Data Processing Agreement
Version 1.0 · 10 September 2026
This agreement (the “DPA”) governs our processing of personal data on your behalf when you use Summarly. It forms part of our Terms of Service and applies automatically from the moment you accept them — there is nothing to sign. If your own compliance requires a signed counterpart, email founders@summarly.com and we will execute one.
It is written to satisfy Article 28 of the EU General Data Protection Regulation. Where this DPA and the Terms of Service conflict on the subject of personal data, this DPA prevails.
1. The parties and their roles
You (the customer, and any workspace you own) are the controller. Summarly, a company registered in Cyprus, is the processor.
This applies to everything inside your workspace: transactions, receipts, invoices, customers, suppliers, employees and payslips. It does not apply to your own account data — sign-in identity, billing record, service logs — for which we are the controller and our Privacy Policy governs.
If you are an accountant or a firm holding records on behalf of your own clients, you may be a processor in your own right and your client the controller. Nothing here disturbs that; we are your sub-processor in that arrangement, and this DPA is what you rely on when passing those obligations down.
2. Subject matter, duration, nature and purpose
Subject matter: providing the Summarly bookkeeping service.
Duration: for as long as you have a workspace, and for the short period afterwards described in section 9.
Nature and purpose: storing, organising, categorising, matching, calculating and presenting the financial records you put into the service, and producing the reports, statements, invoices, payslips and exports you ask it for.
3. Categories of data and data subjects
Data subjects: you and your colleagues; your customers and their contacts; your suppliers and their contacts; your employees; and any other individual named in the records you upload.
Categories of personal data: names, business and personal contact details, bank account and transaction details, tax and VAT identifiers, employment and remuneration details including salary, deductions and social insurance identifiers, and the contents of any document you upload.
Summarly is not designed for special categories of personal data (Article 9) and you should not put them into it. Payroll records necessarily touch employment and pay data, which is sensitive in practice even though it is not special-category data in law, and it is treated accordingly.
4. We process only on your instructions
We process personal data only on your documented instructions, including as to transfers, unless required otherwise by EU or Member State law — in which case we will tell you before processing, unless that law forbids it. Your use of the service, together with the Terms and this DPA, constitutes those instructions.
We will tell you if, in our opinion, an instruction infringes data protection law. We do not sell personal data, we do not use it for our own purposes, and we do not use your financial data or assistant conversations to train AI models.
5. Confidentiality
Everyone we authorise to process personal data is bound by an obligation of confidentiality, and access is limited to those who need it to operate and support the service.
6. Security
We implement appropriate technical and organisational measures under Article 32. As at the version date these include:
- Tenant isolation enforced in the database, by row-level security rather than by an application filter, so one workspace’s data cannot be read from another even if the application requests it.
- Encryption in transit and at rest. Uploaded documents are held in private storage reachable only through short-lived signed URLs.
- Role-based access within a workspace, enforced server-side. An invited accountant holds read access and cannot alter your ledger.
- Expiring share linksfor payslips, so a distributed URL does not remain a permanent route to an employee’s data.
- Authentication through a managed identity provider, with sign-in links and OAuth rather than passwords we store.
- Backups of the database, held under the same protections as the live data.
These measures may change as the service develops. We will not reduce the overall level of security.
7. Sub-processors
You give us general authorisation to engage the sub-processors listed below. Each is bound by data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
| Provider | Purpose |
|---|---|
| Supabase | Database, file storage, authentication. |
| Anthropic (Claude) | AI categorization, receipt extraction, and the assistant. Inputs are not used to train models — see our AI Terms. |
| Vercel | Application hosting. |
| MXroute | Sign-in and notification emails we send you. |
| Resend | Receipts and invoices you forward to your workspace email address, and the waiting list. |
| Cloudflare | Bot protection on sign-up and the waiting list, which sees the IP address of the device making the request. |
We will give you at least 30 days’ notice before adding or replacing a sub-processor, by email to your workspace owner and by updating this page. If you object on reasonable data protection grounds within that period, tell us and we will work with you to find a solution; if we cannot, you may terminate and we will refund any prepaid fees for the unused remainder of your term.
Payments are handled by Polar as merchant of record. Polar is a separate controller for the payment, not our sub-processor, and is therefore not covered by this section.
8. International transfers
Your workspace data is stored and processed in the European Union. Where a sub-processor listed above is outside the EEA, the transfer is protected by the EU Standard Contractual Clauses, together with any supplementary measures the transfer requires. The table in section 7 shows where each provider sits.
9. Deletion and return
You can export a complete copy of your workspace at any time from Settings → Privacy & data, without asking us. That is the return mechanism under Article 28(3)(g), and it is available for as long as your workspace exists.
On deletion of your workspace, or on termination, we delete the personal data in it — records and uploaded files — except where EU or Member State law requires us to keep something, such as billing records. Backups are overwritten on their ordinary cycle, and data in a backup remains subject to this DPA until it is.
10. Assisting you
Data subject requests. The export and deletion tools are how you satisfy most requests yourself, immediately and without involving us. Where a request needs more than those tools can do, we will assist you, taking into account the nature of the processing.
Personal data breaches. We will notify you without undue delay after becoming aware of a personal data breach affecting your workspace, with the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken. As controller, your own obligation to notify your supervisory authority within 72 hours under Article 33(1) is yours to discharge, and we will give you what you need to do it.
Impact assessments. We will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the information available to us.
11. Audit
We will make available the information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits conducted by you or an auditor you mandate. In practice, please start by asking us — documentation and written answers satisfy most requests. An on-site audit may be requested no more than once a year, on reasonable notice, during business hours, without unreasonable disruption, and subject to confidentiality. We may charge for the time an on-site audit takes.
12. Liability and changes
The liability provisions of the Terms of Service apply to this DPA. We may update this DPA — for example when the law changes or the service does — and material changes will be notified to you before they take effect, with the version number and date above being what identifies the agreement in force.
Questions, or need a signed counterpart? Email founders@summarly.com.