Data Processing Addendum
Last updated: September 3, 2026
This Data Processing Addendum (“DPA”) forms part of the End-User License Agreement, or any other written agreement, between the customer identified in that agreement (“Customer,” “you”) and Automate Accounting (“Automate Accounting,” “we,” “us”) governing your use of the Automate Accounting application (the “Agreement”). It applies to the extent Automate Accounting processes Personal Data on your behalf in providing the Application. If this DPA and the Agreement conflict on the subject of data protection, this DPA prevails. Capitalised terms not defined here have the meaning given in the Agreement.
1. Definitions
- “Application” means the software and related services provided under the Agreement, as described in the Privacy Policy.
- “Customer Data” means all data, including Personal Data, that you or your users submit to, upload to, or generate in the Application, including data retrieved from systems you connect to it (such as QuickBooks Online or a bank feed).
- “Personal Data” means information within Customer Data that relates to an identified or identifiable natural person, or that is “personal information” (or the equivalent) under Data Protection Laws.
- “Data Protection Laws” means all laws applicable to the processing of Personal Data under this DPA, including, where applicable, the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”); the GDPR as incorporated into United Kingdom law (“UK GDPR”) and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection (“FADP”); the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”); and other United States state privacy laws.
- “Controller,” “Processor,” “Data Subject,” “Processing,” “Supervisory Authority” and “Personal Data Breach” have the meanings given in the GDPR. “Business,” “Service Provider,” “Sell” and “Share” have the meanings given in the CCPA. Where the CCPA applies, “Processor” includes “Service Provider” and “Controller” includes “Business.”
- “Subprocessor” means a third party engaged by Automate Accounting to process Personal Data on its behalf in providing the Application.
- “Security Incident” means a Personal Data Breach affecting Personal Data in Automate Accounting’s possession or control.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
2. Roles and Scope
2.1 Roles
As between the parties, you are the Controller of Personal Data and Automate Accounting is the Processor, except where you act as a Processor on behalf of a third-party Controller (Section 2.2), in which case Automate Accounting acts as your Subprocessor.
2.2 Firms and their clients
Where you are an accounting, bookkeeping or advisory firm keeping books in the Application on behalf of your own clients, you are a Processor for those clients and Automate Accounting is your Subprocessor. You warrant that your agreements with those clients permit you to engage Automate Accounting on the terms of this DPA and that your instructions under this DPA are consistent with your obligations to them.
2.3 Accounting Advisor
Accounting Advisor is a separate legal entity under shared ownership with Automate Accounting. It is not a party to this DPA and does not process Customer Data under it. If you engage Accounting Advisor for advisory or controller services, it processes Customer Data under its own agreement with you, and you grant it access to your books yourself, through the Application’s own access controls.
2.4 Your responsibilities
You are responsible for:
- the lawfulness of the Personal Data you make available to the Application and of your instructions;
- providing any notices to, and obtaining any consents from, Data Subjects;
- the accuracy and content of Customer Data; and
- configuring the Application’s access controls — user accounts, roles, per-company permissions, multi-factor authentication and external sharing — for your circumstances.
3. Processing on Instructions
3.1 Documented instructions
Automate Accounting will process Personal Data only on your documented instructions, which are: the Agreement, this DPA, and your and your users’ use of the Application’s features (including the connections you authorise and the sharing you configure). Automate Accounting will not process Personal Data for any other purpose.
3.2 Legal requirements
If Automate Accounting is required by law to process Personal Data other than on your instructions, it will inform you before doing so unless the law prohibits that on important grounds of public interest.
3.3 Infringing instructions
Automate Accounting will inform you if, in its opinion, an instruction infringes Data Protection Laws. It is not obliged to perform a legal review of your instructions.
3.4 CCPA service-provider terms
Where the CCPA applies, Automate Accounting is a Service Provider and:
- will not Sell or Share Personal Data;
- will not retain, use or disclose Personal Data for any purpose other than the business purposes specified in this DPA and the Agreement, or outside the direct business relationship between the parties;
- will not combine Personal Data with personal information it receives from other sources, except as the CCPA permits;
- will notify you if it determines it can no longer meet its obligations under the CCPA; and
- grants you the right to take reasonable and appropriate steps to stop and remediate unauthorised use of Personal Data.
Automate Accounting certifies that it understands these restrictions and will comply with them.
4. Confidentiality
Automate Accounting will ensure that persons authorised to process Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality, and that access to Personal Data is limited to those who need it to provide, support or secure the Application.
5. Security
Automate Accounting will implement and maintain the technical and organisational measures described in Annex II, and will not materially reduce the overall level of protection they provide during the term of the Agreement. Annex II describes measures that exist and are in use, not intentions. Capabilities still under development are not relied on in this Addendum.
The measures in Annex II are designed for the categories of Personal Data described in Annex I. You are responsible for assessing whether they are appropriate for the Personal Data you choose to process, and for the security of your own systems, credentials and users.
6. Subprocessors
6.1 General authorisation
You give Automate Accounting general authorisation to engage Subprocessors to provide the Application. The Subprocessors engaged at the date of this DPA are set out in Annex III.
6.2 Notice and objection
Automate Accounting will notify you by email, to the administrative contact on your account, at least thirty (30) days before authorising a new Subprocessor to process Personal Data, or replacing one. You may object in writing within that period on reasonable, documented data-protection grounds. The parties will discuss the objection in good faith; if it cannot be resolved, you may terminate the affected part of the Application, or the Agreement, on written notice without penalty, and Automate Accounting will refund any prepaid fees for the period after termination.
6.3 Subprocessor obligations
Automate Accounting will impose on each Subprocessor, by written contract, data-protection obligations no less protective than those in this DPA, to the extent applicable to the services the Subprocessor provides, and remains responsible to you for the Subprocessor’s performance of them.
7. Data Subject Requests
7.1 The Application's own features
The Application is the first means of responding to Data Subject requests: you can access, correct, export and delete Personal Data in your books directly, and the audit trail records who did so.
7.2 Assistance
Taking into account the nature of the processing, Automate Accounting will assist you, by appropriate technical and organisational measures and insofar as possible, in fulfilling your obligation to respond to requests from Data Subjects to exercise their rights.
7.3 Requests received directly
If Automate Accounting receives a request from a Data Subject relating to Personal Data it processes for you, it will, to the extent legally permitted, promptly forward the request to you and will not respond to it except on your instructions or where required by law. If the request concerns a user’s own account, Automate Accounting may direct the user to you and to the Application’s account features.
8. Security Incidents
8.1 Notification
Automate Accounting will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting your Personal Data. Notification is sent to the administrative contact on your account.
8.2 Content
The notification will describe, to the extent then known, the nature of the incident, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point. Information not available at the time of the first notification is provided in phases as it becomes available.
8.3 Response
Automate Accounting will take reasonable steps to contain and remediate the incident and will cooperate with you in your own notification obligations. A notification under this Section is not an acknowledgement of fault or liability.
9. Assistance With Assessments
Taking into account the nature of the processing and the information available to it, Automate Accounting will provide reasonable assistance to you with data protection impact assessments and with prior consultation of a Supervisory Authority, where Data Protection Laws require them in respect of the Application.
10. Records, Information and Audits
10.1 Information
On request, Automate Accounting will make available the information reasonably necessary to demonstrate compliance with this DPA, including written responses to a reasonable security questionnaire.
10.2 Third-party reports
Automate Accounting does not currently hold a third-party audit report or certification, such as a SOC 2 report, and does not represent otherwise in this Addendum or elsewhere. If and when such a report is obtained, providing it will satisfy an audit request under Section 10.3 to the extent of its scope.
10.3 Audits
Not more than once in any twelve-month period, on at least thirty (30) days’ written notice, you (or an independent auditor you appoint who is reasonably acceptable to Automate Accounting and bound by confidentiality) may audit Automate Accounting’s compliance with this DPA. Audits are conducted during business hours, are limited to what is reasonably necessary, may not access other customers’ data, and are at your cost unless they reveal a material breach of this DPA. An audit is also permitted, without the frequency limit, where required by a Supervisory Authority or following a Security Incident.
11. International Transfers
11.1 Hosting
The Application is hosted on infrastructure in the United States (currently in the US-West region, Oregon). Customer Data is stored and processed there, and may be accessed from the locations where Automate Accounting’s personnel and Subprocessors operate.
11.2 Transfers from the EEA
To the extent Automate Accounting processes Personal Data subject to the GDPR that is transferred to a country not recognised by the European Commission as providing adequate protection, the parties enter into the SCCs, which are incorporated into this DPA by reference, on the following basis:
- Module Two (controller to processor) applies where you are a Controller, and Module Three (processor to processor) where you are a Processor;
- Clause 7 (docking clause) is included;
- under Clause 9, Option 2 (general written authorisation) applies, with the notice period in Section 6.2;
- the optional language in Clause 11 is not included;
- under Clause 13, the competent Supervisory Authority is that of the EU Member State in which the data exporter is established, or otherwise the authority determined under Annex I.C;
- under Clause 17 (Option 1), the SCCs are governed by the law of the EU Member State in which the data exporter is established or, where that law does not allow for third-party beneficiary rights, the law of Ireland; under Clause 18, disputes are resolved by the courts of that Member State; and
- Annexes I and II to the SCCs are completed by Annexes I and II to this DPA, and Annex III to the SCCs by Annex III to this DPA.
11.3 Transfers from the United Kingdom
For Personal Data subject to the UK GDPR, the SCCs as completed above apply as modified by the UK Addendum, which is incorporated by reference. Tables 1 to 3 of the UK Addendum are completed by the information in this DPA and its Annexes, and for Table 4 either party may end the UK Addendum as set out in its Section 19.
11.4 Transfers from Switzerland
For Personal Data subject to the FADP, the SCCs apply with the adaptations the Swiss Federal Data Protection and Information Commissioner requires: references to the GDPR are read as references to the FADP, “Member State” includes Switzerland so that Swiss Data Subjects may bring claims in Switzerland, and the competent Supervisory Authority is the Federal Data Protection and Information Commissioner.
11.5 Replacement mechanisms
If a mechanism relied on above is invalidated or replaced, the parties will cooperate in good faith to put an alternative lawful transfer mechanism in place, and Automate Accounting may update this Section accordingly on notice to you.
12. Return and Deletion
12.1 During the term
You can export Customer Data at any time through the Application — statements, ledgers, the trial balance, journal detail and the documents attached to them — including as a complete due-diligence package. There is no export tier and no charge to leave.
12.2 On termination
On termination or expiry of the Agreement, Automate Accounting will, at your choice, return Customer Data by the same exports or delete it. Absent an instruction, Automate Accounting will delete Customer Data within thirty (30) days after termination, and from backup copies in the ordinary course of the backup cycle thereafter, except where retention is required by applicable law, in which case the retained data remains subject to this DPA and is deleted when that requirement ends.
12.3 Integrity records
The audit trail — the record of who did what in the Application, and the tamper-evident chain over it — is designed so that it cannot be edited or deleted, which is what makes it evidence. Entries in it that identify your users are retained on that basis and under the record-keeping obligations that apply to books of account; they are not used for any other purpose, and access to them is restricted as described in Annex II.
13. Liability
Each party’s liability arising out of or related to this DPA, including the SCCs, is subject to the exclusions and limitations of liability in the Agreement, except to the extent Data Protection Laws or the SCCs do not permit them to be limited. Each party is liable for its own breach of this DPA. Where you are a Processor for a third-party Controller, that Controller is not a third-party beneficiary of this DPA except as the SCCs provide.
14. Term, Precedence and Changes
14.1 Term
This DPA forms part of the Agreement and takes effect when you accept the Agreement, including by accepting it at sign-up. It continues for as long as Automate Accounting processes Personal Data for you, including the return-and-deletion period in Section 12. No separate signature is required for it to apply.
14.2 Precedence
In the event of conflict, the following order of precedence applies: the SCCs (where they apply), then this DPA, then the Agreement.
14.3 Changes
Automate Accounting may update this DPA to reflect changes in Data Protection Laws, in the Application, or in its Subprocessors, by publishing the revised version at this address and, for material changes, notifying the administrative contact on your account at least thirty (30) days before they take effect. A change that materially reduces the protections in this DPA gives you the termination right in Section 6.2.
15. Contact
Requests, notices and questions under this DPA go to contact@automate-accounting.com. This DPA applies from acceptance without a signature; where your own process requires a countersigned copy, Automate Accounting will execute one on request and provide it with Annex III completed.
Annex I — Details of the Processing
A. The parties
- Data exporter: Customer, as identified in the Agreement, acting as Controller or Processor as set out in Section 2.
- Data importer: Automate Accounting, acting as Processor (or Subprocessor).
- Contact points: the administrative contact on the Customer’s account, and contact@automate-accounting.com for Automate Accounting.
B. Description of the processing
- Subject matter: provision of the Application — multi-entity accounting software — under the Agreement.
- Duration: the term of the Agreement plus the return-and-deletion period in Section 12.
- Nature and purpose: hosting, storage, transmission, retrieval and display of Customer Data; posting and reporting on accounting records; importing bank transactions, payroll data and documents; extracting data from uploaded documents where you enable that feature; transmitting electronic invoices where you enable that feature; sending the notifications and emails you configure; providing support; and securing and operating the Application, including its audit trail.
- Categories of Data Subjects: your users and personnel; your customers, vendors and their contacts; your employees and contractors, where you process payroll or expenses; the recipients you share documents or reports with (lenders, investors, auditors); and, where you are a firm, the equivalent categories for each client whose books you keep.
- Categories of Personal Data: identification and contact details (names, email addresses, postal addresses, phone numbers, job titles); account and authentication data (credentials stored as one-way hashes, multi-factor enrolments, session and login records); financial and transaction data (invoices, bills, payments, journal entries, bank transactions and the descriptions they carry, bank account identifiers); payroll and expense data (compensation, deductions, reimbursements and the tax identifiers those records require); the content of documents you upload as evidence, which may contain any of the above; and usage data (IP address, browser information, timestamps and the actions recorded in the audit trail).
- Special categories of data: the Application is not designed for, and Automate Accounting does not require, special categories of Personal Data. Such data may be present incidentally in documents or payroll records you choose to upload; you are responsible for limiting it to what you need and for any additional safeguards it requires.
- Frequency: continuous, for the term.
- Retention: as set out in Section 12.
- Transfers to Subprocessors: to the Subprocessors in Annex III, for the purposes and duration stated there.
C. Competent Supervisory Authority
Determined in accordance with Clause 13 of the SCCs, as set out in Section 11.2.
Annex II — Technical and Organisational Measures
These are the measures in place at the date of this DPA. They describe the Application as it runs today; capabilities that have not been released are not counted here, whatever is said about them elsewhere.
- Tenant separation. Each customer’s records are kept separate at the database itself: row-level security policies are enforced on every customer-scoped table, so a session working in one company cannot read another’s records even if a query asks for them. The separation is tested automatically every day against the live database, and a failure raises an alert.
- Encryption in transit. All connections use TLS. The Application sends HTTP Strict Transport Security with a two-year lifetime and preload, so browsers refuse unencrypted connections.
- Encryption at rest. Customer Data is stored on managed infrastructure that encrypts storage at rest. Integration credentials (such as bank-feed and accounting-platform tokens) and multi-factor secrets are additionally encrypted at the application layer with dedicated keys held separately from the database.
- Authentication. Passwords are stored only as salted one-way hashes. Multi-factor authentication (time-based one-time codes) and passkeys are available to every user; active sessions are recorded and can be reviewed and revoked by the user.
- Authorisation. Access is governed by a firm-level role and a per-company permission set that determines what each person can see and approve. Segregation of duties is enforced where entries are written — the person who creates a transaction cannot approve it — and approval thresholds are configurable by amount.
- Audit trail and integrity. Every action of record is written to an append-only audit trail in which each record is cryptographically linked to the one before it; the ledger’s own change history and the log of who viewed or downloaded each document are kept the same way. The chains are re-verified automatically every day, and a break raises an alert.
- Verifiable exports. A sealed package produced by the Application — a reporting pack or a due-diligence package — carries the means of checking itself. It contains a manifest listing every file with the cryptographic digest that file had when the package was sealed, and a self-contained verification tool that runs on a standard runtime with no network access, no account and no contact with us. A recipient can therefore confirm that every file still matches the digest recorded for it, that no file has been added or removed, and that the manifest has not itself been altered to match changed files. Where a time-stamping authority is reachable at the moment of sealing, the package also carries a token issued by an independent RFC 3161 authority attesting that the manifest’s digest existed at a stated time, under a signature we do not control and checkable with standard tooling against a certificate obtained from that authority rather than from us. That authority receives the digest alone — never the package, its contents, or any identifier of you or your data. Sealing is never blocked by that authority’s availability, and a package states on its own face whether it carries a token.
- Change control. The database schema changes only through versioned, reviewed migrations, and a daily check confirms the production database matches the intended schema. Automated checks in the build refuse code that reads customer data outside the customer boundary or exposes a route without an authorisation check.
- Application security. A content security policy with per-request nonces, standard security headers, server-side input validation, request size limits and rate limiting on public endpoints, and bot protection on public forms. Production dependencies are kept free of known vulnerabilities, enforced in the build.
- Availability and recovery. The managed database provides continuous backup with point-in-time recovery. Scheduled automated work is monitored for silence as well as for failure, so a task that stops running raises an alert.
- Portability and deletion. Customer Data can be exported by you at any time and is deleted on termination as set out in Section 12.
- Personnel and access. Administrative access to production infrastructure is restricted to personnel who need it for their role, requires multi-factor authentication, and is not used to access Customer Data except to provide, support or secure the Application. Personnel are bound by confidentiality obligations.
- Subprocessor management. Subprocessors are engaged under written terms consistent with this DPA, and changes are notified in advance as set out in Section 6.
Annex III — Subprocessors
The Subprocessors authorised at the date of this DPA, with the purpose and location of each, are provided with every executed copy of this DPA and on request to contact@automate-accounting.com at any time. Changes are notified under Section 6.2.
© 2026 Automate Accounting. All rights reserved.
