LEGAL & TRUST
Data Processing Agreement
Updated 9 September 2026 · AIONA Grade & AIONA Bookkeeping
On this page
- 1. Subject matter and duration
- 2. Nature and purpose of processing
- 3. Categories of data and data subjects
- 4. AIONA's obligations
- 4A. Customer's obligations
- 5. Sub-processors
- 6. Security measures (Article 32)
- 7. Deletion and retention
- 8. Audit
- 9. International transfers
- 10. Liability and order of precedence
- Execution
How this DPA applies. This DPA forms part of our Terms of Service and applies to every Customer account from the point of sign-up. Any Customer may request a countersigned copy for its own records (see Execution). The sub-processor register and the security measures in §6 are maintained to reflect the live system, and the version and date above change whenever they do.
This Data Processing Agreement ("DPA") is entered into between the customer identified in the account registration or applicable order ("Customer", the controller or a processor authorised to instruct AIONA on behalf of its controller) and AIONA Ltd (trading as AIONA), a company registered in England and Wales with company number 16606520, registered office 128 City Road, London, United Kingdom, EC1V 2NX, ICO registration number ZC189017 ("AIONA", the processor), and forms part of the Terms of Service. It is made under Article 28 of the UK GDPR.
1. Subject matter and duration
AIONA processes personal data contained in the accounting records, source documents, connected Xero records, Grade findings, source references, scorecards, reports and contact data the Customer uploads to, connects to or generates in AIONA Grade or AIONA Bookkeeping, for as long as the Customer holds an account plus the retention period in §7.
2. Nature and purpose of processing
- Read-only review of connected Xero records, generation of Grade findings and scorecards, source-record links and PDF reports;
- Automated data extraction and AI-assisted classification of uploaded documents where Bookkeeping is enabled;
- Double-entry bookkeeping, reconciliation, reporting and (on the Customer's explicit approval) submission of returns to HMRC;
- Storage of source documents as the evidence chain behind posted journals;
- Transactional email and billing where those features are enabled.
3. Categories of data and data subjects
| Data subjects | Personal data categories |
|---|---|
| The Customer's staff and account users | Names, business email addresses, roles, authentication records, actions taken (audit trail) |
| The Customer's suppliers, customers and contacts | Names, business contact details, bank details appearing on invoices, transaction descriptions and amounts |
| Employees (where payroll features are used) | Names, National Insurance numbers, pay and deduction figures required for RTI submissions |
No special-category data is required by the Service; the Customer agrees not to upload it except where it incidentally appears in source documents.
4. AIONA's obligations
AIONA shall:
- process personal data only on the Customer's documented instructions - including with regard to transfers of personal data outside the United Kingdom (§9) - the Customer's use of the Service constituting its instruction; where UK law requires AIONA to process otherwise, AIONA will inform the Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest;
- ensure persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in §6;
- engage sub-processors only under §5;
- assist the Customer with data-subject requests (Articles 12-23) and with Articles 32-36 obligations, taking into account the nature of the processing;
- notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Customer's personal data, and provide - as the information becomes available - the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, so the Customer can meet its own notification obligations to the ICO and data subjects; AIONA will not notify regulators or data subjects on the Customer's behalf unless legally required or instructed;
- at the Customer's choice, delete or return the personal data at the end of the engagement, subject to statutory retention duties (§7);
- make available information necessary to demonstrate compliance and allow audits as set out in §8;
- immediately inform the Customer if, in AIONA's opinion, an instruction from the Customer infringes the UK GDPR or other applicable UK data-protection law.
4A. Customer's obligations
The Customer is responsible for the lawfulness of the personal data it uploads or connects (including having a lawful basis and giving any required privacy notices to its own staff, suppliers, customers and contacts), for the accuracy and legality of its instructions, and for managing its users' access rights. The Customer warrants that its instructions to AIONA will comply with UK GDPR.
5. Sub-processors
The Customer gives general written authorisation for the providers acting as AIONA sub-processors identified in the Privacy Policy §5 (hosting, document data extraction and storage, AI assistant, outbound and inbound email, billing, bank feeds, error monitoring). AIONA will update that register and give at least 14 days' prior notice by email before adding or replacing a sub-processor; the Customer may object on reasonable data-protection grounds within that 14-day window, in which case the parties will discuss in good faith and, if no resolution is found, the Customer may terminate the affected feature or - where the sub-processor is integral to the Service (such as hosting or document storage) - terminate the affected Services and receive a pro-rata refund of prepaid fees. AIONA remains fully liable for its sub-processors' performance.
6. Security measures (Article 32)
- Encryption in transit (TLS) and at rest (provider-managed) for all customer data;
- OAuth tokens for HMRC and bank-feed integrations are additionally encrypted at the application level (AES-based authenticated encryption) before storage;
- UK/EU data residency for primary storage (London region hosting and storage; EU document-AI processing);
- Tenant isolation enforced in two independent places: in the application layer on every query, and by database-level row-level-security policies enforced in production on tenant tables, so a query that omits its tenant context returns nothing rather than another Customer's records;
- An append-only, hash-chained audit trail of posting and submission actions; posted ledger entries are immutable at the database level;
- Role-based access control, bcrypt password hashing, account lockout, rate limiting and refresh-token revocation;
- Least-privilege database roles for the running application (no schema-modification rights);
- Anonymisation with k-anonymity thresholds before any cross-tenant aggregation.
7. Deletion and retention
At the end of the service, the Customer may choose return or deletion of its personal data. On account closure or written request, AIONA will return or delete that data within 30 days, and delete remaining copies unless applicable law requires retention. Where a legal retention duty prevents deletion, AIONA will explain the basis and scope, restrict processing to that purpose and delete the data when that duty ends.
The standard seven-year Bookkeeping retention policy in the Privacy Policy supports the Customer’s record-keeping instructions while records are held in the Service; it does not override the return or deletion obligation above or impose a blanket seven-year retention period on Grade reviews. Backups remain protected and expire under the applicable backup rotation; if a backup is restored, deletion instructions must be reapplied. Replacing a user identifier in a ledger is not a substitute for deleting other personal data where deletion is required.
Subscription cancellation and Xero disconnection are separate from account closure. Saved Grade reviews remain available while the account remains open. Contact support@aionatech.com to arrange data return or deletion.
8. Audit
AIONA will make available, on request and no more than once per 12-month period (unless a breach has occurred), the information reasonably necessary to demonstrate compliance with this DPA - including summaries of security measures, sub-processor terms and relevant certifications. Where this is insufficient, the Customer may conduct (at its own cost, on 30 days' notice, without access to other customers' data) an audit through an independent auditor bound by confidentiality.
9. International transfers
Primary hosting and document storage are in the United Kingdom/EU (London-region hosting; UK/EU-region cloud storage; EU-region document AI). Where a sub-processor processes personal data outside the UK/EEA - currently Anthropic, Resend, Stripe and Sentry, in the United States (see Privacy Policy §9) - the transfer is protected by the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement entered into with that sub-processor, or by UK adequacy regulations (including the UK Extension to the EU - U.S. Data Privacy Framework where the recipient is certified).
10. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms, this DPA prevails for data-protection matters.
Execution
This DPA applies to your account by incorporation into the Terms of Service. If you need a countersigned copy for your own records, email support@aionatech.com with "DPA" in the subject line and your company details, and we will return one.