Last Updated: 11/5/2025
Available for Enterprise customers
The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of personal data to third countries or international organizations.
The Processor implements:
Current sub-processors include:
The Processor shall assist the Controller in responding to requests from data subjects exercising their rights under GDPR/CCPA.
The Processor shall notify the Controller without undue delay (within 48 hours) after becoming aware of a personal data breach.
Enterprise customers have the right to conduct audits of the Processor's data processing activities upon reasonable notice.
Upon termination of services, the Processor shall delete or return all personal data within 30 days, unless legal retention is required.
To execute a DPA for your Enterprise account, contact dpa@ai-bookkeeper.app