Oikos Books — Data Processing Addendum
Version 2.1 · Effective date: September 18, 2026 · Last updated: September 21, 2026 · Contact: [email protected]
What changed in 2.1 (September 21, 2026). Annex I now covers per-person labour cost records, because the Service is gaining the ability to track hours by person against a job. No new identifier is collected: still no Social Security numbers, no dates of birth, no home addresses and no bank details, and the Service still calculates no withholding, classifies nobody and files nothing. Section 13.2 has also been corrected to describe the US-only control accurately: a non-US subscription is cancelled automatically on completion rather than refused at checkout.
Plain-language summary (not a substitute for the full text).
If the books you keep in Oikos Books contain personal information about other people, your clients, your customers, your vendors, your employees, then you are responsible for that information and we handle it only on your instructions. This document is the contract that says so.
It applies automatically. You do not have to ask for it or sign anything. If your firm needs a countersigned copy for its own files, section 1.3 tells you how to get one.
Annex II lists our actual security measures, and it also lists what we deliberately do not claim. We would rather you knew both.
1. What this is, and when it applies
1.1 Purpose. This Data Processing Addendum (the "DPA") forms part of the Oikos Books Terms of Service (the "Terms") between Oikos United LLC ("Oikos," "we," "us") and the customer agreeing to them ("you," "Customer"). It governs our processing of personal data contained in Your Books on your behalf, and it is intended to satisfy Article 28 of the EU General Data Protection Regulation and the UK GDPR, and the service-provider requirements of the California Consumer Privacy Act as amended by the CPRA.
1.2 It applies automatically. This DPA applies to you, without further action by either party, whenever your use of the Service involves personal data relating to individuals other than yourself. That is the ordinary case for an accounting firm keeping books for clients, and for any business whose books contain customer, vendor or employee records. No request, signature or negotiation is required, and nothing in the Service is withheld until you have one.
1.3 If you need a signed copy. Some firms need a countersigned instrument for their own compliance files. Email [email protected] from your account address, naming the legal entity to be recorded as Customer, and we will return this DPA executed by Oikos United LLC for your countersignature. The terms are the terms published here; a signature changes nothing in them.
1.4 Where it does not apply. The free desktop application stores your books on your own computer and transmits nothing to us, so we process nothing on your behalf and this DPA has no subject matter. It begins to apply if you adopt a cloud or online feature.
2. Definitions
"Customer Personal Data" means personal data within Your Books or Your Data that Oikos processes on your behalf under the Terms. "Personal data," "processing," "controller," "processor," "data subject" and "sub-processor" have the meanings given in the GDPR; where the CCPA applies, "business," "service provider," "sell," "share" and "consumer" have the meanings given there. Terms defined in the Terms of Service carry those meanings here.
3. Roles of the parties
- You are the controller (the "business" under CCPA) of Customer Personal Data. You decide what goes into your books, why, and for how long, and you are responsible for having a lawful basis for it and for giving the people concerned whatever notice their law requires.
- Oikos is the processor (the "service provider" under CCPA). We process Customer Personal Data only on your documented instructions, which for these purposes are the Terms, this DPA, and your use of the Service.
- Where we act as a controller in our own right, and this DPA does not govern that processing, is limited and worth naming: your own account and billing records, our security and fraud-prevention logs, and our own business records. Our handling of those is described in the Privacy Policy. Separately, when you connect a bank account through Stripe Financial Connections, or connect your own Ramp account, those providers process data under their own terms and their own relationship with you.
4. Scope and detail of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I, which is incorporated into this DPA.
5. Our obligations as processor
Oikos will:
- 5.1 process Customer Personal Data only on your documented instructions, including in relation to transfers, unless required to do otherwise by law, in which case we will tell you before processing unless the law forbids us from telling you;
- 5.2 not sell or share Customer Personal Data, not retain, use or disclose it for any purpose other than performing the Service, and not combine it with personal data from other sources except as permitted by applicable law. We do not use Customer Personal Data to train AI models, our own or anyone else's;
- 5.3 limit access to the personnel who need it to provide the Service, on the terms in section 6;
- 5.4 implement and maintain the technical and organizational measures described in Annex II;
- 5.5 engage sub-processors only on the terms in section 8;
- 5.6 assist you, so far as is reasonably possible given the nature of the processing and the information available to us, with data subject requests (section 9), with the security of processing, with breach notification (section 10), and with data protection impact assessments and prior consultations;
- 5.7 delete or return Customer Personal Data as set out in section 11; and
- 5.8 make available the information reasonably necessary to demonstrate compliance with this DPA, and submit to audits on the terms in section 12.
6. Confidentiality
6.1 Oikos treats Customer Personal Data as confidential and uses it only to provide the Service.
6.2 Oikos will not authorize any person to access Customer Personal Data unless that person is bound by an obligation of confidentiality covering it. That obligation is undertaken by Oikos under this DPA and is binding on Oikos in respect of every person it authorizes, whether that person is a member, an officer, an employee or a contractor, and it survives the end of their involvement.
6.3 Access is granted on a need-to-know basis and is withdrawn when it is no longer needed.
7. Security
7.1 Oikos implements appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Those measures are set out in Annex II, which describes what is actually in place and is written to be checked rather than admired.
7.2 Security is not static. We may change a measure in Annex II provided the change does not materially reduce the overall level of protection, and we will update Annex II when we do.
7.3 No method of transmission or storage is completely secure. Annex II states the measures we maintain; it is not a warranty that any particular safeguard is effective against every attack.
8. Sub-processors
8.1 General authorization. You give Oikos general authorization to engage the sub-processors listed in Annex III, and to engage replacements and additions on the terms below.
8.2 Flow-down and responsibility. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully responsible to you for their performance.
8.3 Notice of change. We will notify cloud customers by email or in-app notice before a new or replacement sub-processor begins processing Customer Personal Data, and we will update Annex III and the sub-processor table in the Privacy Policy at the same time. This is the same commitment section 15 of the Privacy Policy already makes.
8.4 Objection. You may object to a new sub-processor on reasonable data protection grounds within thirty days of that notice, by emailing [email protected]. We will work with you in good faith to find an alternative. If no reasonable alternative exists and you maintain the objection, you may terminate the affected subscription and we will refund any prepaid fees covering the period after termination, notwithstanding the general no-refund rule in section 6 of the Terms.
9. Data subject requests
9.1 What you can do yourself. Because you control Your Books, most requests are yours to satisfy directly and immediately in the app: you can access, correct, export and delete records without involving us, and export is available at any time in formats you can open elsewhere.
9.2 Where you need us. Taking into account the nature of the processing, we will provide reasonable assistance with requests you cannot satisfy on your own, including requests for access, rectification, erasure, restriction, portability and objection. Contact [email protected] from your account address.
9.3 If a data subject contacts us. We will not respond to a request about Customer Personal Data on our own account. We will refer the person to you promptly, and tell you, unless the law requires us to respond.
10. Personal data breaches
10.1 Oikos will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
10.2 The notice will describe, so far as we know it at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases as it becomes available rather than delaying the first notice.
10.3 We will cooperate reasonably with your own notification obligations. Our notice is not an acknowledgement of fault or liability.
11. Deletion and return
11.1 On your instruction. Email [email protected] from your account address and we will delete your account and cloud data within thirty days. Deletion reaches the books and their version history, the account itself, and receipt images in both the primary and the backup storage bucket.
11.2 On termination without an instruction. Your books remain retrievable for ninety days so you can export them, are then closed to access, and are permanently purged at one year. Those clocks are enforced by an automated sweep that runs daily, not by an intention, and the sweep leaves an append-only record that it ran.
11.3 Export first. Export is available at any time and we recommend you use it before you go. After permanent deletion we cannot recover your records, and financial records usually have to be kept for several years for tax purposes.
11.4 What survives a deletion, stated plainly. Our own billing and tax records are exempt from deletion because law requires us to keep them, and those records contain the account email address. So a completed erasure removes your books, your receipts, your version history and your login, and leaves your email address inside our billing records for as long as tax, accounting and audit law requires, which may be up to seven years. We are a controller for those records, not your processor, and they are not used for anything but the legal purpose that requires them.
11.5 Backups. Database backups run daily and are kept for seven days, so data removed from live systems is gone from database backups within seven days. Receipt images are copied nightly to a second storage bucket, and a deletion under 11.1 reaches that bucket too.
11.6 Legal hold. Data subject to a legal hold is retained until the hold is lifted, which overrides every clock above.
12. Audits and information rights
12.1 We will make available the information reasonably necessary to demonstrate compliance with this DPA. In practice that means Annex II, the Security page, and a written answer to your security questionnaire. We answer questionnaires from real customers as a matter of course.
12.2 Where the information under 12.1 is not sufficient for your legal obligations, you or an independent auditor you mandate may audit our processing no more than once in any twelve-month period, and additionally where a supervisory authority requires it. An audit must be on at least thirty days' written notice, during business hours, under confidentiality obligations, at your cost, and conducted so that it does not compromise the security, confidentiality or availability of any other customer's data.
12.3 What we do not have, said before you ask. Oikos holds no SOC 2 report and no ISO 27001 certification, and has not undergone an independent third-party security audit or penetration test. If your procurement process requires one of those, we would rather you learned it here than three weeks into a diligence cycle.
13. International transfers
13.1 Oikos United LLC is based in the United States, the Service is operated from the United States, and every sub-processor in Annex III processes Customer Personal Data in the United States.
13.2 The Service is offered to customers in the United States only. Checkout collects a billing address, and a subscription with a non-US billing country is cancelled automatically and immediately on completion, so it never becomes an active subscription. A card issued outside the United States is also blocked at the payment step. We therefore do not currently rely on the EU Standard Contractual Clauses or the UK International Data Transfer Addendum, because we do not offer the Service to customers established in the EEA, Switzerland or the UK. If you attempted to subscribe from outside the United States, the billing details you entered are held by our payment processor as a cancelled transaction record, and you may ask us to delete what we hold under section 11.
13.3 If we begin offering the Service to customers subject to EEA, Swiss or UK transfer rules, we will put an appropriate transfer mechanism in place, including the applicable Standard Contractual Clauses and UK Addendum, before doing so, and this section will be replaced accordingly. This matches the commitment in section 13 of the Privacy Policy.
13.4 If you are a US customer whose own books happen to contain personal data about people located in the EEA or the UK, this DPA governs our processing of it on your behalf; your own transfer analysis as controller remains yours.
14. California (CCPA/CPRA)
14.1 With respect to Customer Personal Data, Oikos is a service provider and you are the business. Oikos is provided personal data for the limited and specified purpose of performing the Service.
14.2 Oikos certifies that it understands the restrictions in this section and will comply with them. Oikos does not sell or share Customer Personal Data as those terms are defined by the CCPA, does not retain, use or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA, does not retain, use or disclose it outside the direct business relationship between the parties, and does not combine it with personal data received from another source except as the CCPA permits.
14.3 Oikos will notify you if it determines it can no longer meet its obligations under the CCPA, and you may take reasonable and appropriate steps to stop and remediate unauthorized use.
15. Liability
Each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations in section 12 of the Terms, including the data-incident sub-cap in section 12(c) and the carve-outs in section 12(d). This DPA does not increase or decrease those limits.
16. Term, precedence and changes
16.1 Term. This DPA takes effect when the Terms do, and continues for as long as Oikos processes Customer Personal Data. Sections that by their nature should survive, including sections 6, 10, 11 and 15, survive termination.
16.2 Precedence. This DPA supplements the Terms. On any question of data protection, this DPA controls over the Terms and over the Privacy Policy. On every other question the Terms control.
16.3 Changes. We may update this DPA. For a material change we will give notice by email or in-app notice and update the version and the Last updated date above. A change that reduces the protections in this DPA, or that adds a sub-processor, will not take effect before the notice.
16.4 Governing law. Section 17 of the Terms governs this DPA. Where the GDPR applies, nothing in this section displaces a data subject's rights or a supervisory authority's jurisdiction.
Annex I — Details of the processing
| Item | Detail |
|---|---|
| Controller | The Customer. |
| Processor | Oikos United LLC, Commonwealth of Virginia, USA. |
| Subject matter | Provision of the Oikos Books cloud accounting Service. |
| Duration | The term of the Terms of Service, plus the retention periods in section 11. |
| Nature and purpose | Hosting, storing, syncing, sharing and reporting financial and business records; invoicing and statements; optional bank and card transaction import; optional online payment collection; optional AI assistance, each invoked by the Customer. |
| Types of personal data | Account identifiers (name, email address, organization name); contact records the Customer enters (customers, vendors, contacts, including names, email addresses, postal addresses, phone numbers); financial transaction records, invoices, bills and payments that relate to identifiable people; tax identifiers the Customer chooses to record, such as a vendor's identification number for 1099 preparation; receipt and document images the Customer uploads; and any other personal data the Customer chooses to place in its books. |
| Special category data | Not required by the Service and not requested by it. The Customer should not place special category data in its books. |
| Payroll and labour data | No payroll identifiers. The Service records payroll as summary totals only: gross wages, employee withholding, employer taxes and the pay date. Where the Customer tracks labour by person, the Service holds the name the Customer types, the hours, the rate, the amount and the job, as a cost record so the cost reaches the right project. It does not collect, store or transmit Social Security numbers or other tax identifiers for the people the Customer pays, dates of birth, home addresses or direct deposit details anywhere in the product, and it does not calculate withholding, produce a W-2 or a 1099, classify anyone as an employee or a contractor, file with any authority, or pay anyone. |
| Categories of data subjects | The Customer and its personnel and authorized users; people the Customer pays and records labour for; the Customer's own clients, customers, vendors and contacts; and payers who pay a Customer invoice online. |
| Frequency | Continuous for the duration of the subscription. |
Annex II — Technical and organizational measures
These are the measures actually in place as at the effective date of this DPA, stated specifically enough to be checked.
Encryption
- In transit: TLS on all connections between your device and the Service, and between the Service and its sub-processors.
- At rest, your books: each set of cloud books is compressed and then encrypted with AES-256-GCM, with a fresh random nonce per write and an authentication tag that detects tampering, before it is written to the database. What is stored is ciphertext, not a readable table of your transactions, and the same is therefore true of the database backups that contain it.
- Key handling: the encryption key is held only as a deployment secret, is never in source control and is never logged. The service refuses to start in a cloud environment without it, so it cannot silently resume writing plaintext, and a failed decryption is a hard error rather than a silent fallback. The stored format carries a key identifier so keys can be rotated.
- Third-party credentials: credentials you give us for a connected service are separately encrypted at the application layer with AES-256-GCM before being written, and writing one without the key fails rather than falling back to plaintext.
- Honest limit: this is encryption at rest with a key our service holds. It is not end-to-end encryption, and we do not claim to be zero-knowledge. A cloud product that generates your reports on its servers cannot also be zero-knowledge.
Access control and tenant separation
- Row-level security is enabled and forced on tenant tables in the production database, so one account's data is not reachable from another account's session. The production role configuration is pinned by an automated test, so breaking it fails the build rather than reaching production quietly.
- Passwords are stored only as secure hashes by our authentication provider, never in plain text; changing a password requires the current one.
- Receipt images are held in a private bucket namespaced per account and are served only through short-lived signed links.
- Production access is limited to the personnel who need it, on the confidentiality terms in section 6.
Application security
- An enforced Content-Security-Policy on the application, with a violation reporting endpoint.
- Per-IP rate limiting on authentication and other sensitive endpoints, resolved through the real client address rather than a spoofable forwarded header.
- A server-verified bot challenge on signup.
- Tenant-scoped authorization checks on API routes, covered by an automated test suite that runs on every change.
Resilience, backup and deletion
- Database backups run daily and are retained for seven days. Recovery point objective is approximately twenty-four hours.
- Receipt images are mirrored nightly to a second storage bucket, with a recovery point objective of approximately twenty-four hours for newly added images. Both buckets are within the same storage provider, so this protects against deletion and restore skew rather than against a provider-level loss. Your own export is the zero-loss layer and is available at any time.
- The retention and deletion clocks in section 11 are executed by an automated sweep that runs daily and writes an append-only record that it ran.
- A written disaster-recovery runbook covers the loss surfaces, the restore procedure and the known skew between the database and file storage after a restore.
Vulnerability and change management
- Automated dependency vulnerability alerts, plus a scheduled weekly dependency audit that fails on high-severity findings.
- Changes are reviewed and must pass an automated test suite before release.
Sub-processor and personnel management
- Data protection obligations imposed on each sub-processor under section 8.
- Access on a need-to-know basis under the confidentiality obligation in section 6.
What we do not claim
Listing a control we do not have would make the rest of this annex worthless, so here is the other side of it.
- No SOC 2 report, no ISO 27001 certification, no independent third-party security audit and no penetration test.
- No point-in-time database recovery. Recovery point objective is approximately twenty-four hours, not minutes.
- No cross-provider replication of receipt images.
- Not end-to-end encrypted, for the reason given above.
- No formal, independently assessed information security management system. Oikos United is a small company and this annex describes the measures of a small company that has chosen to be specific rather than impressive.
Annex III — Sub-processors
This list is kept in step with the sub-processor table in section 4 of the Privacy Policy. All process in the United States.
| Sub-processor | Function | Customer Personal Data involved |
|---|---|---|
| Supabase | Authentication, multi-tenant API, database storage of the encrypted books snapshot, private storage of receipt images | Account and authentication data, encrypted books data, receipt images |
| Render | Hosting of the Oikos Books cloud API | Data in transit and in processing for API requests |
| Cloudflare | Web and application hosting, CDN, DNS, network security and bot challenge | Technical and connection data |
| Stripe | Subscription billing, and Stripe Connect payments where the Customer enables them | Billing details and payment status; card data is held by Stripe and not by Oikos |
| Stripe Financial Connections | Optional bank feeds, only for accounts the Customer connects | Bank account identity basics and posted transaction history for the connected accounts |
| Resend | Transactional email: invoices, statements and reminders the Customer sends, and account emails | Recipient email address and the content of the message being sent |
| Anthropic | The Oikos AI features, each invoked by the Customer | Varies by feature; section 6 of the Privacy Policy sets out exactly what each feature sends. Anthropic does not use API inputs or outputs to train its models under its commercial terms. |
Not a sub-processor: Ramp. If the Customer connects its own Ramp account, Ramp is a source we read from on the Customer's instruction using credentials the Customer issues, not a provider to which we disclose Customer Personal Data. We send Ramp nothing beyond authenticating with those credentials.
Acceptance
This DPA is accepted by your agreement to the Terms of Service and does not require a signature. Where a countersigned copy is required, it is executed for Oikos United LLC by its authorized signatory on request under section 1.3, and the version and effective date above identify the instrument.