Data Processing Addendum
Defines roles, responsibilities, and security commitments.
Table of contents
Jump to any section
1. Roles
You are the data controller for business data. BookOS acts as a data processor to provide the service.
2. Processing scope
BookOS processes data to deliver bookkeeping automation, financial reporting, and AI insights. Processing is limited to the services you enable.
3. Security measures
We implement access controls, encryption in transit and at rest, security logging, and secure development practices.
4. Service providers
We use approved service providers for infrastructure, analytics, and AI. We require equivalent security commitments and contractual protections. A current list is available at Service providers.
5. Data requests
We support access, deletion, and export requests when required by law and according to your instructions.
6. International transfers
Where required, we rely on standard contractual protections such as Standard Contractual Clauses (SCCs) for cross-border transfers.
7. Audits
We make available security documentation and reports upon request to support your compliance obligations. A signed DPA is available upon request for enterprise customers.
Version history
Track changes over time
v1.0