Effective: September 2026 ยท Last updated: September 2026
This DPA forms part of the KontraBooks Terms of Service and applies automatically to all customers who process personal data using the KontraBooks platform. No separate signature is required.
KontraBooks processes personal data on behalf of the Controller for the following purposes:
The duration of processing corresponds to the term of the Controller's subscription, plus any retention period required by law or this DPA.
Data subjects
The Controller's authorised users (employees, accountants); the Controller's customers and vendors whose details are entered into the platform.
Categories of personal data
KontraBooks does not process special categories of personal data (sensitive data as defined in GDPR Article 9) unless the Controller enters such data into the platform, in which case the Controller is solely responsible for the lawful basis for that processing.
KontraBooks commits to the following:
Instructions
Process personal data only on documented instructions from the Controller, unless required to do so by applicable law. KontraBooks will inform the Controller if any instruction infringes GDPR.
Confidentiality
Ensure that all personnel authorised to process personal data are bound by confidentiality obligations.
Security
Implement and maintain appropriate technical and organisational measures to protect personal data, as described in Annex A of this DPA.
Sub-processors
Not engage a sub-processor without prior general written authorisation from the Controller. The current sub-processor list is published at kontrabooks.com/legal/subprocessors. KontraBooks will give at least 30 days' notice of changes, during which the Controller may raise a reasoned objection.
Data subject rights
Assist the Controller in fulfilling data subject rights requests (access, rectification, erasure, portability, restriction, objection) to the extent technically feasible. Requests will be acknowledged within 72 hours.
Security assistance
Notify the Controller without undue delay (and within 24 hours) upon becoming aware of a personal data breach. Provide all information necessary for the Controller to meet its obligations under GDPR Articles 33 and 34.
Deletion or return
Upon termination of the agreement, at the Controller's choice, delete or return all personal data and delete existing copies, unless retention is required by law. Controllers may export their data within 30 days of account termination.
Audit rights
Make available all information necessary to demonstrate compliance with this DPA. Allow for and contribute to audits conducted by the Controller or a mandated third-party auditor, subject to reasonable notice and confidentiality obligations. KontraBooks may provide security certification reports (such as SOC 2 or equivalent) as an alternative to on-site audits where appropriate.
Personal data is hosted on infrastructure located in the European Union. Where KontraBooks transfers personal data to sub-processors outside the EEA, it does so only where one of the following conditions is met:
Transfer mechanism details for each sub-processor are available upon request at privacy@kontrabooks.com.
KontraBooks implements the following technical and organisational security measures:
Encryption in transit
All data transmitted between users and the service is encrypted using TLS 1.2 or higher.
Encryption at rest
All data stored in our database and backups is encrypted at rest.
Access controls
Access to production systems is restricted to authorised personnel only, using multi-factor authentication and the principle of least privilege.
Authentication security
Short-lived access tokens with automatic rotation; httpOnly and Secure cookie flags; brute-force protection with automatic lockout after repeated failed attempts.
Audit logging
All significant data access and modification events are logged with timestamps and user identifiers.
Backups
Regular automated backups with a rolling 30-day retention window. Backups are encrypted.
Vulnerability management
Regular dependency audits and security reviews. Critical vulnerabilities are patched within 30 days of disclosure.
Breach response
A documented incident response plan. The Controller will be notified within 24 hours of a confirmed breach.
Physical security
All infrastructure is hosted on a major cloud provider with ISO 27001 certification. No personal data is stored on physical media under KontraBooks' direct control.
This DPA is governed by the laws applicable to the KontraBooks Terms of Service. For EU customers, this DPA is construed in accordance with GDPR. In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection matters.
By using the KontraBooks service, you (the Controller) agree to the terms of this DPA. No separate signature is required. If you require a countersigned DPA for enterprise procurement purposes, contact privacy@kontrabooks.com.
See also our Privacy Policy, Sub-processors, and Cookie Policy.