Data Processing Agreement
For accounting firms and businesses. When you put your own or your clients’ data into DecaBooks, we process it only on your instructions, keep it confidential and secure, tell you within 48 hours of a breach, list every provider we use, and delete it when you are finished.
This agreement applies automatically to every DecaBooks account.
1. Parties and how this agreement applies
This Data Processing Agreement (“DPA”) is between you, the customer named on the DecaBooks account (“you”), and the processor:
- Renipa LTD, a company registered in the Republic of Cyprus
- Registration number HE 458467
- Registered office: Nikodimou Mylona 3, 3095 Limassol, Cyprus
- Email hello@decabooks.com
It forms part of our Terms of Service and applies automatically whenever we process personal data in your workspaces. It meets the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Cyprus Law 125(I)/2018. You do not need to sign it separately. If you need a signed copy, write to hello@decabooks.com.
2. Roles
For personal data in your workspaces (“Customer Data”), you are the controller and we are the processor. If you are an accounting firm acting for a client, the client may be the controller and you its processor; in that case we act as your sub-processor, and you confirm that your client has authorised you to use DecaBooks.
You are responsible for having a lawful basis for the Customer Data, for the instructions you give us, and for the accuracy of the data.
3. Details of the processing
| Subject matter | Providing the DecaBooks bookkeeping, VAT, payroll and reporting service. |
|---|---|
| Duration | For as long as you use the Service, plus the deletion period in section 11. |
| Nature and purpose | Storing, reading (including with AI), organising, calculating, reconciling, reporting on and exporting Customer Data, and sending emails you ask the Service to send, so that you can keep books, prepare returns and run payroll. |
| Types of personal data | Names, contact details, addresses, VAT and tax identification numbers, bank account details (IBAN), invoice, payment and transaction details, and the content of uploaded documents. For payroll: identity card and social insurance numbers, salary and deductions, tax allowance details, leave records and employment dates. |
| Data subjects | Your (or your clients’) customers, suppliers, employees, directors, shareholders and contact people, and the users you invite. |
| Special categories | Identity card, social insurance and salary data are not special category data, but payroll leave records can show sick leave, which may be health data under Article 9 GDPR. Access to payroll is limited by role. Do not upload other special category data unless it is strictly necessary and lawful. |
4. Processing only on your instructions
We process Customer Data only on your documented instructions. These terms, your configuration of the Service and your actions in it are your instructions. We will not use Customer Data for our own purposes, sell it, or use it for advertising, and our AI provider does not use it to train models.
If the law requires us to process Customer Data in another way, we will tell you first unless the law forbids it. If we think an instruction breaks data protection law, we will tell you.
5. Confidentiality
Everyone at Renipa LTD who can access Customer Data is bound by confidentiality. Access is limited to staff who need it to provide, support or secure the Service, such as viewing a workspace to answer a support request or investigate a fault.
6. Security measures
We maintain appropriate technical and organisational measures under Article 32 GDPR, including:
- encryption of data in transit (HTTPS/TLS) and at rest;
- passwords stored only as one-way bcrypt hashes; access by role within each workspace; workspace separation enforced on our servers;
- uploaded files stored at long, random, unguessable addresses;
- a tamper-evident hash chain on posted accounting entries, and audit logs of key actions;
- regular backups with point-in-time recovery of the database;
- limited, need-to-know staff access, and monitoring of errors and security events;
- review of these measures as the Service and the risks change.
7. Sub-processors
You give us general authorisation to use sub-processors. We currently use:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Runs the DecaBooks app and website, and stores uploaded files | United States |
| Neon Inc. | Database that holds the accounting data in each workspace | Germany (Frankfurt) |
| Google LLC (Gemini API, paid service) | AI reading of documents, account suggestions and Ask AI answers | United States |
| Functional Software Inc. (Sentry) | Error monitoring and session recordings, for finding and fixing faults | Germany (Frankfurt) |
| Resend (Plus Five Five, Inc.) | Sends emails such as invitations, payslips and statements | United States |
We impose data protection obligations on each sub-processor that are at least as protective as this DPA, and we remain responsible to you for their work. We will tell you by email at least 30 days before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that time; if we cannot address your objection, you may end the affected part of the Service and we will refund any fees paid in advance for the period after it ends.
8. Transfers outside the EU
Some sub-processors process Customer Data in the United States, as listed above. We transfer data outside the European Economic Area only with appropriate safeguards: the EU–US Data Privacy Framework where the recipient is certified, or otherwise the European Commission’s Standard Contractual Clauses, with supplementary measures where needed.
9. Helping you meet your obligations
- Requests from individuals: the Service lets you find, correct, export and delete Customer Data. If an individual contacts us directly about Customer Data, we will pass the request to you and not answer it ourselves unless you ask us to.
- Impact assessments and authorities: we will give you reasonable information to help with data protection impact assessments and with any consultation of a supervisory authority.
10. Personal data breaches
If we become aware of a personal data breach affecting Customer Data, we will tell you without undue delay and in any case within 48 hours. We will give you the information you reasonably need to assess it and to meet your own duty to notify within 72 hours, update you as we learn more, and take reasonable steps to contain it and reduce its effects.
11. Return and deletion at the end
You can export Customer Data at any time. When a workspace is closed, it can be restored for 30 days. After that, we delete its Customer Data from our systems within a further 60 days, unless the law requires us to keep it. Copies in backups are overwritten in their normal cycle and are not used in the meantime. On request, we will confirm the deletion in writing.
12. Information and audits
We will make available the information reasonably needed to show that we comply with this DPA, and answer your reasonable written questions about our security. If that is not enough, you may audit our compliance once a year, or after a breach, with at least 30 days’ written notice, at your own cost, during business hours, through an independent auditor bound by confidentiality, and without access to other customers’ data.
13. Liability and precedence
Each party’s liability under this DPA is subject to the limits in our Terms of Service, except where the law does not allow it. If this DPA conflicts with the Terms of Service on the processing of Customer Data, this DPA applies. This DPA is governed by the laws of the Republic of Cyprus.
