Data Processing Agreement

Last updated: July 20, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and Kwata Team ("we," "us"). It describes how we process personal data on your behalf when you use Kwata Books. If you need a countersigned copy for your records, email privacy@kwatateam.com.

1. Roles of the parties

You are the controller of the personal data you put into Kwata Books. You decide what to upload, why, and for how long you keep it. We are the processor: we process that data only to provide the Service and only on your documented instructions, which include your use of the product's features.

Where you upload personal data about other people, such as employees on a payroll run or individuals named on a receipt, you confirm you have a lawful basis to do so.

2. What we process

Categories of data: account and contact details; business and tax identifiers; financial transaction records; uploaded documents such as receipts and invoices; payroll data including compensation and, where you enter it, Social Insurance Numbers; and product usage records.

Categories of data subjects: you and your authorised users, your employees and contractors where you run payroll, and individuals identified in documents you upload.

Purpose: providing bookkeeping, document extraction, reporting, and related features. Nothing else.

3. Purpose limitation

  • We never use your data to train AI models. Your documents and records are not training data, ours or anyone else's.
  • We never sell your data and we do not share it for advertising.
  • Your data is isolated to your account and is not commingled with another customer's for any purpose.
  • We do not access your data except as needed to operate the Service, to fix a fault you have reported, or where the law requires it.

4. Confidentiality

Access to customer data is limited to people who need it to run the Service, and they are bound by confidentiality obligations that survive the end of their engagement.

5. Security measures

The measures below describe what is implemented today.

  • Encryption in transit for all connections to the Service.
  • Encryption at rest for uploaded documents, using a key derived per business, so one customer's key cannot read another customer's files.
  • Encryption at rest for Social Insurance Numbers and for stored third-party integration credentials.
  • Access to data scoped to your account and enforced on every request.
  • Audit logging of authentication and of operations that change your data.
  • Rate limiting on sensitive and expensive endpoints.
  • Regular dependency and vulnerability scanning, with prompt patching.
  • Backups maintained to support recovery.

Not zero-knowledge, stated plainly. Kwata Books decrypts your documents in order to read them, extract data, and show them back to you. We do not claim we are technically unable to access your data. We claim that we do not, that access is limited and logged, and that a breach of the storage layer alone yields ciphertext.

6. Subprocessors

You give general authorisation for us to engage subprocessors to deliver the Service. Each is bound by data protection terms no less protective than this DPA. By function, they are:

  • Managed cloud infrastructure and hosting
  • Object and document storage
  • Enterprise AI model provider, for document extraction and assistance
  • Payment processing, as merchant of record
  • Transactional email delivery
  • Global edge content delivery network
  • Product analytics, self-hosted by us
  • Financial data connectivity and accounting integrations, where you choose to connect them

A current list naming the specific providers is available to customers on request from privacy@kwatateam.com. We will give at least 30 days' notice before adding or replacing a subprocessor. If you reasonably object on data protection grounds, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.

7. Assisting you with individual rights

Kwata Books gives you self-serve tools to satisfy most access and portability requests directly: you can export a complete copy of your data at any time from your account settings, and you can request deletion of your account and its data. Where you receive a request you cannot satisfy with those tools, we will provide reasonable assistance, taking into account the nature of the processing.

8. Security incidents

We will notify you without undue delay and within 72 hours of becoming aware of a breach of security affecting your personal data. The notice will describe what we know, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed. We maintain an internal breach register in line with PIPEDA record-keeping requirements.

Reporting to a privacy commissioner or to affected individuals, where required of you as controller, remains your decision and your obligation. We will give you the information you need to make it.

9. Audit

On written request, once in any twelve-month period, we will provide the documentation reasonably necessary to demonstrate compliance with this DPA, including our security documentation and responses to a due diligence questionnaire. Any on-site audit is at your cost and subject to reasonable notice and confidentiality.

We do not hold a SOC 2 attestation or ISO 27001 certification. Both are on our roadmap. We say what we are built to and aligned with, and we will say we hold a report only once we actually do.

10. Retention and deletion

You control retention. You can delete records at any time, and you can request deletion of your entire account, which we complete within 30 days of the end of the grace period. Inactive accounts are purged on the schedule set out in our Privacy Policy, after advance warning by email.

Your record-keeping duty is yours. The CRA generally requires business records to be kept for six years from the end of the last tax year they relate to. Kwata Books is not your system of record for that purpose. Export and keep your own copies.

11. Your responsibilities

  • You have a lawful basis for the personal data you upload, including data about your employees.
  • You keep your credentials secure and manage who has access to your account.
  • You review the Service's output before relying on it. AI extraction can be wrong, and what you file is your responsibility.

12. Liability

Liability under this DPA is governed exclusively by the limitation of liability in the Terms of Service. This DPA does not create a separate or additional cap, and nothing here increases or reduces the limits set out there.

13. Term, precedence, and governing law

This DPA applies for as long as we process personal data on your behalf. Where it conflicts with the Terms of Service on a data protection matter, this DPA controls; on every other matter, the Terms control. It is governed by the laws of Alberta, Canada.

We may update this DPA. Material changes are notified in advance and require your acceptance, which we record.

14. Contact

Privacy and data protection: privacy@kwatateam.com
Security reports: security@kwatateam.com