1. INTRODUCTION
This Data Processing Agreement ("DPA") is entered into between:
- Data Subject (Responsible Party): You (the accountant or accounting firm using THE ACCOUNTANTS)
- Data Operator: THE ACCOUNTANTS, operated by Books Xperts (Pty) Ltd
This DPA outlines how THE ACCOUNTANTS ("Operator") processes personal information on your behalf, in compliance with the Protection of Personal Information Act, 2013 ("POPIA").
2. WHAT IS A DATA PROCESSING AGREEMENT?
Under POPIA §21, when a company processes personal information on behalf of another party, a written Data Processing Agreement must exist. This DPA confirms:
- You retain control over your data (you are the "Responsible Party")
- THE ACCOUNTANTS processes data only as instructed by you
- THE ACCOUNTANTS implements security measures to protect your data
- THE ACCOUNTANTS will not use your data for its own purposes (except where necessary to provide the Service)
3. ROLES & RESPONSIBILITIES
3.1 You Are the "Responsible Party"
As the user, you:
- Determine what personal data is processed (e.g., client names, firm details, trial balance data)
- Decide the purpose of processing (e.g., AFS compilation, SARS compliance, audit trails)
- Ensure you have lawful basis to process data (consent, contract, legitimate interest, legal obligation)
- Are responsible for compliance with POPIA and all South African data protection law
3.2 THE ACCOUNTANTS Is the "Operator"
THE ACCOUNTANTS:
- Processes personal data only as instructed by you (via the platform)
- Implements security safeguards to protect your data (encryption, access controls, audit logs)
- Does not use your data for THE ACCOUNTANTS's own marketing or business purposes (except to provide the Service)
- Allows you to access, correct, and delete your data
- Notifies you promptly if a data breach occurs (within 30 days per POPIA §22)
4. WHAT PERSONAL DATA DO WE PROCESS?
When you use THE ACCOUNTANTS, you may input or we may collect:
- Firm Data: Firm name, registration number, email, phone, address, proprietor/partner names
- User Data: Accountant name, email, password, login history, 2FA settings
- Client Data: Client names, ID numbers, email, phone, company details (input for AFS compilation)
- Financial Data: Trial balance uploads, journal entries, asset registers, income/expense classifications
- AFS Data: Entity type, shareholding structure, management commentary, related-party transactions
- Communication Data: Support tickets, feedback, feature requests
- Usage Data: Pages visited, reports generated, time spent (anonymised logs)
5. HOW WE PROCESS YOUR DATA
5.1 Purpose of Processing
THE ACCOUNTANTS processes your data to:
- Create and manage your firm account and user access
- Generate compliant AFS reports and engagement letters
- Store and organize client trial-balance data
- Process subscription billing and payment collection
- Send transactional emails (account confirmations, report ready, billing notifications)
- Prevent fraud and maintain platform security
- Comply with South African law (SARS, CIPC, financial regulations)
5.2 Lawful Basis for Processing
THE ACCOUNTANTS processes your data based on:
- Contract: To perform the services you've requested (e.g., AFS compilation, report generation)
- Legal Obligation: To comply with South African law (SARS, CIPC, tax regulations)
- Legitimate Interest: To prevent fraud, maintain platform security, and improve the Service
- Your Consent: If you opt-in to marketing communications or service updates
5.3 Data Retention
THE ACCOUNTANTS retains your data for:
- Active accounts: As long as you use the platform
- Closed accounts: 7 years (for tax, audit, and legal compliance under South African law)
- AFS records: 7 years (SARS requirement for financial records)
- Client data: 7 years after account closure (for compliance)
- Legal disputes: Longer if required by law or for legal proceedings
After the retention period, your data is securely deleted or anonymised where legally permissible.
6. SECURITY MEASURES
THE ACCOUNTANTS implements the following security safeguards:
- ✅ Encryption: Data in transit (HTTPS/TLS) and at rest (AES-256 or equivalent)
- ✅ Access controls: Role-based access; only authorised staff can view sensitive data
- ✅ Authentication: Secure login with password encryption; optional MFA for sensitive accounts
- ✅ Audit logging: All data access is logged and monitored for suspicious activity
- ✅ Data segregation: Your firm's data is isolated from other firms' data
- ✅ Regular backups: Automated backups to prevent data loss
- ✅ Security testing: Regular penetration testing and vulnerability scanning
- ✅ Incident response: Documented procedures for data breaches
Your Responsibility: Keep your account password confidential and log out of shared computers. Notify us immediately of any suspected unauthorized access.
7. YOUR RIGHTS (POPIA DATA SUBJECT RIGHTS)
You have the right to:
7.1 Right of Access (POPIA §23(1)(c))
You can request a copy of your personal data. To exercise this right:
- Click Settings → Privacy & Data → Download My Data in THE ACCOUNTANTS, or
- Email [DATA-PROTECTION-EMAIL] with subject "Data Access Request"
- We will provide your data within 30 days in a machine-readable format (CSV/JSON)
7.2 Right of Correction (POPIA §23(1)(b))
You can correct inaccurate or incomplete data:
- Edit your firm profile in THE ACCOUNTANTS (Settings → Firm Profile), or
- Email [DATA-PROTECTION-EMAIL] with details of what needs correction
- We will update your data within 10 business days
7.3 Right of Deletion (POPIA §23(1)(d))
You can request deletion of your data (subject to legal exceptions):
- Click Settings → Account → Delete My Account, or
- Email [DATA-PROTECTION-EMAIL] with subject "Data Deletion Request"
- Exception: AFS records and financial data must be retained for 7 years (SARS requirement)
- We will delete your data (except legally required records) within 30 days
7.4 Right to Object (POPIA §23(1)(e))
You can object to processing of your data for direct marketing:
- Click Settings → Communications → Opt Out of Marketing, or
- Email [DATA-PROTECTION-EMAIL] with subject "Opt Out"
- We will stop sending marketing emails within 5 business days
7.5 Right to Lodge a Complaint
If you believe THE ACCOUNTANTS is mishandling your data, you can:
- Contact us first: [DATA-PROTECTION-EMAIL]
- If unresolved, lodge a complaint with the Information Regulator (South Africa's data protection authority)
- Information Regulator: www.justice.gov.za/inforeg/
8. SUB-PROCESSORS (THIRD PARTIES)
THE ACCOUNTANTS uses the following sub-processors to handle your data:
| Sub-Processor |
Purpose |
Location |
| Railway |
Hosting (servers, database, storage) |
USA (US-East) |
| DigitalOcean Spaces |
File storage (documents, exports, uploads) |
USA |
| SendGrid |
Email delivery (transactional emails) |
USA |
| Anthropic |
AI features (if enabled) |
USA |
Important: Your data may be transferred to the USA for processing by these sub-processors. This transfer is lawful under POPIA §72 (lawful transfer outside South Africa) because these sub-processors comply with international data protection standards (ISO 27001, SOC 2).
If you object to your data being processed outside South Africa, please notify us at [DATA-PROTECTION-EMAIL].
9. DATA BREACH NOTIFICATION
If THE ACCOUNTANTS discovers that your personal information has been compromised (unauthorized access, theft, loss), we will:
- ✅ Notify you within 30 days (per POPIA §22)
- ✅ Provide details of what data was affected
- ✅ Explain the steps we're taking to secure your data
- ✅ Recommend actions you should take (password change, monitor accounts, etc.)
We will also notify the Information Regulator if the breach poses a significant risk.
10. ACCOUNTANT RESPONSIBILITY & DISCLAIMER
Important Clarification: THE ACCOUNTANTS is an AFS compilation tool provider, not a data controller for your clients' financial data. You (the accountant) remain responsible for:
- ✅ Verifying that client data is accurate and complete before input
- ✅ Ensuring IFRS for SMEs compliance in the final AFS you deliver
- ✅ Obtaining client consent for data processing and AFS distribution
- ✅ Maintaining audit trails and supporting documentation
- ✅ Compliance with all South African accounting standards and regulations
THE ACCOUNTANTS provides the platform; you provide the professional judgment and accountability.
11. DURATION OF THIS AGREEMENT
This DPA is effective as long as you use THE ACCOUNTANTS. Upon account deletion:
- We delete your data (except legally required records)
- This DPA remains in effect for 7 years (retention period for business records)
12. CHANGES TO THIS AGREEMENT
THE ACCOUNTANTS may update this DPA as laws change or our practices improve. Material changes will be notified via email at least 30 days before taking effect. Your continued use of the platform constitutes acceptance of the updated DPA.
13. CONTACT US
If you have questions about this DPA or your data, contact:
- Data Protection Officer: [DPO-NAME]
- Email: [DATA-PROTECTION-EMAIL]
- Mailing Address: [PHYSICAL ADDRESS]
Response time: within 10 business days.
14. GOVERNING LAW
This DPA is governed by the laws of South Africa (Western Cape). Any disputes shall be subject to the jurisdiction of the South African courts.
Questions About Your Data Rights?
You have rights under POPIA. If THE ACCOUNTANTS is not responding to your data access or deletion request within 30 days, you can lodge a complaint with:
Information Regulator of South Africa
Email: enquiries@inforeg.org.za
Phone: 010 536 1300
Website: www.justice.gov.za/inforeg/