For accounting practices
Data processing agreement
This is the standard agreement each practice accepts before RecordsIn handles any client data. Blank lines (________) are filled in when a practice accepts it. Questions: nexttryis@gmail.com.
Parties
(1) blank ("the Practice", "you"), the controller; and
(2) Next Try is, United Kingdom, operator of RecordsIn ("we", "us"), the processor. Contact: nexttryis@gmail.com.
This agreement covers the personal data we handle for you when you use RecordsIn. It is made under Article 28 of the UK GDPR and forms part of your RecordsIn service terms. If the two conflict on data protection, this agreement wins.
1. What the processing is
1.1 Subject matter: collecting your clients' records and documents for Making Tax Digital for Income Tax (MTD ITSA) quarterly updates, on your behalf.
1.2 Duration: from acceptance until the RecordsIn service ends, plus the time needed to delete or return data under clause 9.
1.3 Nature and purpose: we
- chase your clients and their contacts for records by email, and by WhatsApp and SMS when you switch those channels on;
- receive, store, read and extract data from the records and documents they send;
- produce MTD category totals or an import file for you to review and submit; and
- keep the logs needed to run, secure and support the service.
We do not submit anything to HMRC, and we do not use your data for our own purposes.
1.4 Data subjects: your clients, and their contacts (for example bookkeepers, spouses or staff who send records for them). Your own staff who use RecordsIn.
1.5 Types of data: names; contact details (email, mobile number, WhatsApp number); your client references; financial records and documents (bank statements, invoices, receipts, income and expense figures); message content; and technical data (delivery and access logs). We do not expect special category or criminal offence data. Please tell your clients not to send it. If any arrives, we will handle it securely, tell you, and delete it on your instruction.
2. Your instructions
2.1 We process the personal data only on your documented instructions. Your instructions are this agreement, your RecordsIn settings (clients, channels, schedules and templates) and any written instruction you send to nexttryis@gmail.com. This includes instructions about international transfers.
2.2 If UK law requires us to do something else, we will tell you first, unless the law forbids it.
2.3 We will tell you straight away if we think an instruction breaks data protection law.
2.4 You are responsible for having a lawful basis to give us the data and for telling your clients about it (for example in your engagement letter or privacy notice).
3. Confidentiality
Everyone we allow to access your data (our staff, contractors and agents) is bound by a written duty of confidence or a legal duty of confidentiality, and may access it only as needed to provide the service.
4. Security
We take the measures required by Article 32 of the UK GDPR, including:
- encryption in transit (TLS/HTTPS) and at rest across our hosting, storage and email providers;
- client documents and the service database held on Oracle Cloud Infrastructure in UK South (London);
- Google Workspace / Gmail / Drive for email and documents, n8n for automated workflows, and Cloudflare for web traffic, DNS and protection against attack;
- access control: unique accounts, multi-factor authentication where available, and least-privilege access, so people and systems get only the access they need;
- secrets kept in credential stores, never in documents, chat or code;
- separation of each practice's data, backups, and logging of access and changes; and
- regular review of these measures.
5. Sub-processors
5.1 You give general written authorisation for us to use the sub-processors listed in the Schedule.
5.2 We will give you at least 30 days' notice by email before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot address your objection, you may stop using the affected feature, or end the service, without penalty.
5.3 Each sub-processor is bound by a written contract with data protection terms equivalent to this agreement. We remain fully liable to you for their performance.
6. Helping you
6.1 Data subject rights: we will pass to you, within 5 working days, any request we receive from your clients (for example access, correction or deletion), and help you respond to it. We will not answer it ourselves unless you tell us to.
6.2 We will also help you with security, breach notification to the ICO and to individuals, data protection impact assessments (DPIAs), and any prior consultation with the ICO, taking into account the nature of the processing and the information available to us.
7. Personal data breaches
7.1 We will tell you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data.
7.2 We will tell you what we know: what happened, the data and people likely affected, the likely consequences, and what we are doing about it. We will update you as we learn more.
7.3 We will not notify the ICO or your clients on your behalf unless you ask us to.
8. Audits and information
We will give you the information you need to show that we and you comply with Article 28. We will allow, and contribute to, audits and inspections by you or an auditor you appoint, on reasonable notice, during working hours and under confidentiality. We may answer first with documents, such as our security summary and sub-processor certifications, where that is enough.
9. End of service
Within 30 days of the end of the service, we will delete your personal data, or return it to you first if you ask before then, and confirm deletion in writing. This includes copies held by sub-processors, except routine backups, which are overwritten in their normal cycle and kept secure until then. We keep data longer only where UK law requires it, and only for as long as it requires.
10. International transfers
10.1 We keep your client documents and service database in the UK (Oracle UK South, London) where we can. Some sub-processors process data outside the UK. The Schedule shows where.
10.2 We will make a restricted transfer outside the UK only where it is lawful, for example to:
- a country covered by UK adequacy regulations (including the EEA);
- a US organisation certified under the UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge"); or
- a recipient bound by the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
10.3 On request, we will tell you which mechanism applies to each sub-processor.
11. Liability
Each party is responsible for its own compliance with data protection law and is liable to the other for losses caused by its breach of this agreement, as set out in the UK GDPR (Article 82) and subject to any limits in the RecordsIn service terms. Nothing in this agreement limits liability that cannot be limited by law.
12. General
This agreement is governed by the law of England and Wales. We may update it to reflect changes in the law or the service. We will give you 30 days' notice and a new version number, and you can end the service if you do not accept the change.
Schedule: authorised sub-processors
Locations are taken from each provider's own published information when this version was prepared. "When enabled" means the provider is used only once you switch that channel on.
1. Google (Gmail; also Google Drive)
Purpose: Sending and receiving chase emails; storing documents
Location: Google's global data centres. Google's Workspace sub-processor list names data-centre sites in several countries, including the US and European countries (not UK-only).
2. Cloudflare
Purpose: Website and upload-page delivery, DNS and security
Location: Global network; traffic is handled at the nearest data centre (usually in the UK). Cloudflare is a US company.
3. n8n (n8n Cloud)
Purpose: Running the automated chasing and intake workflows
Location: European Union (Microsoft Azure, for example Germany and Sweden)
4. Oracle Cloud Infrastructure, UK South (London)
Purpose: Hosting the service database and client documents
Location: United Kingdom: UK South (London)
5. LlamaParse (LlamaIndex, Inc.), via the n8n AI gateway
Purpose: Reading and extracting text from uploaded documents. Used through n8n's AI gateway under n8n's provider account, as a sub-processor engaged by n8n.
Location: European Union (as stated in n8n's sub-processor list)
6. Anthropic, via the n8n AI gateway
Purpose: AI reading and categorising of records into MTD categories. Used through n8n's AI gateway under n8n's provider account, as a sub-processor engaged by n8n.
Location: United States (as stated in n8n's sub-processor list; Anthropic stores API data in the US)
7. Meta (WhatsApp Business Cloud API), when enabled
Purpose: Sending and receiving WhatsApp chase messages
Location: Meta data centres. Stored in the United States by default, or in the UK where UK local storage is switched on.
8. Twilio (SMS), when enabled
Purpose: Sending and receiving SMS chase messages
Location: United States (Ireland for supported products when the regional option is used; account data stays in the US)
Acceptance
By ticking "I agree" or typing your name below, you confirm that you are authorised to accept this agreement for the Practice, and that the Practice accepts it.
Accepted by: blank
For: blank
Date and time (UK): blank
Method: blank
DPA version: v1.0
We keep a record of the name, date and time, method and version accepted, and send you a copy.