Data Processing Agreement (Annex 2)
Version 2.0, [DATE]. Part of every agreement under which Audit Scoot B.V. (“Provider”) processes personal data on behalf of the customer (“Customer”). Where Customer itself acts as processor for its own clients, Customer warrants it may engage Provider as subprocessor and this DPA applies mutatis mutandis. For UK customers, references to the GDPR include the UK GDPR.
1. The processing model — scope first
Audit Scoot processes Client Audit Data (general ledger files, trial balances, journal entry populations, master data) locally on Customer’s hardware. Provider does not receive, host, store, or access Client Audit Data. Provider’s processor role is therefore limited to the following data transmitted by the application:
| Data stream | Content | Personal data risk |
|---|---|---|
| Mapping Metadata | Column names and standardized category labels of the dataset; no transaction records | Low (column names rarely contain personal data) |
| AI questions | Free-text questions typed by users | May incidentally contain personal data (e.g., “show entries approved by J. Smith”) |
| Licence fingerprint | One-way cryptographic hash of the dataset | None (irreversible; contains no readable data) |
| Account & usage data | User accounts, engagement counts, feature events | Provider acts as controller (see Privacy Policy), not under this DPA |
Nature and purpose: transmission, temporary processing to generate analysis specifications, licensing integrity, deletion. Duration: the term of the underlying agreement.
2. Data subjects and categories
Personnel and counterparties of Customer’s audit clients whose names or identifiers appear incidentally in AI questions or, exceptionally, in column labels; Customer’s own users (as controller data, outside this DPA). No special categories are intended; Customer will not deliberately include them and is encouraged to use field-exclusion options at mapping stage.
3. Instructions
Provider processes the §1 data only on Customer’s documented instructions (the agreement, this DPA, and in-application configuration), unless EU or member-state law requires otherwise, in which case Provider informs Customer before processing unless prohibited. Provider flags instructions it considers infringing.
4. Confidentiality and personnel
Persons authorised to process are bound by contractual or statutory confidentiality; access is least-privilege and logged.
5. Security (Art. 32)
Provider implements the measures in Schedule 1 and will not materially reduce the overall security level during the term.
6. Subprocessors
6.1 Customer grants general authorisation for the subprocessors in Schedule 2. Provider announces additions or replacements at least 30 days in advance; Customer may object on reasonable data-protection grounds; failing a solution, Customer may terminate the affected service with pro-rata refund of prepaid unused fees.
6.2 Provider imposes materially equivalent obligations on subprocessors and remains fully liable for their performance.
7. Data subject rights and assistance
Taking into account the nature of the processing (Provider holds no Client Audit Data), Provider assists Customer with appropriate measures for data subject requests and, insofar as information is available to Provider, with Customer’s Art. 32–36 obligations. Requests received directly are forwarded to Customer without response beyond acknowledgement. Data subjects’ underlying records reside on Customer’s systems.
8. Personal data breach
Provider notifies Customer without undue delay and at the latest within 48 hours of becoming aware of a breach affecting the §1 data streams, with the information reasonably required for Customer’s own notifications, supplemented as it becomes available. Provider documents breaches and remediation. Breaches affecting only data on Customer’s own systems are Customer’s responsibility.
9. International transfers
Server-side processing occurs in the EU. Where the AI subprocessor processes data outside the EEA/UK or is subject to third-country law, the parties rely on an adequacy decision or the EU SCCs (and, for UK data, the UK IDTA/Addendum) executed between Provider and that subprocessor, with supplementary measures as documented.
10. Audit and regulatory inspections
Provider makes available the information reasonably necessary to demonstrate Art. 28 compliance: current security documentation, penetration-test summary [and, when available, third-party assurance reports]. Customer may audit, itself or via a mandated auditor under confidentiality, maximum once per 12 months, on 30 days’ notice, during business hours, without access to other customers’ data, at its own cost. Provider will additionally provide reasonable cooperation where information is required in connection with Customer’s regulatory inspections (AFM/NBA, FRC, PCAOB, or equivalent). Findings are confidential.
11. Deletion, and the local files
Upon termination, any remaining personal data processed under this DPA is deleted within [30] days and deletion is certified on request; in operation, AI-request content (Mapping Metadata and questions) is processed transiently and anonymised operational logs are retained no more than 24 hours before deletion, unless law requires storage. Client Audit Data, project files, and Engagement Archives reside on Customer’s systems under Customer’s exclusive control; their retention, export into the audit file, and deletion are Customer’s responsibility. Provider’s deletion duties do not relieve Customer of its professional retention obligations.
12. Liability and precedence
Liability under this DPA follows the liability provisions of the underlying agreement, including the elevated cap for data-protection breaches. For data-protection subject matter, this DPA prevails.
Schedule 1 — Technical and Organisational Measures
Architecture (primary safeguard). Local-first processing: ingestion, storage, and analysis of Client Audit Data occur exclusively on Customer hardware; datasets are never transmitted to Provider. Generated database queries execute locally with read-only access to the dataset. Project files are single local files under Customer control.
AI data flow. Only Mapping Metadata and the user’s question are transmitted to the AI subprocessor; the proxy is stateless and request content is not persisted; anonymised operational logs are retained no more than 24 hours, then deleted. Processing runs on Google Cloud (Vertex AI) under Google’s Cloud Data Processing Addendum, under which Google does not use submitted data to train its models. The AI subprocessor is contractually barred from training on submitted data.
Licensing integrity. Signed engagement tokens; a one-way HMAC dataset fingerprint (irreversible, no readable content) verifies licence bindings; offline usage records are signed and deduplicated.
Server-side infrastructure. EU hosting ([PROVIDER], region [EU]); logical tenant separation with row-level security on the customer identifier; TLS 1.2+ in transit; AES-256 at rest; key management via [KMS]; no production data on developer machines.
Access control. Role-based, MFA on administrative access, least privilege, personal accounts, [quarterly] access reviews, logged production access.
Application security. Dependency scanning; input validation; [annual] penetration test [first: DATE]; automated cross-tenant isolation tests blocking releases on failure.
Operations. Daily encrypted backups of server-side data, [35]-day retention, restore tests [semi-annually]; authentication and admin-event logging, 12-month retention; documented incident response.
Organisation. Confidentiality clauses for all staff/contractors; onboarding/offboarding checklist; security awareness; annual review of this Schedule.
Schedule 2 — Approved subprocessors
| Subprocessor | Role | Data received | Location | Safeguard |
|---|---|---|---|---|
| [HOSTING PROVIDER] | Website, licensing backend, account data | Account, licensing, Mapping Metadata in transit | EU ([REGION]) | Art. 28 DPA |
| Google (Google Cloud, Vertex AI) | AI generation of analysis specifications | Mapping Metadata + user question only; never Client Audit Data | Vertex AI region nearest the user | Cloud Data Processing Addendum; not used to train models; EU SCCs + UK Addendum; EU–US Data Privacy Framework |
| [EMAIL PROVIDER] | Transactional email | Account contact data | EU | Art. 28 DPA |
| [PAYMENT PROVIDER] | Invoicing/payments | Billing data only | EU | Art. 28 DPA |
Current list: auditscoot.com/subprocessors.