Data Processing Agreement

Your books contain personal data about other people: your customers, your staff, your vendors. You decide what goes in and why. We hold it on your instructions, and this is the agreement that says so.

This is a draft, and it does not bind anyone yet

An agreement has to be able to name who you are contracting with and where a dispute would be heard. Until it can, we would rather show you the wording we intend to use than publish a contract with a hole in it. Still to be filled in:

  • the legal name of the business
  • a real postal address
  • the governing law and venue

1.Which of us is which

For the personal data inside your books, you are the controller and the operator of kBooks is the processor. You decide what personal data to collect and why. We process it only to provide kBooks to you, and only on your instructions, which for practical purposes means: the things the product does when you use it.

For the handful of details we hold about YOU in order to run your account and bill you, we are the controller, and the privacy policy governs that instead. Keeping the two apart is the point of this document.

2.What is processed, and about whom

Categories of people: your customers, your vendors and their contacts, your employees and contractors, and the people you invite into your books.

Categories of data: names, business and postal addresses, email addresses and phone numbers, transaction and payment history, bank transaction descriptions, and the contents of documents you upload. Where you use the product for payroll-adjacent or tax purposes it may include a taxpayer identification number, which is stored encrypted under its own key.

For how long: for as long as you keep it in your books. When an account is closed we keep its books for 90 days and then delete them. That window exists so leaving is reversible and so you can still export after you have stopped paying, which is exactly when most people discover they need to.

3.What we will and will not do with it

We process it to provide, secure and support the service, and for nothing else. We do not sell it, share it for advertising, or use it to train machine learning models. If we ever believe an instruction from you would break the law, we will tell you rather than quietly comply.

Everyone here who can reach customer data is bound by confidentiality, and access is limited to what the job needs.

4.Security

We apply appropriate technical and organisational measures, and the ones we actually use are set out in full on the security page rather than described here in the abstract: encryption in transit and at rest, separately encrypted bank credentials and tax identifiers, per-person and per-company access enforced on the server, audit records on every change, and point-in-time backups.

That page also states plainly what we do not yet have, including a SOC 2 report and a third-party penetration test. We would rather you knew that before you signed this than after.

5.Telling you when something goes wrong

If personal data we hold for you is breached, we tell you without undue delay and in any case within 72 hours of becoming aware of it, with what we know, what we are doing, and what you may need to do.

We will help you meet your own notification duties, because the clock that matters is usually the one running against you rather than against us.

6.Other companies we use

You authorise us to use subprocessors to run the service. Every one of them is named, with what they do and what data actually reaches them, on the subprocessors page, which forms part of this agreement. Each is bound by terms no weaker than these, and we remain responsible to you for what they do.

That page is where a change appears first. If you want to be told before a new subprocessor starts handling your data, say so and we will tell you.

7.Helping you answer the people whose data it is

If one of your customers or staff asks you for their data, or asks you to correct or delete it, the product itself is usually the fastest route: you can search, edit, export and delete inside your own books without asking us. Where a request needs more than that, we will help, and we will not charge you for reasonable assistance.

If such a request reaches us directly, we will not answer it ourselves. We will pass it to you, because it is your relationship and your decision.

8.Where the data lives

kBooks is hosted in the United States, and the subprocessors page says where each company holds data. If you are subject to the GDPR or the UK equivalent, transfers outside your region rely on the European Commission’s standard contractual clauses, which are incorporated into this agreement by reference and prevail over anything here that conflicts with them.

9.Proving it

Ask and we will give you the information you reasonably need to satisfy yourself we are meeting this agreement. We do not currently hold an independent audit report; when we do, it will be offered here instead of an exchange of emails.

10.When it ends

This agreement lasts as long as we process personal data for you. When your account closes, the retention window in clause 2 runs and then the data is deleted, and you can export all of it at any point before that, including after you have stopped paying.