← TechAccounting

Data Processing Agreement

Effective date: 5 August 2026 · Version 2026-08-05

This Data Processing Agreement (the "DPA") forms part of, and is incorporated by reference into, the Terms of Service between you and Fintech Accounting OÜ, a private limited company registered in Estonia under registry code 17056631, VAT number EE102773976, with its registered office at Maakri tn 19/1, 10145 Tallinn, Estonia ("TechAccounting", "we", "us" or "our"). Where there is a conflict between this DPA and the rest of the Terms of Service on the subject of personal-data processing, this DPA prevails.

This DPA applies where, and to the extent that, we process personal data on your behalf as your processor in the course of providing the Service. It reflects the requirements of Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and applicable Estonian law.

It does not apply to personal data for which we are ourselves the controller (for example, the account, profile and billing data of the people who use the Service on your behalf). Our handling of that data is described in our Privacy Policy.

1. Definitions

"Client Data" means the documents and information you upload or otherwise provide to the Service so that we can perform the accounting services, to the extent they contain personal data (for example bank statements, invoices, contracts, and payroll records relating to your staff and your own customers).

"Controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings given to them in the GDPR. "Data Protection Law" means the GDPR and the Estonian Personal Data Protection Act (isikuandmete kaitse seadus) and any other law applicable to the processing of Client Data. "Sub-processor" means any third party engaged by us to process Client Data.

2. Roles of the parties

In relation to Client Data, you are the controller and we are the processor. You determine the purposes and means of the processing; we process Client Data only to provide the Service and only as set out in this DPA and your instructions.

You are responsible for ensuring that you have a lawful basis for the processing of Client Data, that any required notices have been given to the relevant data subjects, and that your instructions to us comply with Data Protection Law.

3. Our obligations as processor

We will:

  • process Client Data only on your documented instructions, including as to transfers of Client Data to a third country, unless we are required to process it by a law to which we are subject (in which case we will inform you of that legal requirement before processing, unless the law prohibits it on important grounds of public interest);
  • ensure that the people we authorise to process Client Data are bound by an appropriate duty of confidentiality;
  • take the technical and organisational security measures described in Section 6 and Annex II;
  • respect the conditions in Section 7 for engaging a sub-processor;
  • taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as this is possible, to respond to requests from data subjects exercising their rights;
  • assist you in ensuring compliance with your obligations relating to the security of processing, notification of personal data breaches, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR), taking into account the nature of the processing and the information available to us;
  • at your choice, delete or return all Client Data to you after the end of the provision of the Service, and delete existing copies, unless a law to which we are subject requires the storage of the Client Data (see Section 12); and
  • make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits as set out in Section 11.

If, in our opinion, an instruction from you infringes Data Protection Law, we will inform you without undue delay.

4. Your instructions

Your complete and final instructions for the processing of Client Data are this DPA and the Terms of Service, together with your use and configuration of the Service and any further written instructions you give us. Additional instructions outside the scope of the Service are subject to prior written agreement, including on any fees for carrying them out.

5. Confidentiality

We treat Client Data as confidential. We limit access to Client Data to personnel and sub-processors who need it to provide or support the Service, and we require them to keep it confidential.

6. Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II. We keep those measures under review and may update them, provided the level of protection is not reduced.

7. Sub-processors

You give us general authorisation to engage sub-processors to help provide the Service. The sub-processors we currently use are listed in Annex III.

Where we engage a sub-processor to carry out processing on your behalf, we will impose on it, by contract, data-protection obligations that are no less protective than those set out in this DPA. We remain fully responsible to you for the performance of each sub-processor's obligations.

We will inform you of any intended addition or replacement of a sub-processor, giving you a reasonable opportunity to object on reasonable data-protection grounds. If you object and we cannot offer a reasonable alternative, you may terminate the affected part of the Service.

8. International transfers

We host and process Client Data within the European Union or European Economic Area (EEA) where reasonably possible. Where a sub-processor processes Client Data outside the EEA, we will ensure that the transfer is covered by an adequacy decision of the European Commission or by appropriate safeguards under Chapter V of the GDPR, such as the European Commission's standard contractual clauses.

9. Assistance with data subject rights

If we receive a request directly from a data subject in relation to Client Data, we will not respond to it ourselves except on your instructions, and we will forward the request to you without undue delay. Taking into account the nature of the processing, we will provide reasonable assistance to help you meet your obligations to respond to such requests.

10. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Client Data, and will provide you with the information reasonably available to us to help you meet any obligation you may have to notify the supervisory authority or affected data subjects. Our notification is not an acknowledgement of fault or liability.

11. Audits and information

On your reasonable written request, and no more than once a year unless required by a supervisory authority or following a personal data breach, we will make available the information reasonably necessary to demonstrate our compliance with this DPA. Where an on-site audit is genuinely required, it will be conducted on reasonable prior notice, during business hours, in a way that does not disrupt our operations or compromise the confidentiality of other customers, and at your cost.

12. Return and deletion

On termination of the Service, and at your choice, we will delete or return the Client Data and delete existing copies, except to the extent that a law to which we are subject requires us to keep it. In particular, accounting source documents and related records must be retained for the period required by Estonian law, which is generally seven years; during any such retention period the Client Data remains protected by this DPA and is processed only for the purpose of meeting that legal obligation.

13. Liability

Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA limits any liability that cannot be limited under Data Protection Law.

14. Term and governing law

This DPA takes effect when you accept the Terms of Service and continues for as long as we process Client Data on your behalf. It is governed by the laws of the Republic of Estonia, and the courts of Estonia have jurisdiction, without prejudice to any mandatory rights of data subjects under Data Protection Law.

Annex I - Description of the processing

  • Subject matter: our processing of Client Data in order to provide the accounting and compliance services described in the Terms of Service.
  • Duration: for as long as you use the Service, plus any retention period required by law (see Section 12).
  • Nature and purpose: storage, organisation, consultation, use and other operations necessary to keep your books, prepare and file returns and reports, and support related compliance.
  • Types of personal data: identification and contact details, financial and transactional data, tax and payroll data, and any other personal data contained in the documents you choose to upload.
  • Categories of data subjects: your representatives and staff, and your own customers, suppliers and other counterparties whose data appears in the documents you provide.

Annex II - Technical and organisational measures

We maintain measures including:

  • encryption of Client Data in transit;
  • access controls and authentication, including role-based access and least-privilege principles, so that Client Data is accessible only to authorised personnel and sub-processors;
  • logical separation of each customer's data and enforcement of access rules at the database level;
  • rate limiting and other measures to protect the Service against abuse;
  • use of reputable infrastructure providers that maintain recognised security certifications; and
  • internal procedures for handling personal data breaches and for restoring availability after an incident.

Annex III - Sub-processors

As at the effective date of this DPA, we use the following sub-processors to provide the Service:

  • Supabase - managed database, authentication and file storage for the application and the documents you upload;
  • Vercel - hosting and content delivery for the web application, and file storage (Vercel Blob) for profile pictures and the documents the Service generates;
  • Upstash - managed Redis used for rate limiting and abuse prevention (processes technical data such as IP addresses);
  • Resend - delivery of transactional emails such as verification and account messages (processes email addresses);
  • Sentry - error monitoring for the web application, hosted in Sentry's EU region (processes technical data contained in automatic diagnostic reports, such as the error, the page it occurred on and the surrounding technical state).

Each sub-processor is engaged under a written agreement containing data-protection terms, and processes Client Data within the EEA or subject to the safeguards described in Section 8.

Contact

Questions about this DPA, or requests relating to it, can be sent to privacy@techaccounting.ee, or by post to Fintech Accounting OÜ, Maakri tn 19/1, 10145 Tallinn, Estonia. See also our Privacy Policy and Terms of Service.