Skip to content
AccountingKit
WorkflowsAPIUse casesPricingDocs
Log in
WorkflowsAPIUse casesPricingDocsLog in

Legal

Subprocessors

This is the whole list. AccountingKit runs a deliberately small processing chain, because every name here is a name your customers have to trust as well.

Version
1.0
Effective
1 September 2026
Questions
privacy@accountingkit.dev

On this page

  1. Current subprocessors
  2. Your accounting provider
  3. Not currently engaged
  4. Change notice and objection

Current subprocessors

Each subprocessor below is engaged under a written contract that binds it to data protection obligations no less protective than those in our Data Processing Addendum. AccountingKit remains fully liable to you for their performance.

SubprocessorPurposeData it can touchProcessing location
Google Cloud
Google Cloud EMEA Limited
Application compute (Cloud Run), the primary PostgreSQL database (Cloud SQL), encryption key management (Cloud KMS), and secret storage (Secret Manager)All customer data held by the service, including console accounts, connections, stored accounting records, and workflow stateGermany — europe-west3 (Frankfurt, Germany)
Cloudflare
Cloudflare, Inc.
DNS, TLS termination, CDN, and static asset hosting for the marketing site and the developer consoleRequest metadata only — IP address, user agent, requested URL, timestamp. No accounting data is stored at the edgeGlobal edge network
Resend
Plus Five Five, Inc.
Transactional email delivery — sign-in messages, team invitations, and operational noticesRecipient name and email address, and the content of that messageUnited States
Vercel
Vercel, Inc.
Hosting for the documentation site at docs.accountingkit.devRequest metadata for documentation pages only. The documentation site is static and holds no customer dataGlobal edge network
Dodo Payments
Merchant of record
Subscription checkout, payment processing, invoicing, and sales tax handling. Dodo Payments is the seller of record on your receiptBilling contact name and email, billing country, tax identifier, and transaction records. No accounting record dataGlobal

This list is complete and current as of the effective date at the top of this page.

Your accounting provider is not our subprocessor

Xero, and any accounting platform you connect, is a third party you hold a relationship with and instruct us to reach on your behalf. It is not engaged by AccountingKit, and it processes your data under your agreement with it, not ours.

We mention this because procurement reviews frequently ask. The distinction matters: revoking AccountingKit's access does not affect your provider account, and our subprocessor commitments do not extend to a platform we do not engage.

Not currently engaged

The platform supports several integrations that production does not use today. We list them so that reading the code, or a future release note, does not look like an undisclosed change:

  • Object storage. Disabled in production. No files are stored with a third-party object store.
  • Third-party error monitoring. Not enabled in production. Application errors are captured in the platform's own logs, which exclude secrets and payload bodies.
  • Social sign-in. No third-party identity provider is enabled for console sign-in.

Turning any of these on would be a subprocessor change and would follow the notice process below.

Change notice and objection

We give at least 30 days' notice before adding or replacing a subprocessor. Notice goes by email to your account contacts and by updating this page and its effective date.

You may object on reasonable data protection grounds within that period by writing to privacy@accountingkit.dev. We will work with you to resolve it. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid, unused fees.

To be notified of changes here, email us and ask to be added to the subprocessor notice list.

Related

Terms of ServiceThe contract that governs access to the API, the console, and workflow execution.Privacy PolicyWhat personal data AccountingKit handles, why, where it lives, and for how long.Data Processing AddendumArticle 28 processor terms, the processing record, security measures, and transfer safeguards.Acceptable Use PolicyWhat you may not run through AccountingKit, and what happens if you do.Cookie NoticeThe marketing site sets no cookies. The console sets one, and it is essential.SecurityThe controls behind the platform, stated plainly, including the ones not yet certified.
AccountingKit

Accounting workflows for the systems businesses already use.

hello@accountingkit.dev
ProductWorkflowsUnified APIUse casesPricing
DevelopersDocumentationDeveloper consolellms.txt
CompanyFAQSecurityReport a vulnerability
LegalTermsPrivacyDPASubprocessorsAcceptable useCookies
© 2026 AccountingKit. All rights reserved.AccountingKit is an independent product and is not affiliated with, endorsed by, or sponsored by any accounting software vendor. Xero is a trademark of Xero Limited. QuickBooks is a trademark of Intuit Inc. Sage and Sage Intacct are trademarks of The Sage Group plc. FreshBooks and Wave are trademarks of their respective owners, as are all other product names and marks used here for identification only.