Accountive Start free trial

Legal

Data processing agreement

Your clients' data, and what we are bound to do with it. This is the one your buyers will actually read.

Last updated 8 September 2026 · [SCORP LEGAL NAME — e.g. S Corp Accounting & Tax Consultancy L.L.C]

Draft for review. This is a working draft prepared to save your lawyer the blank page, not legal advice. Have UAE-qualified counsel read it before it goes live, and fill in every square-bracketed detail first.

This is the document your clients' data is governed by. It applies automatically to every Accountive subscription — you do not need to sign anything separately, though we will sign a copy on request. If your firm has its own DPA it wants used instead, send it to legal@accountive.ae.

1 · Who is who

Your firm is the Controller of the personal data you put into Accountive about your clients and their people. [SCORP LEGAL NAME — e.g. S Corp Accounting & Tax Consultancy L.L.C] is the Processor. We process that data only on your documented instructions — using the service is the instruction — and for no other purpose.

We are not a joint controller and we do not use your clients' data for our own ends: not for advertising, not for resale, and not to train models.

2 · What is processed

Subject matterProviding practice-management software to your firm
DurationFor as long as your subscription is current, plus the 90-day read-only period
Nature and purposeStoring, organising, displaying, calculating deadlines from, exporting and backing up the records you enter
Types of personal dataNames, work contact details, roles and identifiers of your clients' officers, owners and contacts; tax registration numbers; licence details; portal usernames and passwords you choose to store; the contents of bank statements you upload; free-text notes you write
Categories of data subjectYour clients' owners, directors, employees and contacts; your own staff
Special categoriesNone is required by the service. Do not put health or biometric data into it.

3 · What we undertake to do

  1. Process only on your instructions. If we ever believe an instruction breaches UAE law we will tell you rather than act on it.
  2. Keep it confidential. Everyone at our end with access is under a written confidentiality obligation that survives their employment.
  3. Apply security by design. The specific measures are in clause 5 and on our security page, and we will not weaken them during your subscription.
  4. Process only for the agreed period, and tell you if processing needs to run beyond it.
  5. Return or delete on request. On termination you may export everything; after the 90-day read-only period we delete it, and we will confirm deletion in writing if you ask.
  6. Keep a record of the processing we carry out on your behalf, and produce it to the UAE Data Office if required.
  7. Help you meet your own obligations — responding to a data subject who contacts you, completing an impact assessment, or answering the regulator.
  8. Prove it. We will provide the information you reasonably need to verify our compliance, and will accept one audit or detailed security questionnaire per year, at reasonable notice, at your cost.

4 · Sub-processors

You give general authorisation for the sub-processors listed at accountive.ae/subprocessors. Each is engaged under a written contract imposing protections no less demanding than these.

We will give 30 days' notice by email before adding or replacing one. If you reasonably object on data-protection grounds within those 30 days, and we cannot resolve it, you may terminate the affected part of the service and we will refund the unused portion of any prepaid fee — a case where the usual no-refund rule does not apply.

5 · Security measures

  • Separation between firms is enforced by the database, not by the page. Every record carries its workspace and PostgreSQL row-level security refuses reads and writes across workspaces. It was tested with two live accounts rather than reasoned about.
  • Access levels are database rules. A read-only advisor who reached past the interface would still be refused by the database.
  • Portal passwords sit in a separate table that only roles with write access may read, and are stripped out of the client record by a trigger on every save. The audit log records that a password changed — never the value.
  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • A content security policy pinned to the exact application script, so a tampered page will not run.
  • Automatic daily backups with point-in-time recovery; restores are tested, not assumed.
  • An immutable audit log of who changed what, on which record, and when.
  • Multi-factor authentication available on every account and required on ours.

6 · International transfer

Data is hosted in Mumbai, India (AWS ap-south-1) and is therefore transferred outside the UAE. No federal adequacy list has been published under the UAE PDPL, so this transfer relies on contractual safeguards: each sub-processor is bound by written terms requiring protection substantially equivalent to the PDPL, and we remain liable to you for their acts and omissions as if they were our own.

7 · If there is a breach

We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting your data — by email to the workspace owner and administrators, and by telephone where we have a number and the matter is urgent.

We will tell you what happened, which categories and roughly how many records are affected, the likely consequences, what we have done and what we recommend you do. We will keep you updated as we learn more, and help you make any notification you must make as controller.

24 hours is our commitment, not a legal minimum. The UAE PDPL requires a processor to notify the controller “as soon as it becomes aware” without fixing a number, and the implementing regulations that were to set one have not been issued. We would rather commit to a figure than shelter behind that.

8 · Liability and term

This agreement takes effect when you first use Accountive and continues until processing ends. The liability limits in the terms of service apply to it. Where those terms and this agreement conflict on the handling of personal data, this agreement prevails.

It is governed by the federal laws of the United Arab Emirates as applied in the Emirate of Dubai, with the Courts of Dubai having exclusive jurisdiction.

9 · A signed copy

Email legal@accountive.ae with your firm's legal name, licence number and the name of the signatory. We return a countersigned PDF within one working day.