SSOMFA Business Cloud
PlatformPricingLive demoBookkeepingBlog
Sign inTry the demoStart free
Home/Legal

Data Processing Agreement

Effective 16 September 2026 · Somfa Financial Books Services, Calgary, Alberta, Canada

This DPA applies automatically whenever you use SOMFA Business Cloud to process personal information about other people — your customers, employees, suppliers or contacts. You are the controller (in US terms, the business); we are the processor (service provider). It forms part of our Terms of Service, and no signature is required, though we will sign a counterpart on request.

1. Subject matter, duration and purpose

  • Subject matter: our provision of the platform and support services described in the Terms.
  • Duration: for as long as your subscription is active, plus the retention windows in clause 9.
  • Purpose: processing solely to deliver, secure, support and bill for the service on your documented instructions — the platform’s own configuration and your use of it constitute those instructions.

2. Categories of data and data subjects

  • Data subjects: your customers, employees and contractors, suppliers, invited bookkeepers and advisors, and your own users.
  • Personal data: names, contact details, billing and shipping addresses, transaction and invoice records, receipts and uploaded documents, employment details, pay rates, hours worked, timesheets and leave, tax identifiers you enter, and technical identifiers such as IP address and device data.
  • We do not require special-category data. If you choose to upload it, you confirm you have a lawful basis for doing so and accept the additional risk.

3. Our obligations as processor

  • Process only on your instructions and for no independent purpose; never sell or share personal data, and never use it for our own advertising or to train third-party models.
  • Ensure personnel with access are bound by confidentiality and trained, on a least-privilege basis.
  • Implement the technical and organisational measures in clause 5 and keep them under review.
  • Assist you with data-subject requests, privacy impact assessments and regulator enquiries.
  • Tell you without undue delay if we believe an instruction breaches applicable data-protection law, or if we receive a law-enforcement demand for your data (unless legally prohibited).

4. Your obligations as controller

  • Have a lawful basis, and give required notices or collect required consents, before entering personal data.
  • Configure roles, permissions and invitations so only appropriate people can see personal data.
  • Keep your own records of processing, and respond to the requests of your data subjects — we will help.
  • Do not enter personal data you do not need, and use the platform’s export and deletion tools to keep it current.

5. Security measures

  • TLS in transit and encryption at rest for the database, backups and file storage.
  • Row-level security enforcing strict tenant isolation, plus role-based and per-person permissions.
  • Authentication controls: verified activation, expiring links, rate limiting, breached-password screening, optional TOTP multi-factor, session and device revocation.
  • Immutable audit logging of sensitive actions such as document cancellation, restoration, amendment, role changes and administrative access.
  • Segregated administrative access, monitored logs and error reporting, encrypted secret storage, and tested backup restoration.
  • Change management with typechecked builds, automated tests and security linting before release.

6. Sub-processors

You authorise us to engage sub-processors for the following functions, each under written terms no less protective than this DPA: cloud hosting and managed database infrastructure (North America), transactional email delivery, payment processing and subscription billing, customer relationship management and meeting booking, error and performance monitoring, AI model providers for assistant features, and — only where you connect it — the Amazon Selling Partner API. We will give at least 30 days’ notice before adding or replacing a sub-processor; if you reasonably object on data-protection grounds you may terminate the affected service and receive a pro-rata refund of prepaid fees. A current list is available on request.

7. International transfers

UK & EEA controllers

Transfers out of the UK/EEA rely on the European Commission’s Standard Contractual Clauses (Module Two, controller-to-processor) and the UK International Data Transfer Addendum, both incorporated into this DPA by reference, together with a transfer risk assessment and the measures in clause 5.

Canada, US, Africa, Australia

We rely on contractual protections plus, where required, local transfer mechanisms and notice — including PIPEDA and Quebec Law 25 transfer assessments, POPIA section 72 conditions, NDPA and Kenyan transfer requirements, and Australian APP 8 accountability.

8. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours of confirming a personal data breach affecting your data, with the nature of the incident, the categories and approximate volume of records, the likely consequences and the remedial steps taken. We will help you meet your own notification duties, including the GDPR’s 72-hour deadline and Canada’s real-risk-of-significant-harm test. We will not notify your data subjects on your behalf without your instruction, unless law requires us to.

9. Return, deletion and audits

Return and deletion

You may export data at any time. On termination we keep your workspace read-only for 30 days, then delete or de-identify personal data within 90 days, and purge backups within their normal 35-day cycle, except where law obliges us to retain records.

Audits

On reasonable written notice, and no more than once a year unless a regulator or an incident requires otherwise, we will provide our security documentation, answer a security questionnaire and — where necessary — support an audit under confidentiality, at your cost for third-party auditors.

10. Liability and precedence

Liability under this DPA is subject to the limits in the Terms of Service. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails; where the Standard Contractual Clauses conflict with either, the Clauses prevail.

Questions about this document? Email admin@somfabookkeeping.com or call (825) 785-8683. This page is information about our practices, not legal advice; please have your own counsel review it before you rely on it for your own compliance obligations.

All policies

  • Terms of Service
  • Privacy Policy
  • Cookie & Tracking Notice
  • Data Processing Agreement
  • Acceptable Use Policy
  • Subscription, Billing & Refunds
  • Security & Data Retention
  • Bookkeeping Engagement Terms
SOMFA

Accurate books today. Stronger business tomorrow.

Explore

  • Home
  • Platform
  • Pricing
  • Live demo
  • Bookkeeping
  • Blog

Product

  • Dashboard
  • Point of sale
  • Invoices
  • Expenses
  • Banking & reconciliation
  • Reports
  • Payroll
  • People & time

Pro Hub

  • Professional workspace
  • Find an accountant
  • My accountant
  • Team & roles
  • Settings
  • Sign in
  • Start free

Contact

  • (825) 785-8683
  • admin@somfabookkeeping.com
  • www.somfabookkeeping.com
  • Calgary, Alberta, Canada

Intuit QuickBooks Certified ProAdvisor — Elite tier.

Legal CentreTerms of ServicePrivacy PolicyCookiesData ProcessingAcceptable UseBilling & RefundsSecurity
© 2026 Somfa Financial Books Services. All rights reserved.