Draft — pending review before publication.

To confirm: governing law (New South Wales, Australia), and the law and courts chosen for the standard contractual clauses.

Legal

Data processing agreement

Last updated

Parties and scope

As Counted is operated by Ryan James Spencer, a sole trader in Australia, trading as As Counted (“As Counted”, “we”, “us” or “our”).

This data processing agreement (“DPA”) is between us and the business that has agreed to our terms of service (“you”). It forms part of those terms and applies whenever we process personal data on your behalf in providing As Counted. No separate signature is needed. If you would like a countersigned copy, email legal@ascounted.com.

If this DPA and the terms conflict on the processing of personal data, this DPA applies. If the standard contractual clauses conflict with this DPA, the clauses apply.

Definitions

Roles and instructions

For customer personal data, you are the controller and we are your processor. For account data, such as the names and email addresses of the people who sign in and how they use the service, we are a controller, as described in our privacy policy.

We process customer personal data only on your documented instructions. Your instructions are these terms, this DPA and how you and your members use and configure the service, including the integrations you connect. We will tell you if we believe an instruction breaks data protection law. You are responsible for having a lawful basis for the processing and for the instructions you give.

Our obligations

Subprocessors

You authorise us to use the subprocessors listed on our subprocessors page. We will bind each subprocessor to data protection obligations at least as protective as this DPA, and remain responsible for its performance.

Before a new subprocessor starts processing customer personal data, we will update that page and email your organization's owners at least 30 days in advance. If you object on reasonable data protection grounds, tell us at privacy@ascounted.com within that period. We will try to address your objection; if we cannot, you may end the agreement and we will refund fees paid in advance for the period after it ends.

Services you choose to connect, such as Airtable or Salesforce, are not our subprocessors. We exchange data with them on your instructions, and your own agreement with each of them governs what they do with it.

Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting customer personal data. We will give you the information we have, and more as it becomes available, to help you meet your own obligations to notify regulators and data subjects, and we will take reasonable steps to contain it. Notifying you is not an admission of fault.

International transfers

We operate from Australia, and the service runs on Cloudflare's global network, so customer personal data may be processed outside the country you are in. Where the GDPR applies and you transfer customer personal data to us, Module 2 (controller to processor) of the standard contractual clauses is incorporated into this DPA, with you as data exporter and us as data importer. Where the UK GDPR applies, the UK addendum is incorporated as well. For the clauses:

We transfer data onward to subprocessors only with safeguards that data protection law accepts.

Australian Privacy Act

Where the Privacy Act 1988 (Cth) applies to customer personal data, we will handle it in line with the Australian Privacy Principles as they would apply to you, use and disclose it only to provide the service to you, and help you meet your obligations under the Notifiable Data Breaches scheme.

Deletion and return

When the agreement ends, you can export customer data through the app, the API and the CLI. We will then delete customer personal data, unless the law requires us to keep it. Data in backups maintained by our hosting provider is deleted when those backups expire.

Information and audits

We will make available the information reasonably needed to show that we meet this DPA, and answer your reasonable written questions about our processing. If that is not enough to meet a requirement of data protection law, we will allow an audit by you or an independent auditor you appoint, on reasonable notice, during normal business hours, no more than once a year, and under confidentiality. Each party bears its own costs. Our subprocessors' independent audit reports may be used to meet this obligation for their part of the processing.

General

This DPA lasts as long as we process customer personal data for you. The limits of liability in the terms apply to this DPA, except where the standard contractual clauses or data protection law do not allow it. Apart from the standard contractual clauses, this DPA is governed by the same law as the terms.

Annex 1: Details of processing

Details of the processing of customer personal data
Data exporterYou, the business using As Counted, as controller. Contact: your organization's owners.
Data importerAs Counted, as processor. Contact: privacy@ascounted.com.
Subject matter and purposeProviding As Counted: recording stock, orders, purchasing, manufacturing and rentals; calculating availability; imports; the API, CLI and MCP server; and integrations you connect.
Nature of processingStoring, organising, retrieving, calculating with, displaying, transmitting to services you connect, and deleting.
Data subjectsYour members; your customers, suppliers and other contacts whose details you record; people named in imported files.
Categories of personal dataNames and contact details you record on documents and other records; names and email addresses of members and people you invite; a record of which member made each change and through which client. As Counted is not designed to hold special category data, and you should not put it in.
FrequencyContinuous, while you use the service.
Duration and retentionThe term of the agreement, then deletion as described under Deletion and return.
SubprocessorsAs listed on our subprocessors page.

Annex 2: Security measures