessment and the obligation are the Controller's.

Assistance and audits

AccountingKit assists the Controller with data protection impact assessments and prior consultations with supervisory authorities, so far as the Controller reasonably requires it and the information is available to AccountingKit.

AccountingKit makes available the information necessary to demonstrate compliance with Article 28, and will answer reasonable security questionnaires by email. The security measures above, the subprocessor list, and the security page are published precisely so that this can usually be satisfied without a bespoke process. Where a supervisory authority requires more, or where the published material genuinely does not answer the question, the parties will agree a proportionate way to close the gap that does not expose other customers' data or AccountingKit's production secrets.

International transfers

Accounting data is processed in europe-west3 (Frankfurt, Germany) and rests in the European Union. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the transfer relies on the European Commission's Standard Contractual Clauses of 4 June 2021, with the UK International Data Transfer Addendum and the Swiss amendments applied where relevant. Those clauses are incorporated into this addendum by reference.

For those clauses: Module Two applies where the Controller is a controller, Module Three where the Controller is itself a processor. The Controller is the data exporter and AccountingKit is the data importer. The optional docking clause applies. The governing law and forum are those stated in the Terms of Service, and where the clauses require a member state, Ireland. Annex I is the record of processing above; Annex II is the security measures; Annex III is the subprocessor list.

Return and deletion

The Controller can export its data through the API at any time during the term. On termination, AccountingKit deletes the Controller's personal data within thirty days, except where law requires retention — principally billing records, which are kept for the statutory period and remain subject to this addendum until deleted.

Deleting an organization cascades through the database to its environments, connections, accounting records, and operations. Backups roll off on their own schedule and are not restored into the live system.

Precedence and liability

Where this addendum conflicts with the Terms of Service on the processing of personal data, this addendum controls. Where it conflicts with the Standard Contractual Clauses, the clauses control. Each party's liability under this addendum is subject to the limitations in the Terms of Service, except where data protection law does not permit that limitation.

Related

Terms of ServiceThe contract that governs access to the API, the console, and workflow execution.Privacy PolicyWhat personal data AccountingKit handles, why, where it lives, and for how long.SubprocessorsEvery third party in the processing chain, what it touches, and where it runs.Acceptable Use PolicyWhat you may not run through AccountingKit, and what happens if you do.Cookie NoticeThe marketing site sets no cookies. The console sets one, and it is essential.SecurityThe controls behind the platform, stated plainly, including the ones not yet certified.
AccountingKit

Accounting workflows for the systems businesses already use.

hello@accountingkit.dev
ProductWorkflowsUnified APIUse casesPricing
DevelopersDocumentationDeveloper consolellms.txt
CompanyFAQSecurityReport a vulnerability
LegalTermsPrivacyDPASubprocessorsAcceptable useCookies
© 2026 AccountingKit. All rights reserved.AccountingKit is an independent product and is not affiliated with, endorsed by, or sponsored by any accounting software vendor. Xero is a trademark of Xero Limited. QuickBooks is a trademark of Intuit Inc. Sage and Sage Intacct are trademarks of The Sage Group plc. FreshBooks and Wave are trademarks of their respective owners, as are all other product names and marks used here for identification only.