Data Processing Agreement

Effective: September 2026 ยท Last updated: September 2026

This DPA forms part of the KontraBooks Terms of Service and applies automatically to all customers who process personal data using the KontraBooks platform. No separate signature is required.

1. Definitions

ControllerThe customer (you) who determines the purposes and means of processing personal data using KontraBooks.
ProcessorKontraBooks, acting on the Controller's instructions to process personal data.
Personal DataAny information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1).
ProcessingAny operation performed on personal data, including collection, storage, use, disclosure, or deletion.
Sub-processorA third party engaged by KontraBooks to process personal data on behalf of the Controller.
GDPRRegulation (EU) 2016/679 of the European Parliament and of the Council.
Data SubjectAn individual whose personal data is processed - typically the Controller's employees, customers, or vendors.

2. Subject matter, nature, and purpose

KontraBooks processes personal data on behalf of the Controller for the following purposes:

  • Storing and managing the Controller's accounting records (invoices, bills, expenses, contacts, payments)
  • Generating financial reports from Controller data
  • Sending invoice and reminder emails to the Controller's customers on the Controller's behalf
  • Providing access to the service to users authorised by the Controller

The duration of processing corresponds to the term of the Controller's subscription, plus any retention period required by law or this DPA.

3. Categories of personal data and data subjects

Data subjects

The Controller's authorised users (employees, accountants); the Controller's customers and vendors whose details are entered into the platform.

Categories of personal data

  • Identity data: names, email addresses
  • Contact data: postal addresses, phone numbers (where provided)
  • Financial data: invoice amounts, payment records, account codes
  • Tax data: tax identification numbers (where provided)
  • Account credentials: email addresses used for platform access

KontraBooks does not process special categories of personal data (sensitive data as defined in GDPR Article 9) unless the Controller enters such data into the platform, in which case the Controller is solely responsible for the lawful basis for that processing.

4. Processor obligations (Article 28(3) GDPR)

KontraBooks commits to the following:

Instructions

Process personal data only on documented instructions from the Controller, unless required to do so by applicable law. KontraBooks will inform the Controller if any instruction infringes GDPR.

Confidentiality

Ensure that all personnel authorised to process personal data are bound by confidentiality obligations.

Security

Implement and maintain appropriate technical and organisational measures to protect personal data, as described in Annex A of this DPA.

Sub-processors

Not engage a sub-processor without prior general written authorisation from the Controller. The current sub-processor list is published at kontrabooks.com/legal/subprocessors. KontraBooks will give at least 30 days' notice of changes, during which the Controller may raise a reasoned objection.

Data subject rights

Assist the Controller in fulfilling data subject rights requests (access, rectification, erasure, portability, restriction, objection) to the extent technically feasible. Requests will be acknowledged within 72 hours.

Security assistance

Notify the Controller without undue delay (and within 24 hours) upon becoming aware of a personal data breach. Provide all information necessary for the Controller to meet its obligations under GDPR Articles 33 and 34.

Deletion or return

Upon termination of the agreement, at the Controller's choice, delete or return all personal data and delete existing copies, unless retention is required by law. Controllers may export their data within 30 days of account termination.

Audit rights

Make available all information necessary to demonstrate compliance with this DPA. Allow for and contribute to audits conducted by the Controller or a mandated third-party auditor, subject to reasonable notice and confidentiality obligations. KontraBooks may provide security certification reports (such as SOC 2 or equivalent) as an alternative to on-site audits where appropriate.

5. International data transfers

Personal data is hosted on infrastructure located in the European Union. Where KontraBooks transfers personal data to sub-processors outside the EEA, it does so only where one of the following conditions is met:

  • The destination country benefits from an adequacy decision by the European Commission
  • Standard Contractual Clauses (SCCs) as approved by the European Commission are in place
  • Another lawful transfer mechanism under GDPR Chapter V applies

Transfer mechanism details for each sub-processor are available upon request at privacy@kontrabooks.com.

6. Annex A - Security measures

KontraBooks implements the following technical and organisational security measures:

Encryption in transit

All data transmitted between users and the service is encrypted using TLS 1.2 or higher.

Encryption at rest

All data stored in our database and backups is encrypted at rest.

Access controls

Access to production systems is restricted to authorised personnel only, using multi-factor authentication and the principle of least privilege.

Authentication security

Short-lived access tokens with automatic rotation; httpOnly and Secure cookie flags; brute-force protection with automatic lockout after repeated failed attempts.

Audit logging

All significant data access and modification events are logged with timestamps and user identifiers.

Backups

Regular automated backups with a rolling 30-day retention window. Backups are encrypted.

Vulnerability management

Regular dependency audits and security reviews. Critical vulnerabilities are patched within 30 days of disclosure.

Breach response

A documented incident response plan. The Controller will be notified within 24 hours of a confirmed breach.

Physical security

All infrastructure is hosted on a major cloud provider with ISO 27001 certification. No personal data is stored on physical media under KontraBooks' direct control.

7. Governing law

This DPA is governed by the laws applicable to the KontraBooks Terms of Service. For EU customers, this DPA is construed in accordance with GDPR. In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection matters.

8. How this DPA applies to you

By using the KontraBooks service, you (the Controller) agree to the terms of this DPA. No separate signature is required. If you require a countersigned DPA for enterprise procurement purposes, contact privacy@kontrabooks.com.

See also our Privacy Policy, Sub-processors, and Cookie Policy.