Data Processing Agreement (DPA)
Last updated: September 8, 2026
This Data Processing Agreement (“Agreement”) forms part of the Terms of Service between the customer (“Controller”) and Tally Crow (“Processor”).
It outlines the terms under which Tally Crow processes personal data on behalf of the Controller in accordance with applicable data protection laws, including Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”).
Subject Matter and Duration
This Agreement governs the processing of personal data by Tally Crow on behalf of the Controller in the context of providing the bookkeeping and invoicing platform.
This Agreement remains in effect for the duration of the Controller’s use of the Service and until deletion of all personal data as specified herein.
Nature and Purpose of Processing
Tally Crow processes personal data solely for the purpose of providing access to and use of the Service, including:
- Storing and organising client-generated data (e.g. invoices, credit notes, business records)
- Providing authentication and user management functionality
- Facilitating customer support and usage analytics
No processing shall occur for unrelated or unauthorised purposes.
Categories of Data Subjects
The personal data processed may relate to:
- The Controller’s own personnel (e.g. users who sign up for the Service)
- The Controller’s customers, vendors, or clients (whose information may appear on invoices or in records)
Categories of Personal Data
Personal data may include:
- Name, email address, and contact details
- Business or client information (e.g. company name, VAT number)
- Invoice and credit note data (e.g. billing details, amounts, due dates)
- IP address and user activity logs (for audit and security purposes)
Tally Crow does not knowingly process sensitive personal data as defined in Article 9 of the GDPR.
Controller Obligations
The Controller confirms that:
- It has the legal right to process the personal data and to engage Tally Crow as a Processor
- It shall comply with all applicable data protection laws and inform data subjects as required
- It shall use the Service in accordance with its own policies and applicable regulations
Processor Obligations
Tally Crow agrees to:
- Process data only on documented instructions from the Controller
- Ensure personnel authorised to process personal data are subject to confidentiality obligations
- Implement appropriate technical and organisational measures to ensure data security (e.g. access control, encryption, audit logs)
- Assist the Controller in responding to requests from data subjects under GDPR
- Notify the Controller without undue delay in the event of a data breach
- Provide reasonable support for audits or inspections related to data protection compliance
- Delete or return personal data upon termination of the Service
Sub‑Processors
Tally Crow uses the following sub‑processors:
- Supabase: database, authentication and file storage for the application (EU-hosted)
- Stripe: billing for Tally Crow subscriptions and, where the Controller enables it, processing of invoice “Pay now” payments via Stripe Connect
- MailerSend: sending transactional email on the Controller’s behalf (invoices, credit notes, reminders and account notifications)
- Cloudflare: bot and abuse protection (Cloudflare Turnstile) on sign-in, sign-up, password reset and the newsletter form, subject to Cloudflare’s Turnstile Privacy Addendum
- Google Cloud (OAuth): optional Google sign-in
- Namecheap / EasyWP: hosting infrastructure for the application and website
All sub-processors are bound by agreements that offer an equivalent level of protection as this Agreement. The Controller will be notified of any material changes to sub-processor arrangements.
Data Transfers
All data is stored within the European Union. If international transfers are required in future, Tally Crow will ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
Data Retention and Deletion
Upon termination of the Service or upon request, Tally Crow will delete or return all personal data to the Controller, unless retention is required by law.
Backups are retained securely for limited periods in accordance with our data retention policies and are subject to the same protections.
Liability
Each party shall be responsible for its own compliance with applicable data protection laws. Tally Crow’s liability under this Agreement shall be limited in accordance with the limitation of liability set out in the Terms of Service.
Governing Law and Jurisdiction
This Agreement is governed by the laws of Malta. Any disputes shall be resolved by the competent courts of Malta.
Contact
Questions related to this DPA may be directed to: info@tallycrow.com