Product: Accruate
Data Processing Agreement
Last updated: August 7, 2026In plain terms: when you use Accruate to process documents belonging to your own clients, you stay legally responsible for that data and we act on your instructions. This agreement sets out what we will and will not do with it, who else touches it, how we protect it, what happens if something goes wrong, and what happens when you leave. It is required by Article 28 of the GDPR, and it is the document your own clients' compliance reviews will ask you for.
1. Parties, and When This Applies
This Data Processing Agreement ("DPA") is between Islandbridge Automation Limited, a company registered in Ireland under company number 790984, with its registered office at Venture Hub, 136 Capel Street, Dublin, D01 T2C9, Ireland ("we", "us", "Processor"), and the organisation that has agreed to our Terms and Conditions ("you", "Customer", "Controller").
This DPA forms part of our Terms and Conditions and takes effect when you accept them. No separate signature is needed. It applies whenever we process personal data on your behalf in providing the Services. Where you need a signed copy for your own records or for a client, email info@islandbridge.io and we will provide one.
Where this DPA conflicts with the Terms and Conditions on the subject of data protection, this DPA prevails.
2. Definitions
"GDPR" means Regulation (EU) 2016/679 and, where relevant, the UK GDPR and the Data Protection Act 2018 (Ireland). "Personal data", "processing", "controller", "processor", "data subject", "supervisory authority" and "personal data breach" have the meanings given to them in the GDPR.
"Customer Personal Data" means personal data contained in documents, messages, and accounting data that you or those acting for you supply to the Services, or that we retrieve from systems you connect, and which we process on your behalf.
3. Roles of the Parties
You are the controller of Customer Personal Data. You decide what documents are supplied, whose data they contain, which accounting systems are connected, and who is contacted through the Services. You are responsible for having a lawful basis for that processing and for giving whatever notices data subjects are entitled to.
We are the processor of Customer Personal Data. We process it only to provide the Services to you.
We are a controller, separately, of your own account information: the names and contact details of your users, authentication records, billing details, and records of your use of the Services. That processing is governed by our Privacy Policy, not by this DPA.
4. Our Obligations as Processor
We will:
- Process only on your instructions. We process Customer Personal Data only on your documented instructions, including in relation to transfers outside the EEA, unless we are required to do otherwise by EU or Member State law. If that happens, we will tell you before processing, unless the law prohibits us from doing so on important grounds of public interest.
- Treat your use of the Services as your instructions. Your instructions consist of this DPA, the Terms and Conditions, and the actions you and your users take in the Services, including which documents are uploaded, which accounting systems are connected, which messages are sent, and the configuration you choose.
- Tell you if an instruction looks unlawful. We will inform you if, in our opinion, an instruction infringes the GDPR or other data protection law. We may suspend that instruction until it is resolved.
- Keep it confidential. Anyone we authorise to process Customer Personal Data is bound by an appropriate duty of confidentiality, and access is limited to those who need it to provide or support the Services.
- Apply appropriate security. We implement the technical and organisational measures required by Article 32, described in Annex B.
- Not use your data for our own purposes. We do not use Customer Personal Data to train our own artificial intelligence models, we do not sell or share it, and we do not use it for advertising or profiling.
5. Your Obligations as Controller
You will:
- Ensure you have a lawful basis for the processing you instruct, and that you have given data subjects any notice they are entitled to. This matters most for people who are not your own staff, such as your clients' suppliers and the recipients of document requests sent through the Services.
- Ensure you are entitled to supply the data to us, including under any confidentiality or professional obligation you owe your clients.
- Not upload special category data as defined in Article 9 of the GDPR, or data relating to criminal convictions and offences, unless you have told us in writing and we have agreed in advance. The Services are designed for commercial financial documents and are not configured for special category data.
- Be responsible for the accuracy of the data you supply and for the decisions you make on the basis of the Services' output.
6. Sub-processors
You give us general authorisation to engage sub-processors. The sub-processors we currently use, what each does, where each is located, and the safeguard for any transfer outside the EEA, are listed and kept up to date in our GDPR and Data Protection statement.
Where we engage a sub-processor, we impose on it data protection obligations no less protective than those in this DPA, and we remain fully liable to you for its performance.
Notice of changes. We will give you at least 30 days' notice before adding or replacing a sub-processor that handles Customer Personal Data, by email to the address on your account or by notice in the Services.
Your right to object. If you object on reasonable data protection grounds within that period, tell us and we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the Services without penalty and without further charge, and clause 11 will apply to your data.
7. International Transfers
We store Customer Personal Data in the European Economic Area. Some sub-processors process it outside the EEA, as identified in the table in our GDPR and Data Protection statement.
Where a transfer outside the EEA takes place, we ensure it is covered by an appropriate safeguard under Chapter V of the GDPR, being either a European Commission adequacy decision or the European Commission's Standard Contractual Clauses, together with any supplementary measures required. You instruct us to make those transfers for the purpose of providing the Services. On request we will provide details of the safeguard relied on for any given transfer.
8. Assisting You With Data Subject Requests
The Services give you direct access to Customer Personal Data, so in most cases you can respond to a data subject request yourself by viewing, correcting, exporting, or deleting the relevant records.
Where you cannot, we will provide reasonable assistance, taking into account the nature of the processing, to help you meet your obligations under Chapter III of the GDPR (the rights of access, rectification, erasure, restriction, portability, and objection).
If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request ourselves. We will tell them to contact you, and we will inform you promptly.
9. Personal Data Breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
Our notification will describe, so far as we know at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures we have taken or propose to take; and a contact point for further information. Where we cannot provide all of it at once, we will provide it in phases as it becomes available.
We will assist you in meeting your own obligations under Articles 33 and 34 of the GDPR. Reporting the breach to a supervisory authority or to affected individuals is your decision to make as controller, unless the law requires us to report it in our own right.
10. Impact Assessments and Prior Consultation
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment you carry out under Article 35, and with any prior consultation with a supervisory authority under Article 36.
11. Deletion and Return of Data
You may export Customer Personal Data from the Services at any time during the term.
On termination or expiry of the Services, you have 30 days in which to export your data or ask us to provide it to you. At the end of that period we will delete Customer Personal Data from our live systems, unless EU or Member State law requires us to keep it, in which case we will tell you what we are keeping and why.
Our database backups are taken daily and retained for seven days. Deleted data therefore persists in encrypted backups for up to seven days after deletion from live systems, after which backup rotation removes it. We do not restore backups in order to retrieve deleted data except to recover from a system failure.
On request we will confirm in writing that deletion has taken place.
12. Audit and Information
We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.
In practice, we ask that you first accept the information in this DPA, our Security Statement, and any written responses we give to your security questionnaire. Where that is not sufficient, an on-site or remote audit may be carried out on at least 30 days' written notice, no more than once in any twelve month period unless a personal data breach or a supervisory authority requires otherwise, during business hours, subject to reasonable confidentiality undertakings, and in a way that does not disrupt our operations or the confidentiality of other customers' data. You bear your own costs, and we may charge for our reasonable time where an audit goes beyond one working day.
13. Liability
The limitations and exclusions of liability in our Terms and Conditions apply to this DPA, except where the GDPR prevents that. Nothing in this DPA affects a data subject's rights under Article 82 of the GDPR.
14. Term
This DPA applies for as long as we process Customer Personal Data on your behalf. Clauses 11, 12, and 13 survive its termination.
Annex A: Details of the Processing
Subject matter
Provision of the Accruate pre-accounting service: extraction of data from financial documents, validation against tax rules, coding, review, and posting of approved records to a connected accounting system, together with document request and reminder messaging.
Duration
The term of the Terms and Conditions, plus the 30 day export window described in clause 11.
Nature and purpose
Collection, storage, structuring, analysis by automated means including artificial intelligence, retrieval, transmission to a connected accounting system at your instruction, transmission by email to recipients you designate, and erasure. The purpose is to provide the Services to you.
Categories of data subject
- Your personnel who use the Services.
- Your clients, and their personnel.
- Suppliers and customers named in the documents supplied, and their personnel, including sole traders.
- People who send documents to a workspace intake email address.
- Recipients of document requests and reminders sent through the Services.
Types of personal data
- Names, business contact details, email addresses, postal addresses, and job titles.
- Content of financial documents, including supplier and customer names and addresses, VAT registration numbers, bank account details printed on documents, line item descriptions, quantities, amounts, dates, references, and payment terms.
- Email message content, subject lines, sender and recipient addresses, and attachments sent to or from a workspace intake address.
- Data retrieved from a connected accounting system, including contact records, chart of accounts, tax rates, historical transaction coding, and bank transaction lines (payee, date, amount, description).
- Records of review decisions, notes, and approvals made within the Services.
Special category data
None. The Services are not intended for and are not configured to process special category data under Article 9, or data relating to criminal convictions and offences under Article 10. Financial information is confidential and commercially sensitive but is not special category data.
Annex B: Technical and Organisational Measures
These are the measures we apply under Article 32. Our Security Statement describes them in more detail and is kept current.
- Encryption. Data and uploaded documents are encrypted at rest using AES-256. All traffic between your browser and our systems is encrypted in transit using TLS.
- Data residency. Our database and file storage are hosted in the European Union. Error monitoring runs in a European region.
- Access control and tenant isolation. Access to each client workspace is enforced at the database level through row-level security. Every request is independently checked against the caller's membership of that workspace, so one customer's data cannot be reached from another customer's session.
- Authentication. Token-based authentication. Passwords are stored only as salted hashes by our authentication provider. Multi-factor authentication is available on every account and, once enrolled, is enforced on every request to the application interface.
- Credential protection. Credentials for connected accounting systems are held in an encrypted secrets vault and are accessible only to backend functions that need them. They are never exposed to the browser.
- Least privilege. Internal access to customer data is limited to authorised individuals who need it for support or engineering, and each is bound by a duty of confidentiality.
- Diagnostics minimisation. Error monitoring is configured to exclude request bodies, cookies, and document content, so diagnostic data does not carry Customer Personal Data from documents.
- Resilience and recovery. Daily database backups retained for seven days, enabling restoration in the event of a system failure.
- Human review. No record is posted to a connected accounting system without a person reviewing and approving it, so no decision about a data subject is taken solely by automated means.
Annex C: Sub-processors
The authorised sub-processors under clause 6, together with what each one does, where it is located, and the safeguard relied on for any transfer outside the EEA, are listed in full in our GDPR and Data Protection statement.
That page is the single authoritative list, and it forms part of this DPA. We keep it there rather than repeating it here so that there is only one list to maintain and no risk of two versions disagreeing. It is updated whenever the list changes, and clause 6 governs how we notify you of changes and how you may object.
As at the date of this DPA the sub-processors are: Supabase, Vercel, Google, Resend, Xero, Sentry, and Cal. If you need a point-in-time signed copy of the list for your own records or for a client, email info@islandbridge.io and we will provide one.
Contact
Questions about this DPA, requests for a signed copy, and data protection correspondence:
Islandbridge Automation Limited
Venture Hub, 136 Capel Street
Dublin, D01 T2C9
Ireland
Registered in Ireland, company number 790984
info@islandbridge.io