Oikos Books — Data Processing Addendum

Version 2.1 · Effective date: September 18, 2026 · Last updated: September 21, 2026 · Contact: [email protected]

What changed in 2.1 (September 21, 2026). Annex I now covers per-person labour cost records, because the Service is gaining the ability to track hours by person against a job. No new identifier is collected: still no Social Security numbers, no dates of birth, no home addresses and no bank details, and the Service still calculates no withholding, classifies nobody and files nothing. Section 13.2 has also been corrected to describe the US-only control accurately: a non-US subscription is cancelled automatically on completion rather than refused at checkout.

Plain-language summary (not a substitute for the full text).

If the books you keep in Oikos Books contain personal information about other people, your clients, your customers, your vendors, your employees, then you are responsible for that information and we handle it only on your instructions. This document is the contract that says so.

It applies automatically. You do not have to ask for it or sign anything. If your firm needs a countersigned copy for its own files, section 1.3 tells you how to get one.

Annex II lists our actual security measures, and it also lists what we deliberately do not claim. We would rather you knew both.

1. What this is, and when it applies

1.1 Purpose. This Data Processing Addendum (the "DPA") forms part of the Oikos Books Terms of Service (the "Terms") between Oikos United LLC ("Oikos," "we," "us") and the customer agreeing to them ("you," "Customer"). It governs our processing of personal data contained in Your Books on your behalf, and it is intended to satisfy Article 28 of the EU General Data Protection Regulation and the UK GDPR, and the service-provider requirements of the California Consumer Privacy Act as amended by the CPRA.

1.2 It applies automatically. This DPA applies to you, without further action by either party, whenever your use of the Service involves personal data relating to individuals other than yourself. That is the ordinary case for an accounting firm keeping books for clients, and for any business whose books contain customer, vendor or employee records. No request, signature or negotiation is required, and nothing in the Service is withheld until you have one.

1.3 If you need a signed copy. Some firms need a countersigned instrument for their own compliance files. Email [email protected] from your account address, naming the legal entity to be recorded as Customer, and we will return this DPA executed by Oikos United LLC for your countersignature. The terms are the terms published here; a signature changes nothing in them.

1.4 Where it does not apply. The free desktop application stores your books on your own computer and transmits nothing to us, so we process nothing on your behalf and this DPA has no subject matter. It begins to apply if you adopt a cloud or online feature.

2. Definitions

"Customer Personal Data" means personal data within Your Books or Your Data that Oikos processes on your behalf under the Terms. "Personal data," "processing," "controller," "processor," "data subject" and "sub-processor" have the meanings given in the GDPR; where the CCPA applies, "business," "service provider," "sell," "share" and "consumer" have the meanings given there. Terms defined in the Terms of Service carry those meanings here.

3. Roles of the parties

4. Scope and detail of the processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I, which is incorporated into this DPA.

5. Our obligations as processor

Oikos will:

6. Confidentiality

6.1 Oikos treats Customer Personal Data as confidential and uses it only to provide the Service.

6.2 Oikos will not authorize any person to access Customer Personal Data unless that person is bound by an obligation of confidentiality covering it. That obligation is undertaken by Oikos under this DPA and is binding on Oikos in respect of every person it authorizes, whether that person is a member, an officer, an employee or a contractor, and it survives the end of their involvement.

6.3 Access is granted on a need-to-know basis and is withdrawn when it is no longer needed.

7. Security

7.1 Oikos implements appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Those measures are set out in Annex II, which describes what is actually in place and is written to be checked rather than admired.

7.2 Security is not static. We may change a measure in Annex II provided the change does not materially reduce the overall level of protection, and we will update Annex II when we do.

7.3 No method of transmission or storage is completely secure. Annex II states the measures we maintain; it is not a warranty that any particular safeguard is effective against every attack.

8. Sub-processors

8.1 General authorization. You give Oikos general authorization to engage the sub-processors listed in Annex III, and to engage replacements and additions on the terms below.

8.2 Flow-down and responsibility. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully responsible to you for their performance.

8.3 Notice of change. We will notify cloud customers by email or in-app notice before a new or replacement sub-processor begins processing Customer Personal Data, and we will update Annex III and the sub-processor table in the Privacy Policy at the same time. This is the same commitment section 15 of the Privacy Policy already makes.

8.4 Objection. You may object to a new sub-processor on reasonable data protection grounds within thirty days of that notice, by emailing [email protected]. We will work with you in good faith to find an alternative. If no reasonable alternative exists and you maintain the objection, you may terminate the affected subscription and we will refund any prepaid fees covering the period after termination, notwithstanding the general no-refund rule in section 6 of the Terms.

9. Data subject requests

9.1 What you can do yourself. Because you control Your Books, most requests are yours to satisfy directly and immediately in the app: you can access, correct, export and delete records without involving us, and export is available at any time in formats you can open elsewhere.

9.2 Where you need us. Taking into account the nature of the processing, we will provide reasonable assistance with requests you cannot satisfy on your own, including requests for access, rectification, erasure, restriction, portability and objection. Contact [email protected] from your account address.

9.3 If a data subject contacts us. We will not respond to a request about Customer Personal Data on our own account. We will refer the person to you promptly, and tell you, unless the law requires us to respond.

10. Personal data breaches

10.1 Oikos will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

10.2 The notice will describe, so far as we know it at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases as it becomes available rather than delaying the first notice.

10.3 We will cooperate reasonably with your own notification obligations. Our notice is not an acknowledgement of fault or liability.

11. Deletion and return

11.1 On your instruction. Email [email protected] from your account address and we will delete your account and cloud data within thirty days. Deletion reaches the books and their version history, the account itself, and receipt images in both the primary and the backup storage bucket.

11.2 On termination without an instruction. Your books remain retrievable for ninety days so you can export them, are then closed to access, and are permanently purged at one year. Those clocks are enforced by an automated sweep that runs daily, not by an intention, and the sweep leaves an append-only record that it ran.

11.3 Export first. Export is available at any time and we recommend you use it before you go. After permanent deletion we cannot recover your records, and financial records usually have to be kept for several years for tax purposes.

11.4 What survives a deletion, stated plainly. Our own billing and tax records are exempt from deletion because law requires us to keep them, and those records contain the account email address. So a completed erasure removes your books, your receipts, your version history and your login, and leaves your email address inside our billing records for as long as tax, accounting and audit law requires, which may be up to seven years. We are a controller for those records, not your processor, and they are not used for anything but the legal purpose that requires them.

11.5 Backups. Database backups run daily and are kept for seven days, so data removed from live systems is gone from database backups within seven days. Receipt images are copied nightly to a second storage bucket, and a deletion under 11.1 reaches that bucket too.

11.6 Legal hold. Data subject to a legal hold is retained until the hold is lifted, which overrides every clock above.

12. Audits and information rights

12.1 We will make available the information reasonably necessary to demonstrate compliance with this DPA. In practice that means Annex II, the Security page, and a written answer to your security questionnaire. We answer questionnaires from real customers as a matter of course.

12.2 Where the information under 12.1 is not sufficient for your legal obligations, you or an independent auditor you mandate may audit our processing no more than once in any twelve-month period, and additionally where a supervisory authority requires it. An audit must be on at least thirty days' written notice, during business hours, under confidentiality obligations, at your cost, and conducted so that it does not compromise the security, confidentiality or availability of any other customer's data.

12.3 What we do not have, said before you ask. Oikos holds no SOC 2 report and no ISO 27001 certification, and has not undergone an independent third-party security audit or penetration test. If your procurement process requires one of those, we would rather you learned it here than three weeks into a diligence cycle.

13. International transfers

13.1 Oikos United LLC is based in the United States, the Service is operated from the United States, and every sub-processor in Annex III processes Customer Personal Data in the United States.

13.2 The Service is offered to customers in the United States only. Checkout collects a billing address, and a subscription with a non-US billing country is cancelled automatically and immediately on completion, so it never becomes an active subscription. A card issued outside the United States is also blocked at the payment step. We therefore do not currently rely on the EU Standard Contractual Clauses or the UK International Data Transfer Addendum, because we do not offer the Service to customers established in the EEA, Switzerland or the UK. If you attempted to subscribe from outside the United States, the billing details you entered are held by our payment processor as a cancelled transaction record, and you may ask us to delete what we hold under section 11.

13.3 If we begin offering the Service to customers subject to EEA, Swiss or UK transfer rules, we will put an appropriate transfer mechanism in place, including the applicable Standard Contractual Clauses and UK Addendum, before doing so, and this section will be replaced accordingly. This matches the commitment in section 13 of the Privacy Policy.

13.4 If you are a US customer whose own books happen to contain personal data about people located in the EEA or the UK, this DPA governs our processing of it on your behalf; your own transfer analysis as controller remains yours.

14. California (CCPA/CPRA)

14.1 With respect to Customer Personal Data, Oikos is a service provider and you are the business. Oikos is provided personal data for the limited and specified purpose of performing the Service.

14.2 Oikos certifies that it understands the restrictions in this section and will comply with them. Oikos does not sell or share Customer Personal Data as those terms are defined by the CCPA, does not retain, use or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA, does not retain, use or disclose it outside the direct business relationship between the parties, and does not combine it with personal data received from another source except as the CCPA permits.

14.3 Oikos will notify you if it determines it can no longer meet its obligations under the CCPA, and you may take reasonable and appropriate steps to stop and remediate unauthorized use.

15. Liability

Each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations in section 12 of the Terms, including the data-incident sub-cap in section 12(c) and the carve-outs in section 12(d). This DPA does not increase or decrease those limits.

16. Term, precedence and changes

16.1 Term. This DPA takes effect when the Terms do, and continues for as long as Oikos processes Customer Personal Data. Sections that by their nature should survive, including sections 6, 10, 11 and 15, survive termination.

16.2 Precedence. This DPA supplements the Terms. On any question of data protection, this DPA controls over the Terms and over the Privacy Policy. On every other question the Terms control.

16.3 Changes. We may update this DPA. For a material change we will give notice by email or in-app notice and update the version and the Last updated date above. A change that reduces the protections in this DPA, or that adds a sub-processor, will not take effect before the notice.

16.4 Governing law. Section 17 of the Terms governs this DPA. Where the GDPR applies, nothing in this section displaces a data subject's rights or a supervisory authority's jurisdiction.


Annex I — Details of the processing

ItemDetail
ControllerThe Customer.
ProcessorOikos United LLC, Commonwealth of Virginia, USA.
Subject matterProvision of the Oikos Books cloud accounting Service.
DurationThe term of the Terms of Service, plus the retention periods in section 11.
Nature and purposeHosting, storing, syncing, sharing and reporting financial and business records; invoicing and statements; optional bank and card transaction import; optional online payment collection; optional AI assistance, each invoked by the Customer.
Types of personal dataAccount identifiers (name, email address, organization name); contact records the Customer enters (customers, vendors, contacts, including names, email addresses, postal addresses, phone numbers); financial transaction records, invoices, bills and payments that relate to identifiable people; tax identifiers the Customer chooses to record, such as a vendor's identification number for 1099 preparation; receipt and document images the Customer uploads; and any other personal data the Customer chooses to place in its books.
Special category dataNot required by the Service and not requested by it. The Customer should not place special category data in its books.
Payroll and labour dataNo payroll identifiers. The Service records payroll as summary totals only: gross wages, employee withholding, employer taxes and the pay date. Where the Customer tracks labour by person, the Service holds the name the Customer types, the hours, the rate, the amount and the job, as a cost record so the cost reaches the right project. It does not collect, store or transmit Social Security numbers or other tax identifiers for the people the Customer pays, dates of birth, home addresses or direct deposit details anywhere in the product, and it does not calculate withholding, produce a W-2 or a 1099, classify anyone as an employee or a contractor, file with any authority, or pay anyone.
Categories of data subjectsThe Customer and its personnel and authorized users; people the Customer pays and records labour for; the Customer's own clients, customers, vendors and contacts; and payers who pay a Customer invoice online.
FrequencyContinuous for the duration of the subscription.

Annex II — Technical and organizational measures

These are the measures actually in place as at the effective date of this DPA, stated specifically enough to be checked.

Encryption

Access control and tenant separation

Application security

Resilience, backup and deletion

Vulnerability and change management

Sub-processor and personnel management

What we do not claim

Listing a control we do not have would make the rest of this annex worthless, so here is the other side of it.

Annex III — Sub-processors

This list is kept in step with the sub-processor table in section 4 of the Privacy Policy. All process in the United States.

Sub-processorFunctionCustomer Personal Data involved
SupabaseAuthentication, multi-tenant API, database storage of the encrypted books snapshot, private storage of receipt imagesAccount and authentication data, encrypted books data, receipt images
RenderHosting of the Oikos Books cloud APIData in transit and in processing for API requests
CloudflareWeb and application hosting, CDN, DNS, network security and bot challengeTechnical and connection data
StripeSubscription billing, and Stripe Connect payments where the Customer enables themBilling details and payment status; card data is held by Stripe and not by Oikos
Stripe Financial ConnectionsOptional bank feeds, only for accounts the Customer connectsBank account identity basics and posted transaction history for the connected accounts
ResendTransactional email: invoices, statements and reminders the Customer sends, and account emailsRecipient email address and the content of the message being sent
AnthropicThe Oikos AI features, each invoked by the CustomerVaries by feature; section 6 of the Privacy Policy sets out exactly what each feature sends. Anthropic does not use API inputs or outputs to train its models under its commercial terms.

Not a sub-processor: Ramp. If the Customer connects its own Ramp account, Ramp is a source we read from on the Customer's instruction using credentials the Customer issues, not a provider to which we disclose Customer Personal Data. We send Ramp nothing beyond authenticating with those credentials.

Acceptance

This DPA is accepted by your agreement to the Terms of Service and does not require a signature. Where a countersigned copy is required, it is executed for Oikos United LLC by its authorized signatory on request under section 1.3, and the version and effective date above identify the instrument.