Data Processing Agreement
This Data Processing Agreement sets out Accountaire's commitments as a data processor when we handle personal data on your behalf. It meets the Article 28 UK GDPR requirements for a processor contract, is incorporated by reference into every Engagement Letter, and names the sub-processors, security measures and transfer safeguards we rely on.
Contents
- 1. Parties & status
- 2. Subject matter & duration
- 3. Processing on instructions
- 4. Confidentiality
- 5. Security measures
- 6. Sub-processors
- 7. Data subject rights
- 8. Personal data incidents
- 9. DPIAs & prior consultation
- 10. International transfers
- 11. Audits & inspections
- 12. Return & deletion of data
- 13. Liability
- 14. Governing law
- 15. Schedules
1. Parties & status
This Data Processing Agreement ("DPA") forms part of the Engagement Letter, and is read alongside our standard engagement terms, between Accountaire (SMC-Private) Limited ("Processor", "we", "us") and the client identified in that Engagement Letter ("Controller", "you").
Personal data we control in our own right, rather than process for you, is covered by our privacy policy instead. For the purposes of this DPA, you act as Data Controller and we act as Data Processor in respect of personal data we process to deliver the Services described in the Engagement Letter. Where you are yourself a processor (for example, providing services to your own customers), references in this DPA to "Controller" include your role as such.
2. Subject matter & duration
The subject matter, duration, nature and purpose of processing, categories of personal data and categories of data subjects are set out in Schedule 1. Processing continues for the duration of the Engagement Letter, plus any post-termination period reasonably required to return or delete data.
3. Processing on instructions
We process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by UK, EU or applicable law. Where such legal requirement applies, we will inform you of the requirement before processing, unless that law prohibits informing you on important grounds of public interest.
Your instructions are documented in the Engagement Letter and any subsequent written communications (including email). If we believe that an instruction infringes data protection law, we will inform you immediately.
4. Confidentiality
We ensure that all persons authorised to process personal data are under appropriate confidentiality obligations (by employment contract, contractor agreement or equivalent) and have received appropriate training on data protection.
5. Security measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including (as applicable):
- Pseudonymisation and encryption: encryption in transit (TLS 1.2+) and at rest within all cloud platforms used.
- Confidentiality, integrity, availability: multi-factor authentication enforced, role-based access controls, redundancy across SOC 2 Type II-certified providers.
- Resilience: incident response procedures, backup and recovery processes through our cloud providers.
- Testing & review: regular review of vendor SOC 2 reports and security certifications; annual internal review of our own controls.
The detailed measures applicable to your engagement are set out in Schedule 2.
6. Sub-processors
You provide general written authorisation for us to engage sub-processors. Our current sub-processors are listed in Schedule 3. We will inform you of any intended changes concerning the addition or replacement of sub-processors, giving 30 days' notice. You may object to a sub-processor on reasonable data-protection grounds within that period; if we cannot reasonably accommodate your objection, you may terminate the relevant part of the engagement without penalty.
We impose on each sub-processor, by contract, data-protection obligations no less protective than those in this DPA. We remain fully liable to you for sub-processor performance.
7. Data subject rights
Taking into account the nature of processing, we assist you by appropriate technical and organisational measures, insofar as possible, in responding to data-subject requests under Chapter III UK GDPR (access, rectification, erasure, restriction, portability, objection).
Where we receive a request directly from a data subject relating to data we process on your behalf, we will not respond directly and will refer them to you, notifying you within 48 business hours.
8. Personal data incidents
We notify you without undue delay (and in any event within 48 hours of becoming aware) of any personal data breach affecting personal data we process on your behalf. The notification will include (insofar as known):
- The nature of the breach, categories of data and data subjects affected, and approximate numbers.
- The likely consequences.
- The measures taken or proposed to address the breach and mitigate its effects.
We will assist you in any required notifications to supervisory authorities and data subjects.
9. DPIAs & prior consultation
We provide reasonable assistance with Data Protection Impact Assessments and prior consultations with supervisory authorities under Articles 35 and 36 UK GDPR, taking into account the nature of processing and information available to us.
10. International transfers
Where we transfer personal data outside the UK or EEA, we will: (a) ensure the destination has an adequacy decision; (b) implement Standard Contractual Clauses or equivalent appropriate safeguards under Article 46 UK GDPR; or (c) rely on another lawful transfer mechanism with your prior agreement.
Our principal operational location is Pakistan. Where you require data residency in the UK or EEA, we configure cloud platforms accordingly during onboarding.
11. Audits & inspections
We make available to you all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you. Audits are limited to once per calendar year (unless a personal-data incident gives reasonable grounds for additional audit), subject to 30 days' written notice, conducted during business hours and minimising disruption.
In place of physical audit, you may rely on independent third-party certifications and audit reports of our cloud platform providers (SOC 2 Type II reports) and our own internal review documentation, which we will share on reasonable request under confidentiality.
12. Return & deletion of data
At your choice on termination of the engagement, we will return all personal data to you or delete it. Return is the default. Where deletion is requested, we delete personal data within 30 days from the last live operational system and within 90 days from backups.
We may retain personal data to the extent required by applicable law (notably tax-record retention requirements). Such retained data continues to be protected under this DPA.
13. Liability
The liability provisions of the underlying Engagement Letter apply. Where Article 82 UK GDPR or equivalent liability provisions apply directly, those statutory provisions govern.
14. Governing law
This DPA is governed by the laws of England and Wales. Any dispute is subject to the dispute-resolution provisions of the Engagement Letter.
15. Schedules
Schedule 1: Details of processing
| Subject matter | Provision of the accounting, bookkeeping, tax, payroll and advisory services listed in our list of accounting and bookkeeping services and described in the Engagement Letter. |
|---|---|
| Duration | For the term of the Engagement Letter, plus post-termination return/deletion period (up to 90 days). |
| Nature & purpose | Recording financial transactions, preparing returns and reports, communicating with you and authorities, maintaining records as required by law. |
| Categories of data subjects | Your directors, employees, contractors, customers, suppliers and other parties whose data appears in your financial records. |
| Categories of personal data | Identification data (names, addresses, ID numbers), financial data (salaries, payments, tax data), contact data (emails, phone numbers). No special-category data unless specifically agreed. |
Schedule 2: Security measures
- SOC 2 Type II certified cloud platforms for all production data (Xero, QuickBooks Online, Dext, Karbon, etc.).
- TLS 1.2+ for data in transit; AES-256 encryption at rest (provided by platform vendors).
- Multi-factor authentication mandatory on every tool, every team member.
- Role-based access controls: least-privilege principle.
- Annual security awareness training for all team members.
- Documented incident response procedure with 48-hour notification commitment.
- Professional indemnity and cyber-liability insurance.
- No client data stored on personal devices or local drives.
Schedule 3: Approved sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Xero Limited | Cloud accounting platform | UK / EEA / Australia |
| Intuit Inc. | QuickBooks Online platform | US |
| Dext (Receipt Bank) | Document capture | UK / EEA |
| Karbon | Practice management | US (AWS hosting) |
| Fathom | Reporting & analytics | Australia / US |
| Slack Technologies | Client communication | US |
| Zoom Video Communications | Video calls | US |
| Google (Workspace) | Email & document storage | EU / US |
| DocuSign | Engagement letter signing | US |
| Wise & Stripe | Payment processing | UK / US / EU |
The full, current list (including any specific regional configurations) is maintained internally and made available on request.
Questions about this data processing agreement
Questions about this document should be directed to the addresses below, or raised through our contact page:
Accountaire (SMC-Private) Limited
Reg. 0210374
Email: [email protected]
General enquiries: [email protected]