Legal
Data processing agreement
Parties and scope
As Counted is operated by Ryan James Spencer, a sole trader in Australia, trading as As Counted (“As Counted”, “we”, “us” or “our”).
This data processing agreement (“DPA”) is between us and the business that has agreed to our terms of service (“you”). It forms part of those terms and applies whenever we process personal data on your behalf in providing As Counted. No separate signature is needed. If you would like a countersigned copy, email legal@ascounted.com.
If this DPA and the terms conflict on the processing of personal data, this DPA applies. If the standard contractual clauses conflict with this DPA, the clauses apply.
Definitions
- Data protection law means the laws that apply to the processing: the GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the Australian Privacy Act 1988 (Cth), and other privacy laws that apply.
- Customer personal data means personal data in the customer data you and your members put into As Counted, which we process on your behalf.
- Controller, processor, data subject, personal data breach and processing have the meanings given in the GDPR.
- Standard contractual clauses means the clauses approved by the European Commission in Decision (EU) 2021/914, and UK addendum means the UK International Data Transfer Addendum to them.
Roles and instructions
For customer personal data, you are the controller and we are your processor. For account data, such as the names and email addresses of the people who sign in and how they use the service, we are a controller, as described in our privacy policy.
We process customer personal data only on your documented instructions. Your instructions are these terms, this DPA and how you and your members use and configure the service, including the integrations you connect. We will tell you if we believe an instruction breaks data protection law. You are responsible for having a lawful basis for the processing and for the instructions you give.
Our obligations
- Confidentiality. Anyone we authorise to process customer personal data is bound by confidentiality.
- Security. We maintain the technical and organisational measures in Annex 2, and may improve them over time without reducing overall protection.
- Data subject requests. Much of what is needed to answer requests to access, correct or delete personal data you can do yourself in the service. Where you cannot, we will help you, taking into account the nature of the processing. If a data subject contacts us directly about customer personal data, we will pass the request to you and not respond ourselves unless you instruct us to or the law requires it.
- Assistance. We will give you information you reasonably need for data protection impact assessments and consultations with regulators about the service.
Subprocessors
You authorise us to use the subprocessors listed on our subprocessors page. We will bind each subprocessor to data protection obligations at least as protective as this DPA, and remain responsible for its performance.
Before a new subprocessor starts processing customer personal data, we will update that page and email your organization's owners at least 30 days in advance. If you object on reasonable data protection grounds, tell us at privacy@ascounted.com within that period. We will try to address your objection; if we cannot, you may end the agreement and we will refund fees paid in advance for the period after it ends.
Services you choose to connect, such as Airtable or Salesforce, are not our subprocessors. We exchange data with them on your instructions, and your own agreement with each of them governs what they do with it.
Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting customer personal data. We will give you the information we have, and more as it becomes available, to help you meet your own obligations to notify regulators and data subjects, and we will take reasonable steps to contain it. Notifying you is not an admission of fault.
International transfers
We operate from Australia, and the service runs on Cloudflare's global network, so customer personal data may be processed outside the country you are in. Where the GDPR applies and you transfer customer personal data to us, Module 2 (controller to processor) of the standard contractual clauses is incorporated into this DPA, with you as data exporter and us as data importer. Where the UK GDPR applies, the UK addendum is incorporated as well. For the clauses:
- the optional docking clause (clause 7) applies;
- under clause 9, option 2 (general written authorisation) applies, with the notice period set out under Subprocessors above;
- the optional language in clause 11 does not apply;
- under clauses 17 and 18, the clauses are governed by the law of, and disputes are resolved by the courts of, Ireland;
- Annex I is completed by Annex 1 below, and Annex II by Annex 2 below.
We transfer data onward to subprocessors only with safeguards that data protection law accepts.
Australian Privacy Act
Where the Privacy Act 1988 (Cth) applies to customer personal data, we will handle it in line with the Australian Privacy Principles as they would apply to you, use and disclose it only to provide the service to you, and help you meet your obligations under the Notifiable Data Breaches scheme.
Deletion and return
When the agreement ends, you can export customer data through the app, the API and the CLI. We will then delete customer personal data, unless the law requires us to keep it. Data in backups maintained by our hosting provider is deleted when those backups expire.
Information and audits
We will make available the information reasonably needed to show that we meet this DPA, and answer your reasonable written questions about our processing. If that is not enough to meet a requirement of data protection law, we will allow an audit by you or an independent auditor you appoint, on reasonable notice, during normal business hours, no more than once a year, and under confidentiality. Each party bears its own costs. Our subprocessors' independent audit reports may be used to meet this obligation for their part of the processing.
General
This DPA lasts as long as we process customer personal data for you. The limits of liability in the terms apply to this DPA, except where the standard contractual clauses or data protection law do not allow it. Apart from the standard contractual clauses, this DPA is governed by the same law as the terms.
Annex 1: Details of processing
| Data exporter | You, the business using As Counted, as controller. Contact: your organization's owners. |
|---|---|
| Data importer | As Counted, as processor. Contact: privacy@ascounted.com. |
| Subject matter and purpose | Providing As Counted: recording stock, orders, purchasing, manufacturing and rentals; calculating availability; imports; the API, CLI and MCP server; and integrations you connect. |
| Nature of processing | Storing, organising, retrieving, calculating with, displaying, transmitting to services you connect, and deleting. |
| Data subjects | Your members; your customers, suppliers and other contacts whose details you record; people named in imported files. |
| Categories of personal data | Names and contact details you record on documents and other records; names and email addresses of members and people you invite; a record of which member made each change and through which client. As Counted is not designed to hold special category data, and you should not put it in. |
| Frequency | Continuous, while you use the service. |
| Duration and retention | The term of the agreement, then deletion as described under Deletion and return. |
| Subprocessors | As listed on our subprocessors page. |
Annex 2: Security measures
- Access control. Every action in the web app, API, CLI and MCP server goes through the same checks of the user's role (owner, manager or staff) and, for CLI and AI clients, the permissions the user granted them.
- Sign-in. Users sign in with Google; we store no passwords. CLI and AI clients use OAuth with a consent screen naming the client, and can be revoked. There are no static API keys.
- Separation. Every record belongs to one organization, and every request is limited to an organization the user is a member of.
- Encryption. Traffic is encrypted in transit with TLS. Access grants for connected integrations are encrypted with AES-256-GCM and are never returned or logged.
- Record of changes. Every command is logged with who made it, through which client, the input and the outcome.
- Infrastructure. The service runs on Cloudflare, whose security and certifications cover the underlying hosting and database.
- Minimal tracking. No advertising or analytics trackers, and third-party telemetry in our sign-in library is turned off.
- Vulnerability reports. We accept reports at security@ascounted.com, as described on our security page.