Data Processing Addendum
Last updated September 28, 2026Effective September 28, 2026
This Data Processing Addendum, including its Annexes (the "DPA"), is incorporated into and forms part of the Terms of Service (the "Agreement") between Circo, Inc. ("Accountable", "we", "us" or "our") and the entity or person accepting the Agreement ("Customer", "you" or "your"). By accepting the Agreement, Customer agrees to this DPA; no separate signature is needed. References to a "Party" or the "Parties" refer to Accountable and Customer. This DPA is effective on the date Customer first accepts the Agreement or accesses or uses the Services (the "Effective Date").
This DPA sets out the Parties' agreement about the Processing of Personal Data by Accountable as a Processor, Service Provider or Contractor on Customer's behalf. It does not apply to Accountable's Processing of Personal Data as an independent Controller, which Section 10 and our Privacy Policy describe. If this DPA conflicts with the Agreement, this DPA takes precedence, but only for the Processing of Personal Data by Accountable on Customer's behalf.
1. Interpretation and Definitions
Unless otherwise defined in this DPA, capitalized terms have the meanings given in the Agreement.
- "Affiliate" means, for any entity, any other entity that directly or indirectly controls, is controlled by, or is under common control with that entity, where "control" means the power to direct the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.
- "Applicable Data Protection Laws" means, as applicable, (i) State Data Protection Laws; (ii) European Data Protection Laws; and (iii) any other laws, rules and regulations relating to the privacy, security, protection or Processing of Personal Data, in each case as amended, superseded or replaced.
- "Authorized Person" means any natural person authorized by Accountable to Process Personal Data on Accountable's behalf under the Agreement and this DPA.
- "Data Subject" means any natural person who can be identified, directly or indirectly, by reference to that person's Personal Data, including "Consumers" as defined under Applicable Data Protection Laws.
- "DP Regulator" means any governmental or supervisory authority or regulatory body with competent jurisdiction to administer or enforce Applicable Data Protection Laws.
- "European Data Protection Laws" means (i) Regulation (EU) 2016/679 (the "EU GDPR"); (ii) the laws relating to data protection and privacy in force in the United Kingdom, including the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 and the EU GDPR as saved into United Kingdom law (the "UK GDPR"); (iii) the EU e-Privacy Directive (2002/58/EC); (iv) national laws made under any of the foregoing; and (v) the Swiss Federal Act on Data Protection (the "Swiss FADP"), in each case as amended, superseded or replaced.
- "Personal Data" means any information relating to an identified or identifiable natural person, or as otherwise defined in Applicable Data Protection Laws, that Accountable Processes on Customer's behalf in connection with the Agreement.
- "Process", "Processing" or "Processed" means any operation performed on Personal Data, whether or not by automated means, or as otherwise defined in Applicable Data Protection Laws.
- "Restricted Transfer" means (i) where the EU GDPR applies, a transfer of Personal Data from the European Economic Area ("EEA") to a country outside the EEA that is not subject to an adequacy decision by the European Commission; (ii) where the UK GDPR applies, a transfer from the United Kingdom to a country not covered by adequacy regulations under the UK GDPR; and (iii) where the Swiss FADP applies, a transfer from Switzerland to a country not subject to an adequacy decision of the Swiss Federal Council.
- "Security Incident" means any breach of security leading to, or reasonably believed to have led to, the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data, or as otherwise defined in Applicable Data Protection Laws.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to the European Commission's Implementing Decision (EU) 2021/914 of 4 June 2021, as supplemented by this DPA.
- "State Data Protection Laws" means all U.S. state laws and their implementing regulations that apply generally to the Processing of Personal Data of Consumers or Households, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code §§ 1798.100 et seq.) (the "CCPA") and the consumer privacy laws of Colorado, Connecticut, Utah, Virginia and other states, as amended or replaced.
- "Subprocessor" means any person (including a Accountable Affiliate) engaged by Accountable, directly or through another Subprocessor, to Process Personal Data under the Agreement and this DPA.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under s119A(1) of the Data Protection Act 2018 (version B1.0, in force 21 March 2022), as amended or replaced.
The terms Business, Service Provider, Contractor, Third Party, Controller, Processor, Sell and Share have the meanings given in Applicable Data Protection Laws.
2. Obligations of the Parties
Both Parties will comply with their respective obligations under Applicable Data Protection Laws, and each Party is solely responsible for determining its own legal and regulatory obligations. Customer is responsible for its secure use of the Services, including protecting its account credentials, API keys and Connected Agent authorizations, and for keeping its own exports of its books. Each Party will reasonably cooperate with the other to enable each Party to comply with its obligations under Applicable Data Protection Laws.
3. Processing Activities
Under Applicable Data Protection Laws, Customer is the Controller or Business, as applicable, and Accountable is the Processor, Service Provider or Contractor, as applicable, for the Processing of Personal Data under the Agreement and this DPA. Where Customer is itself a Processor for another Controller (for example, an accountant keeping a client's books), Accountable is Customer's Subprocessor, and Customer is responsible for obtaining that Controller's authorization.
Accountable will Process Personal Data only on Customer's behalf and on Customer's documented instructions. The Agreement, this DPA, and Customer's use and configuration of the Services (including the Connected Agents and Third-Party Services Customer authorizes) are Customer's complete instructions. Customer's instructions will comply with Applicable Data Protection Laws. Customer has sole responsibility for the accuracy, quality and legality of Personal Data and the means by which Customer acquires it, including notices to and consents from Data Subjects. Annex A describes the subject matter, nature and purpose of the Processing, its duration, the types of Personal Data and the categories of Data Subjects.
Accountable will not (i) Sell or Share Personal Data; (ii) retain, use or disclose Personal Data for any purpose other than performing the Services specified in the Agreement, including for any commercial purpose other than providing the Services; (iii) retain, use or disclose Personal Data outside the direct business relationship between the Parties; (iv) combine Personal Data with personal data it receives from or on behalf of other persons, except as the CCPA permits; or (v) use Personal Data to train or fine-tune artificial intelligence models. Accountable certifies that it understands and will comply with these restrictions. The Parties agree that Personal Data is not exchanged as part of any monetary or other valuable consideration under the Agreement.
This DPA does not apply to Processing of Personal Data that is excluded from Applicable Data Protection Laws.
Accountable will promptly notify Customer if it determines that it can no longer meet its obligations under this DPA or Applicable Data Protection Laws, and will then work with Customer to take reasonable and appropriate steps to stop and remediate any unauthorized Processing. Accountable will cease (and instruct all Subprocessors to cease) Processing Personal Data if Customer reasonably determines that Accountable has not corrected, or cannot correct, the non-compliance within a reasonable time.
4. Technical and Organizational Security Measures
Accountable will ensure that each Authorized Person with access to Personal Data is subject to a duty of confidentiality (contractual, statutory or otherwise) and Processes Personal Data only as needed to provide the Services.
Accountable will implement and maintain appropriate technical and organizational measures to protect the security, integrity and confidentiality of Personal Data and to protect it from Security Incidents, in accordance with Applicable Data Protection Laws. At a minimum, Accountable will maintain the measures in Annex B. Customer acknowledges that security measures change with technical progress, and Accountable may update them, provided that updates do not materially reduce the overall security of the Services.
5. Cooperation
Accountable will provide reasonable assistance to Customer, taking into account the nature of the Processing, to enable Customer to respond to requests, complaints and other communications from Data Subjects, DP Regulators or judicial bodies relating to the Processing of Personal Data, including requests to exercise Data Subject rights. Most requests can be handled by Customer directly in the Services (for example, by editing or exporting records). If a Data Subject makes a request directly to Accountable about Personal Data in Customer's books, Accountable will promptly forward it to Customer and will not respond, other than to tell the Data Subject to contact Customer, without Customer's authorization unless required by law.
If Accountable receives a subpoena, court order, warrant or other legal demand from a third party (including law enforcement or other public authorities) for the disclosure of Personal Data, Accountable will not disclose the data unless legally required, will promptly notify Customer and provide a copy of the demand unless the law prohibits it, and will reasonably cooperate with Customer if it wishes to limit, challenge or protect against the disclosure.
To the extent required by Applicable Data Protection Laws, Accountable will provide reasonable assistance to Customer, at Customer's expense for work beyond the ordinary course, with data protection impact assessments and any required consultations with DP Regulators about the Processing.
6. Subprocessors
6.1 Authorization and notice
Customer gives Accountable general authorization to engage Subprocessors. The current Subprocessors are listed on our Subprocessors page, which forms Annex C. At least thirty (30) days before a new Subprocessor begins Processing Personal Data, Accountable will publish a new version of the Subprocessors page with the change and its date, and will email notice of the change to Customer's workspace owners and to anyone who has subscribed to notices by writing to privacy@accountable.im. In an emergency affecting the continuity or security of the Services, Accountable may replace a Subprocessor on shorter notice, and will give notice as soon as reasonably practicable.
6.2 Objection
Customer may object to a new Subprocessor on reasonable grounds relating to the protection of Personal Data by writing to privacy@accountable.im within thirty (30) days after notice. The Parties will then discuss Customer's concerns in good faith with a view to a commercially reasonable resolution. If no resolution can be reached, Accountable will, at its option, either not use the new Subprocessor for Customer's Personal Data, or permit Customer to terminate the affected Services without liability to either Party and refund any prepaid Fees for the unused part of the term.
6.3 Subprocessor obligations
Accountable will impose data protection terms on each Subprocessor that provide at least the same level of protection for Personal Data as this DPA, to the extent applicable to the nature of its services. Accountable remains responsible for each Subprocessor's compliance with those obligations.
6.4 Services Customer connects
Third-Party Services and Connected Agents that Customer chooses to connect (for example, Customer's bank, payroll provider, accounting software, Slack workspace or an AI assistant it authorizes through our MCP server) are not Accountable's Subprocessors. Customer instructs Accountable to exchange Personal Data with them, and their Processing is governed by Customer's agreements with them.
7. Security Incidents
Accountable will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer's Personal Data. The notice will be sent to Customer's workspace owners by email and will describe, to the extent known, the nature of the Security Incident, the categories and approximate number of Data Subjects and records concerned, its likely consequences, and the measures taken or proposed to address it; Accountable will provide further information as it becomes known. Accountable will take reasonable steps to contain, investigate and mitigate the Security Incident and will provide reasonable assistance to enable Customer to notify DP Regulators or Data Subjects where Customer is required to do so. Accountable's notification of or response to a Security Incident is not an acknowledgment of fault or liability.
8. Jurisdiction-Specific Terms for Personal Data Subject to European Data Protection Laws
8.1 Application
To the extent Personal Data is subject to European Data Protection Laws, this Section 8 applies in addition to the rest of this DPA and, where they conflict, takes precedence for that Personal Data. Accountable will notify Customer, unless prohibited by law, if it believes that an instruction from Customer violates European Data Protection Laws.
8.2 Standard Contractual Clauses
When the transfer of Personal Data from Customer (as "data exporter") to Accountable (as "data importer") is a Restricted Transfer, the SCCs are incorporated into and form part of this DPA, completed as follows:
- For Personal Data protected by the EU GDPR: Module Two (Controller to Processor) or Module Three (Processor to Processor) applies, as appropriate; in Clause 7, the optional docking clause does not apply; in Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 6.1; in Clause 11, the optional language does not apply; in Clause 13, the competent supervisory authority is the one determined by Clause 13(a) given Customer's establishment or, if Customer has none in the EEA, its representative; in Clause 17, Option 1 applies and the SCCs are governed by the laws of Ireland; in Clause 18(b), disputes are resolved before the courts of Ireland; Annex I of the SCCs is completed with the information in Annex A of this DPA; and Annex II of the SCCs is completed with the information in Annex B of this DPA.
- For Personal Data protected by the UK GDPR, the SCCs as completed under paragraph 1 apply as amended by Part 2 of the UK Addendum; Tables 1 to 3 in Part 1 of the UK Addendum are completed with the information in Annexes A and B of this DPA; and in Table 4, "neither party" may end the UK Addendum as set out in its Section 19.
- For Personal Data protected by the Swiss FADP, the SCCs as completed under paragraph 1 apply with these modifications: references to "Regulation (EU) 2016/679" are to the Swiss FADP, and references to its articles are to the equivalent provisions of the Swiss FADP; references to "EU", "Union", "Member State" and "Member State law" are to Switzerland and Swiss law, and the term "Member State" does not exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and the competent courts are those of Switzerland; and in Clause 17 the SCCs are governed by the laws of Switzerland.
Neither Party intends this DPA to contradict or restrict the SCCs; if the SCCs conflict with the Agreement or this DPA, the SCCs prevail to the extent of the conflict.
8.3 Alternative transfer mechanisms
If Accountable adopts another lawful mechanism for Restricted Transfers (such as certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions), that mechanism will apply instead of the SCCs, upon notice to Customer, to the extent it complies with European Data Protection Laws and covers the transfers concerned.
8.4 Data location
Customer Data is hosted by Cloudflare. Accountable's databases and file storage are located in the United States; the data store for an individual company's books is created by Cloudflare in the data center region nearest to where it is first used, which for customers outside the United States may be in their own region. Subprocessors may Process Personal Data in the locations shown on the Subprocessors page. Accountable will provide Customer, on request, the identity, role, processing purpose and location of each Subprocessor.
9. Audits
Accountable will provide Customer, on a confidential basis, with written responses (which may include summaries or extracts of security assessments and third-party audit reports when available) to all reasonable requests for information about Accountable's Processing of Personal Data that are necessary to confirm Accountable's compliance with this DPA, or that Customer must obtain under Applicable Data Protection Law. Customer may exercise this right once per calendar year, and in addition when a DP Regulator requires it or after a Security Incident. Where the SCCs apply and these written responses are not sufficient to demonstrate compliance, Customer may conduct an audit under Clause 8.9 of the SCCs, at Customer's expense, on at least thirty (30) days' notice, during business hours and subject to reasonable confidentiality and security requirements. Nothing in this Section requires Accountable to disclose trade secrets, information that would breach its confidentiality obligations to others or applicable law, or information whose disclosure could compromise the security of its systems or data.
10. Accountable's Processing as a Controller
In connection with the Agreement, Accountable Processes Personal Data about Customer's Authorized Users and other business contacts as an independent Controller: to create and secure accounts, record sign-ins and acceptance of our terms, communicate with Customer's personnel, provide support, manage billing, prevent fraud and abuse, comply with legal obligations, and as described in the Privacy Policy. That Processing is governed by the Privacy Policy and Applicable Data Protection Laws, and the Processor obligations in this DPA do not apply to it.
11. Effect of Termination; Return and Deletion
This DPA (i) begins on the Effective Date and remains in effect until no Personal Data remains in the possession or control of Accountable or any Subprocessor, and (ii) survives expiration or termination of the Agreement.
Customer can export its Personal Data at any time through the Services, and for thirty (30) days after termination of the Agreement. Upon Customer's request at any time, and in any case after that thirty-day period, Accountable will delete Customer's Personal Data from its active systems within thirty (30) days, and copies in encrypted backups will expire within thirty-five (35) days after deletion. This does not apply to Personal Data that Accountable is required by applicable law to retain, which Accountable will protect with the measures in this DPA and not Process except as that law requires.
12. General
Any claim or remedy Customer or its Affiliates may have against Accountable or its Affiliates, employees, agents and Subprocessors arising under or in connection with this DPA (including the SCCs), whether in contract, tort (including negligence) or any other theory of liability, is subject to the limitations and exclusions of liability in the Agreement, except as the SCCs or Applicable Data Protection Laws do not permit. Any reference in the Agreement to a Party's liability means the aggregate liability of that Party and all of its Affiliates under the Agreement and this DPA together.
If any part of this DPA is held unenforceable, the rest remains in effect. Accountable may update this DPA by publishing a new version at https://accountable.im/legal/dpa, with earlier versions kept readable, provided the update does not materially reduce the protection of Personal Data; material changes are notified as described in the Agreement.
To the extent required by Applicable Data Protection Laws or the SCCs, this DPA is governed by the law of the applicable jurisdiction. Otherwise it is governed by the law that governs the Agreement.
This DPA, including its Annexes, is the Parties' entire agreement about its subject matter and supersedes any prior understandings about it. Customer may request a countersigned copy by writing to privacy@accountable.im.
Annex A: Details of the Processing
A. List of parties
Data exporter (Controller): the entity identified as "Customer" in the Agreement. Address and contact details: those associated with Customer's account. Activities relevant to the transfer: use of the Services to keep its books. Role: Controller (or Processor on behalf of its clients).
Data importer (Processor): Circo, Inc., 1625 San Carlos Ave, Unit D, San Carlos, CA 94070, USA. Contact: privacy@accountable.im. Activities relevant to the transfer: providing the Services under the Agreement. Role: Processor (or Subprocessor).
B. Description of the Processing
Categories of Data Subjects: Customer's Authorized Users; Customer's owners, officers, employees and contractors; Customer's customers, vendors, suppliers and other counterparties; Customer's investors and lenders; and any other individuals whose information appears in the books, documents or messages Customer puts into the Services.
Categories of Personal Data: names and contact details; job titles and roles; financial transaction data (payee and payer names, amounts, dates, descriptions, invoices and bills); masked bank and card account numbers and balances; payroll journals (names and pay amounts); tax identification numbers of vendors, contractors and the company (from W-9 forms and company settings); documents and their contents (statements, receipts, invoices, contracts); messages and comments; account and usage data such as IP addresses and activity logs.
Sensitive data and safeguards: tax identification numbers, which for individuals can be Social Security numbers, and bank connection credentials and tokens. Safeguards: encrypted at the application layer with keys held separately from the data (bank credentials and tokens with their own key); shown only masked in the Services and never written to logs; decrypted only for the task that needs them (for example, a 1099 export); access restricted by role and logged.
Frequency of the transfer: continuous, for the term of the Agreement.
Nature of the Processing: hosting and storage; retrieving data from the Third-Party Services Customer connects; categorizing, matching, reconciling and reporting; reading documents; answering questions and proposing changes with AI Features; sending emails and messages Customer requests; support and Service Desk work Customer orders; backup and security monitoring.
Purpose of the Processing: providing the Services to Customer under the Agreement.
Duration and retention: for the term of the Agreement, then until deletion as described in Section 11.
Transfers to Subprocessors: for the subject matter, nature and duration described on the Subprocessors page (Annex C).
C. Competent supervisory authority
As determined under Clause 13 of the SCCs.
Annex B: Technical and Organizational Security Measures
Accountable maintains at least the following measures. The Security page describes them further.
- Isolation: each company's books are stored in their own isolated data store; a membership check runs before any request reaches a company's books; the web application, AI Features, Connected Agents and the API all write through the same checked path.
- Encryption: data is encrypted in transit with TLS and at rest by our hosting provider; bank and payroll credentials and tokens, employer identification numbers, vendor tax identification numbers and single sign-on secrets are additionally encrypted at the application layer with keys stored as secrets separate from the data.
- Access control: sign-in with emailed one-time codes, Google or company single sign-on, with optional two-factor authentication for every user and required two-factor authentication for staff access in production; breached-password checks; role-based permissions (owner, admin, member, accountant, viewer); OAuth with scoped, revocable, expiring tokens for Connected Agents; sessions that end immediately on sign-out or revocation.
- Staff access: limited to staff who need it for support or a Service the customer ordered, with roles and least privilege; Service Desk access to a company's books only through an open request and recorded in that company's activity log; refunds and staff changes require two-factor verification.
- Integrity and audit trail: double-entry validation of every entry before it posts; posted entries are never edited or deleted (undo writes a reversing entry); closed periods stay locked unless reopened with a logged reason; idempotency keys so a retried write never posts twice; an activity log of every change with its author (person, AI Feature or Connected Agent), time, reason, and values before and after.
- AI safeguards: risky changes proposed by AI Features and Connected Agents wait for a person's approval; agents cannot approve their own changes; no tool exists for agents to move money, manage users or change billing or security; customer data is not used to train models.
- Read-only financial connections: bank, card and payment connections are used only to read data; the Services never move funds.
- Availability and recovery: hosting on Cloudflare's globally distributed network; point-in-time recovery of our databases, including each company's books, for thirty (30) days; exports available to customers at any time.
- Secure development: automated tests for every change, including tests that every agent and company boundary refuses unauthorized access; secrets never stored in source code; dependencies from maintained sources.
- Vendor management: Subprocessors bound by written data protection terms; the list published with thirty (30) days' notice of changes.
- Incident response: a documented process to contain, investigate and notify Security Incidents within the time in Section 7; a public Vulnerability Disclosure Policy and security@accountable.im.
- Data minimization and deletion: only the data needed for the Services is collected from connected services; deletion on request and after termination as described in Section 11.
Annex C: Subprocessors
The list of Subprocessors, their purposes and locations is published at https://accountable.im/legal/subprocessors and is incorporated into this DPA.
Version history
- September 28, 2026Effective September 28, 2026First published version.
Questions about this document: legal@accountable.im.