Last updated: August 2026
This Data Processing Agreement ('DPA') forms part of the agreement between your organization ('Customer') and AcuEntry ('Processor') for use of the AcuEntry service, and describes how AcuEntry processes personal data on Customer's behalf. Where this DPA conflicts with the Terms of Service on data processing matters specifically, this DPA controls.
"Personal Data" means any information relating to an identified or identifiable natural person that Customer submits to or that AcuEntry processes through the service on Customer's behalf — for example, names or contact details appearing on vendor invoices or within connected email accounts.
"Processing", "Controller", and "Processor" have the meanings given under applicable data protection law. Customer is the Controller of Personal Data processed through AcuEntry; AcuEntry is the Processor.
AcuEntry processes Personal Data solely to provide the service described in the Terms of Service: identifying and extracting invoice data from Customer's connected email accounts, matching that data against Customer's Acumatica instance, and posting approved bills to Acumatica. AcuEntry processes Personal Data only on Customer's documented instructions, as reflected in Customer's configuration and use of the service, unless otherwise required by law.
AcuEntry ensures that personnel authorized to process Personal Data are subject to confidentiality obligations, whether contractual or statutory.
AcuEntry implements technical and organizational measures appropriate to the risk, including:
Customer authorizes AcuEntry to engage the following categories of sub-processors to provide the service: cloud infrastructure and hosting providers, database providers, and providers used to perform AI-based invoice data extraction, each engaged under terms that impose data protection obligations consistent with this DPA. AcuEntry will provide notice of any new category of sub-processor and give Customer a reasonable opportunity to object.
AcuEntry will provide reasonable assistance to help Customer respond to requests from individuals to exercise their rights under applicable data protection law, to the extent Customer cannot reasonably fulfill such requests itself using the tools available in the service.
AcuEntry will notify Customer without undue delay after becoming aware of a breach affecting Customer's Personal Data, and will provide reasonably available information to help Customer meet its own notification obligations.
On termination of the service, AcuEntry will make Customer's data available for export for a reasonable period, and will delete or anonymize remaining Personal Data within a reasonable period thereafter, except where retention is required by law.
Personal Data is processed in the United States. Where Customer's Personal Data originates outside the United States, AcuEntry will process it in a manner consistent with applicable cross-border transfer requirements.
AcuEntry will make available to Customer, on reasonable request, information reasonably necessary to demonstrate compliance with this DPA.
This DPA remains in effect for as long as AcuEntry processes Personal Data on Customer's behalf under the Terms of Service.
Questions about this DPA can be sent to legal@acu-entry.com.