Octobooks Data Processing Agreement
Version of 9 October 2026. Part of the Octobooks Terms of Service. Meets Article 28 UK GDPR and EU GDPR.
1. Parties and roles
- The customer who accepted the Octobooks Terms of Service ("you") is the controller.
- The operator of Octobooks named in the Terms of Service ("we") is the processor.
- This agreement applies whenever we process personal data for you through Octobooks. It runs as long as the Terms do, and after that until the data is deleted.
2. What we process
| Item | Details |
|---|---|
| Subject matter | Bookkeeping, invoicing, document storage, reporting and tax preparation for your business |
| Nature | Storing, organising, reading, calculating, transmitting on your release, deleting |
| Purpose | Delivering Octobooks to you under the Terms |
| Data subjects | Your customers, suppliers, staff, directors, contractors and other contacts in your books |
| Data categories | Names, addresses, emails, phone numbers, bank details, VAT and tax numbers, invoice and payment data, salary and expense data, contents of uploaded documents |
| Special categories | None intended. Do not upload health or other special category data unless it is unavoidable in a document; tell us if your use needs it |
3. Our duties
- Instructions. We process the data only on your documented instructions. The Terms, your settings, and the actions you or your connected AI take in Octobooks are your instructions. If we think an instruction breaks data protection law, we tell you.
- Confidentiality. Everyone who can access the data is bound to keep it confidential.
- Security. We keep the measures in Annex 1, and may improve them as long as protection does not drop.
- Sub-processors. You give general authorisation to the sub-processors in the Sub-processor List. We tell you by email at least 30 days before adding or replacing one. You can object on reasonable data protection grounds; if we cannot resolve it, you can end the Terms and get a refund of the unused prepaid period. We bind each sub-processor to the same data protection duties and stay responsible for them.
- Rights requests. If a data subject contacts us, we pass the request to you. Octobooks lets you find, export, correct and delete their data yourself; we help where you cannot.
- Breaches. We tell you without undue delay, and aim for within 48 hours, after becoming aware of a personal data breach affecting your data, with what we know and what we are doing.
- Assistance. We give reasonable help with your impact assessments and consultations with authorities, as far as they concern Octobooks.
- End of service. You can export your data for 90 days after the Terms end. Then we delete it, unless the law requires us to keep it. Backups roll off within a further 35 days.
- Audits. We give you the information you reasonably need to show compliance. On-site audits are possible once a year with 30 days' notice, at your cost, without access to other customers' data.
4. International transfers
Your data is hosted in Germany. Where a sub-processor processes it outside the UK or EU, we use an adequacy decision, the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement or Addendum.
5. Your duties
- You have a lawful basis for the data you put into Octobooks and give the people concerned the information the law requires.
- You decide what your connected AI assistant may read and do. Data you send to your own AI provider is your transfer, not ours.
6. Liability and precedence
- Liability under this agreement is subject to the limits in the Terms of Service, as far as the law allows.
- If this agreement and the Terms conflict on data protection, this agreement wins.
Annex 1: Security measures
- Hosting in an ISO 27001 certified data centre in Germany.
- Encryption in transit (TLS); sensitive fields and every backup encrypted.
- Each customer's books are kept apart by company, and every query is scoped to the company it is for.
- Access by passkey or strong authentication; connector tokens are scoped per company and can be revoked at any time.
- Admin access limited to the owner and named systems, logged, and reviewed.
- Full audit trail of who or what created, changed or released each item. Nothing is deleted silently.
- Nightly encrypted backups with regular restore tests.
- Security updates applied promptly; dependencies monitored.
- If we use an AI provider, only under terms that forbid training on your data.