Skip to content
Astrocounts
HomeSign in

Data Processing Agreement

Version and last updated: 15 September 2026

This agreement under GDPR Article 28 forms part of the Astrocounts Terms. “Customer” is controller and “Provider” is processor for Customer Personal Data processed through the hosted service.

1. Scope and duration

This DPA applies only where the Customer is a controller and the Provider processes personal data on its behalf. Processing lasts for the service contract plus the return, deletion, backup and legally required retention periods. It covers hosting and organising accounting data; creating documents and reports; authentication and permissions; storage, backup, export, support, security and recovery; email delivery; and AI extraction when a receipt is submitted while scanning is enabled.

2. Data and people

Data may include identity and business contact data, customer and supplier records, invoice and receipt contents, bank and payment information, tax and registration identifiers, communications, user activity and document metadata. Data subjects may include Customer users, staff, contractors, customers, suppliers, payers, payees and people named in business records. The service is not intended for special-category or criminal-conviction data unless separately agreed and lawfully protected.

3. Instructions

The Provider processes Customer Personal Data only on documented Customer instructions, including the Terms, configuration and authorised in-service actions, unless Union or Member State law requires otherwise. The Provider will inform the Customer before legally required processing unless prohibited. It will promptly inform the Customer if an instruction appears to infringe data protection law.

4. Confidentiality and security

People authorised to process data are bound by confidentiality. Measures appropriate to risk include encrypted transport; password hashing; cookie and CSRF protections; tenant-scoped authorisation; least-privilege access; protected secrets; audit and security logging without unnecessary document content; database transactions and integrity constraints; backups and restore procedures; vulnerability and dependency maintenance; and incident-response procedures. Measures may evolve without reducing overall protection materially.

5. Subprocessors

By accepting the Terms, the Customer gives general written authorisation for subprocessors needed to provide the service. Categories are hosting/infrastructure, email delivery, and the configured AI extraction provider when a receipt is submitted. The current hosted AI provider is OpenAI; the Provider will maintain a current subprocessor list or identify changes in-service, give reasonable advance notice of a new subprocessor where practicable, and allow a reasoned data-protection objection. If no reasonable alternative exists, the Customer may terminate the affected service. Subprocessors receive Article 28-equivalent obligations and the Provider remains responsible for their performance as required by law.

6. International transfers

The Provider will not transfer Customer Personal Data outside the EEA without a lawful Chapter V GDPR transfer mechanism. Where relevant this may include an adequacy decision or the European Commission's Standard Contractual Clauses, transfer assessments and supplementary safeguards.

7. Assistance

Taking account of the processing and available information, the Provider will reasonably assist the Customer with data-subject requests, security obligations, breach notifications, impact assessments and prior consultation. The Provider will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and provide available information needed for the Customer's duties.

8. Return and deletion

At the Customer's choice after service ends, the Provider will delete or return Customer Personal Data and delete copies, unless applicable law requires storage. Protected backups are isolated from ordinary use and removed through their normal expiry cycle. Required retained data is restricted and used only for the retention purpose.

9. Audit information

The Provider will make information reasonably necessary to demonstrate Article 28 compliance available and permit proportionate audits by the Customer or an agreed independent auditor. Audits require reasonable notice, confidentiality, minimal disruption and regard for other customers' security. Existing independent reports and written evidence should be used first where sufficient.

10. Priority and contact

If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls. Mandatory data protection law controls both. Contact support@astrocounts.com for instructions, requests and incidents.

Astrocounts
Legal NoticeTermsPrivacyDPAAI Processing