New

QuickBooks Online + Xero publishing is here.

See how it works
taently

Zero-decision bookkeeping

From messy documents to clean books.

See the complete Tallently workflow from capture to export.

Product overview
Document captureUpload, paste and email-inAI extractionClassify, split and extractReviewOnly the exceptions need youSupplier automationRules that remove future workArchive & exportSearch, retain and share clean data
Connected booksPublish with the original attached.
qbQuickBooks OnlineFor US businessesxeroXeroFor UK businesses
View all integrations
PricingSecurityBlog
Log inStart free
Controller-to-processor terms

Data Processing Agreement

The instructions, safeguards and transfer terms that apply when Tallently processes personal data for your business.

Effective July 19, 2026Version 1.1
PrivacyTermsCookiesDPASubprocessors

On this page

  1. 01Parties and legal effect
  2. 02Definitions
  3. 03Roles and compliance
  4. 04Documented instructions
  5. 05Confidentiality and personnel
  6. 06Security measures
  7. 07Subprocessors
  8. 08International data transfers
  9. 09Data-subject requests
  10. 10Personal data incidents
  11. 11DPIAs, regulators and compliance information
  12. 12Audit rights
  13. 13Return and deletion
  14. 14Liability, precedence and duration
  15. 15Annex 1 — Processing details
  16. 16Annex 2 — Technical and organisational measures
  17. 17Contact

Questions about this document?Contact our privacy team.

privacy@tallently.com
On this page 17 sections
  1. 01Parties and legal effect
  2. 02Definitions
  3. 03Roles and compliance
  4. 04Documented instructions
  5. 05Confidentiality and personnel
  6. 06Security measures
  7. 07Subprocessors
  8. 08International data transfers
  9. 09Data-subject requests
  10. 10Personal data incidents
  11. 11DPIAs, regulators and compliance information
  12. 12Audit rights
  13. 13Return and deletion
  14. 14Liability, precedence and duration
  15. 15Annex 1 — Processing details
  16. 16Annex 2 — Technical and organisational measures
  17. 17Contact
01

Parties and legal effect

This Data Processing Agreement (“DPA”) is between HeavenlyTrade S.R.L.S., trading as Tallently (“Tallently”, “Processor”, “we” or “us”), and the business that has agreed to the Tallently Terms of Service (“Customer”, “Controller” or “you”).

Automatically incorporated into the service agreement

This DPA forms part of the Terms of Service and takes effect when the Customer accepts those Terms or first uses Tallently to process Customer Personal Data. A separate signature is not required.

If the Customer processes personal data for another controller, the Customer is a processor and Tallently is its subprocessor. References to Controller and Processor will be interpreted accordingly.

02

Definitions

“Applicable Data Protection Law” means the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the UK GDPR and Data Protection Act 2018, and other privacy or data-protection law applicable to the processing. “Customer Personal Data” means personal data contained in Customer Content that Tallently processes on the Customer’s behalf. “SCCs” means the European Commission standard contractual clauses adopted by Decision (EU) 2021/914. “Subprocessor” means a third party engaged by Tallently to process Customer Personal Data.

Terms such as controller, processor, data subject, processing and personal data have the meaning given by Applicable Data Protection Law.

03

Roles and compliance

The Customer determines the purposes and essential means of processing Customer Personal Data. Tallently processes that data to provide the service and acts only on documented instructions. Each party will comply with the obligations that apply to its role.

The Customer confirms that:

  • its instructions and use of Tallently comply with Applicable Data Protection Law;
  • it has provided required privacy notices and established a lawful basis for Customer Personal Data;
  • it will not instruct processing that violates law or the rights of a data subject; and
  • it is authorised to appoint Tallently and its subprocessors.

We will inform the Customer if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law, unless law prohibits notice.

04

Documented instructions

The Terms, this DPA, the Customer’s configuration and actions through the service are the Customer’s documented instructions. They authorise Tallently to receive, host, organise, classify, extract, search, display, export, secure, support and delete Customer Personal Data as necessary to provide the service.

Additional instructions must be consistent with the agreement and agreed in writing. We may charge reasonable costs for instructions that require material work beyond the standard service. If law requires processing outside the Customer’s instructions, we will notify the Customer before processing unless the law prohibits notice.

05

Confidentiality and personnel

Tallently will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations, receive appropriate privacy and security guidance, and access data only where needed for their role. Access to production systems is restricted, authenticated and reviewed according to the principle of least privilege.

06

Security measures

Tallently maintains technical and organisational measures designed to provide a level of security appropriate to the risk. The current measures are described in Annex 2 below. The Customer remains responsible for secure configuration, user management, endpoint security and keeping independent copies where appropriate.

We may update the measures as technology and risk change, provided the overall protection of the service is not materially reduced during the agreement.

07

Subprocessors

The Customer gives Tallently general written authorisation to use the providers on our Subprocessors page. We enter into written terms requiring each subprocessor to protect Customer Personal Data to a standard appropriate to its role, and remain responsible for their processing to the extent required by law.

We will provide at least 30 days’ notice before a new subprocessor begins materially processing Customer Personal Data, normally by updating the list and emailing customers subscribed to change notices. Subscribe by emailing privacy@tallently.com.

A Customer may object during the notice period on reasonable data-protection grounds. The parties will work in good faith on a reasonable solution. If none is available, the Customer may terminate the affected service before the subprocessor is engaged; this is the Customer’s sole remedy for the objection.

08

International data transfers

Where Customer Personal Data is transferred from the EEA, UK or Switzerland to a country without an applicable adequacy decision, Tallently will use the SCCs, UK International Data Transfer Addendum, an applicable Data Privacy Framework certification or another valid transfer mechanism.

For transfers governed by the SCCs:

  • Module Two applies where the Customer is controller and Tallently is processor;
  • Module Three applies where the Customer is processor and Tallently is subprocessor;
  • Clause 9 uses Option 2 with the notice period in this DPA;
  • the optional language in Clause 11 does not apply;
  • the governing law for Clause 17 is Italian law and the courts for Clause 18 are those of Italy; and
  • the competent supervisory authority is determined under Clause 13, ordinarily the Italian Garante where Tallently is the exporter.

For restricted transfers from the UK, the UK Addendum issued by the ICO is incorporated and the SCC information in this DPA completes the relevant tables. For Switzerland, references in the SCCs are adapted as required by Swiss data-protection law.

09

Data-subject requests

The Customer is responsible for responding to requests concerning Customer Personal Data. Tallently will promptly forward a request received directly from a data subject where we can identify the relevant Customer and will not respond substantively unless instructed or legally required.

Taking into account the nature of the processing, Tallently will provide reasonable assistance through service functionality and, where needed, additional measures for access, correction, deletion, restriction, objection and portability requests. Reasonable charges may apply for exceptional assistance not caused by our breach.

10

Personal data incidents

Tallently will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. Notification will include information reasonably available about the nature of the breach, likely consequences, affected data and subjects, and measures taken or proposed. Information may be provided in phases as the investigation develops.

We will take reasonable steps to contain, investigate and mitigate the breach and will cooperate with the Customer’s legally required notifications. Notification is not an admission of fault or liability.

11

DPIAs, regulators and compliance information

Taking into account the nature of processing and information available to us, Tallently will provide reasonable assistance with data-protection impact assessments, prior consultations and enquiries from a competent supervisory authority relating to the service. We will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR, subject to confidentiality, security and cost protections.

12

Audit rights

We will first satisfy audit requests through current security documentation, third-party reports, certifications and written responses. If that is insufficient to meet a legal requirement, the Customer may request one audit in a 12-month period by an independent, non-competing auditor bound by confidentiality.

The parties will agree scope, timing and safeguards. Audits must occur during normal business hours, avoid access to other customers’ data and not unreasonably disrupt operations. The Customer bears its costs unless the audit identifies a material breach by Tallently.

13

Return and deletion

During the agreement, the service provides export features for documents and structured data. After the service ends, Customer Content remains available for export for 90 days, unless access is restricted for security or legal reasons.

At the end of that period, Tallently will delete Customer Personal Data from active systems and require subprocessors to delete it under their applicable deletion and backup cycles. We may retain data where law requires it, but will isolate it and process it only for that legal purpose. Backup copies are overwritten according to ordinary retention cycles and are not restored except for disaster recovery.

14

Liability, precedence and duration

Each party’s liability under this DPA is subject to the exclusions and aggregate cap in the Terms of Service. Nothing limits liability that cannot be limited by law.

If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA prevails. The SCCs or UK Addendum prevail over this DPA where required for a restricted transfer. This DPA continues for as long as Tallently processes Customer Personal Data.

15

Annex 1 — Processing details

Details of processing under this DPA
ItemDetails
Subject matter and purposeProviding AI-assisted document capture, storage, classification, extraction, review, search, automation, export, account support, security and related Tallently functionality.
Nature of processingCollection, recording, organisation, storage, retrieval, consultation, automated analysis, structuring, transmission at the Customer’s direction, restriction, export and deletion.
DurationThe service term, the 90-day post-termination export period and applicable deletion/backup cycles.
Data subjectsCustomer users; Customer employees, contractors and advisers; suppliers, customers and other people identified in business documents or correspondence.
Personal-data typesNames, business contact details, account identifiers, roles, tax identifiers, supplier/customer details, invoice and receipt information, bank/payment references, transaction descriptions, signatures where present, email content, document metadata, corrections and audit records.
Sensitive dataThe service is not designed for special-category, criminal-conviction or children’s data. Such data may appear incidentally in a Customer document; the Customer must have a lawful basis and avoid submitting it unless necessary and permitted.
FrequencyContinuous or as initiated by Customer uploads, inbound email, user actions, scheduled jobs and requested exports.
16

Annex 2 — Technical and organisational measures

Tallently security measures
Control areaMeasures
EncryptionTLS for data in transit and provider-managed encryption for database records, files and backups at rest.
Tenant isolationOrganisation-scoped records, PostgreSQL row-level security and private storage paths that enforce customer boundaries.
Identity and accessIndividual accounts, role-based permissions, time-based one-time-password MFA, restricted service credentials and least-privilege administrative access.
File accessPrivate object storage, authenticated access policies, short-lived signed URLs and validation of accepted file types and sizes.
TraceabilityAppend-only audit events for material document and account actions, processing status and user corrections.
AvailabilityManaged cloud infrastructure, encrypted backups, asynchronous processing with retries and upload-first behaviour when downstream processing is unavailable.
Secure developmentCode review, dependency management, environment-separated credentials, webhook signature/token verification and automated type, lint and build checks.
Incident responseOperational monitoring, provider alerts, investigation, containment, recovery and customer-notification procedures.
Data minimisationProcessing limited to service purposes; full payment-card details remain with Stripe; document context sent to AI is limited to extraction needs.
DeletionCustomer export and deletion workflow, 90-day post-termination window, active-system deletion and provider backup expiration.
17

Contact

DPA, transfer or security enquiries may be sent to privacy@tallently.com. Formal notices should identify the Customer organisation and be addressed to HeavenlyTrade S.R.L.S., Via Roma 114, 81100 Caserta (CE), Italy.

Tallently legal

Related documents

Privacy PolicyTerms of ServiceCookie PolicySubprocessors
Current document: Data Processing Agreement
taently

AI-powered bookkeeping and expense automation for small businesses.

Product

OverviewDocument captureAI extractionReviewSupplier automationArchive & export

Integrations

OverviewQuickBooks OnlineXero

Company

AboutBlogContact

Legal

Privacy PolicyTerms of ServiceCookie PolicyData Processing AgreementSubprocessors
© 2026 Tallently by HeavenlyTrade S.R.L.S. · P. IVA IT04635090618. Built for small businesses in the US and UK.Home