Data Processing Agreement
Last updated: August 2026
This DPA forms part of the Terms of Service between you (the Customer) and Thrive Venture Labs Ltd. Related: Privacy Policy · Security.
1. Parties and roles
This Data Processing Agreement ("DPA") is between:
- Customer: the organisation or individual that subscribes to AccountsOS (including founders using AccountsOS for their own company, and accountancy practices using AccountsOS for their firm and client companies).
- Processor: Thrive Venture Labs Ltd, company number 16871566, registered office 3rd Floor, 86-90 Paul Street, London EC2A 4NE, trading as AccountsOS ("AccountsOS", "we", "us").
For personal data that the Customer uploads to, generates in, or otherwise processes through AccountsOS in the course of using the Service (Customer Data), the Customer is the controller (or a processor acting for its own clients) and AccountsOS is the processor (or sub-processor).
For account, billing, marketing, and product-usage data that AccountsOS determines the purposes of, AccountsOS is the controller. That processing is described in our Privacy Policy and is outside the scope of this DPA.
2. Incorporation and acceptance
This DPA is incorporated into and forms part of the AccountsOS Terms of Service. By creating an AccountsOS account, subscribing, or otherwise using the Service, the Customer accepts this DPA.
Practices and other Customers that need a countersigned copy for their own compliance file can request one at finn@accounts-os.com. The online version at accounts-os.com/dpa is the standard agreement in force unless a written variation is signed by both parties.
3. Scope of processing
Subject matter and purpose
Provision of the AccountsOS accounting platform: bookkeeping, document capture, categorisation, invoicing, expenses, reconciliation, reporting, tax and filing support (including HMRC Making Tax Digital where enabled), multi-client practice tools, messaging integrations, and related AI-assisted features.
Duration
For the term of the Customer's subscription and any wind-down or legal retention period described in section 12 and the Privacy Policy.
Nature of processing
Collection, storage, organisation, structuring, retrieval, consultation, use, alignment, restriction, erasure, destruction, and transmission of Customer Data as required to operate the Service, including automated analysis and machine-learning inference solely to provide the features the Customer uses.
Types of personal data
- Identity and contact details (names, emails, phone numbers, addresses)
- Company and registry identifiers
- Financial and accounting records (transactions, invoices, bills, payroll-related imports, tax figures)
- Documents and images (receipts, statements, contracts, timesheets)
- Bank and payment-provider metadata connected by the Customer
- Communications content the Customer sends into the Service (chat, email, messaging channels)
- User account and access logs for people the Customer invites
Categories of data subjects
- Customer personnel and authorised users
- Directors, officers, and shareholders of Customer companies
- Clients, suppliers, employees, contractors, and other counterparties whose data the Customer stores in AccountsOS
- For practices: end clients of the practice and those clients' personnel and counterparties
4. Customer responsibilities
The Customer warrants that it has a lawful basis to process Customer Data and to instruct AccountsOS to process it, including any personal data of clients, employees, or third parties. Where the Customer is a practice processing client data, the Customer is responsible for its own client terms, privacy notices, and any required authorisations.
The Customer's documented instructions to AccountsOS are: (a) process Customer Data to provide and support the Service as configured by the Customer; (b) process as required by applicable law; and (c) any other written instructions agreed by both parties that are consistent with the Service.
5. Processor obligations
AccountsOS shall:
- Process Customer Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country, unless required to do so by UK or EU law. In that case we will inform the Customer of that legal requirement before processing, unless the law prohibits such notice.
- Ensure that persons authorised to process Customer Data are bound by confidentiality obligations.
- Implement appropriate technical and organisational measures as described in section 7 and on our Security page.
- Not engage another processor without complying with section 8 (sub-processors).
- Taking into account the nature of processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Customer's obligation to respond to data subject requests under UK GDPR.
- Assist the Customer in ensuring compliance with UK GDPR Articles 32 to 36 (security, breach notification, DPIAs, and prior consultation), taking into account the nature of processing and the information available to us.
- At the choice of the Customer, delete or return Customer Data after the end of the provision of services relating to processing, and delete existing copies, unless UK or EU law requires storage (see section 12).
- Make available to the Customer information necessary to demonstrate compliance with Article 28 UK GDPR and allow for and contribute to audits as set out in section 11.
- Immediately inform the Customer if, in our opinion, an instruction infringes UK GDPR or other UK data protection law.
6. AI processing
AccountsOS uses AI providers (currently Anthropic Claude and Google Gemini) solely to deliver product features the Customer uses (for example chat, document extraction, categorisation, and reconciliation assistance). Customer Data is sent to those providers only as needed for the requested feature.
- Customer Data is not used by AccountsOS to train foundation models.
- Under our provider agreements, those providers do not use Customer content to train their models for their own purposes.
- AI providers act as our sub-processors for this purpose and are listed in section 8.
7. Security measures
Without limiting the Security page, AccountsOS maintains at least the following measures appropriate to the risk of processing financial and personal data:
- TLS encryption in transit; AES-256 encryption at rest for stored Customer Data
- Primary application data hosted in the UK (AWS eu-west-2, London) via Supabase
- Row-level security and access controls isolating company and practice data
- Authentication with optional multi-factor authentication (TOTP)
- Encrypted storage of integration credentials and tokens
- Logging, monitoring, and error tracking with access restricted to authorised personnel
- Staff and contractor access limited on a need-to-know basis
8. Sub-processors
The Customer authorises AccountsOS to engage the sub-processors below to process Customer Data as needed to provide the Service. We will impose data protection terms on sub-processors that are no less protective than this DPA in respect of the processing they perform.
We will give the Customer notice of material changes to this list (including via update to this page and/or email to the account owner) and a reasonable opportunity to object on reasonable data-protection grounds. If the parties cannot resolve an objection, the Customer may terminate the affected Service as its sole remedy.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage | UK (eu-west-2) |
| Vercel Inc. | Application hosting and edge delivery | EU/US (global edge) |
| Anthropic | AI chat and tool-assisted accounting features | US (with appropriate transfer safeguards) |
| Google (Gemini) | AI extraction, categorisation, voice and related features | EEA/US (with appropriate transfer safeguards) |
| Resend | Transactional and product email delivery | US/EU |
| Revolut (Merchant) | Subscription billing for AccountsOS | EEA/UK |
| Sentry | Application error monitoring | US/EU |
| Twilio | WhatsApp / SMS messaging where Customer enables it | US/EU |
| Hetzner Online GmbH | Fixed-IP HMRC MTD gateway infrastructure | EU (Germany) |
| Companies House / HMRC | Statutory registry lookups and tax filings when Customer instructs | UK |
Optional Customer-configured integrations (for example the Customer's own Stripe, bank, Deel, Slack, Google Workspace, or MCP connections) process data under the Customer's direction with those providers. They are not AccountsOS sub-processors for the Customer's own accounts with those services.
9. International transfers
Primary Customer Data is stored in the United Kingdom. Where a sub-processor processes data outside the UK or an adequate jurisdiction, AccountsOS will ensure an appropriate transfer mechanism is in place (for example the UK International Data Transfer Agreement / Addendum, EU Standard Contractual Clauses as applicable, or another mechanism permitted under UK GDPR Chapter V).
10. Personal data breaches
AccountsOS will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to us to help the Customer meet its own notification duties to the ICO and data subjects.
Security incidents can be reported to finn@accounts-os.com. Where HMRC-connected data is involved, we also follow the breach procedures described in our Privacy Policy.
11. Audits and information
On written request, and no more than once per twelve months (unless required following a confirmed breach or by a competent supervisory authority), AccountsOS will provide documentation reasonably necessary to demonstrate compliance with this DPA, which may include security summaries, sub-processor lists, and high-level architecture descriptions.
On-site or intrusive audits are available only where the documentation route is insufficient for the Customer's Article 28 obligations, subject to reasonable notice, confidentiality, scope limits, and the Customer bearing its own costs (and any external auditor costs). Audits must not compromise other customers' security or confidential information.
12. Return and deletion
During the subscription, the Customer may export Customer Data using product export features. After termination or expiry:
- The Customer has 30 days to export data (as stated in the Terms of Service).
- After that period, AccountsOS will delete or anonymise Customer Data within a further 30 days, except where UK tax or other law requires longer retention (financial records may be retained for up to 7 years where legally required).
- Backups are cycled out on normal backup schedules after deletion from live systems.
13. Liability and order of precedence
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where those limitations are not permitted by data protection law in respect of a party's obligations to data subjects.
If there is a conflict between this DPA and the Terms of Service on a data protection matter, this DPA prevails. If there is a conflict between this DPA and the Privacy Policy, this DPA prevails for Customer Data processed as a processor; the Privacy Policy prevails for processing where AccountsOS is controller.
14. Governing law
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, without prejudice to any mandatory rights of data subjects or supervisory authorities under UK GDPR.
15. Contact
Data protection and DPA requests:
- Email: finn@accounts-os.com
- Thrive Venture Labs Ltd, 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom
This DPA is a standard commercial agreement for use of AccountsOS. It is not legal advice. Customers with specific regulatory requirements (for example large firms or multi-jurisdiction practices) can request a countersigned copy or discuss variations at finn@accounts-os.com.