Data Processing Addendum
Version 2.0 | Last updated: 12 July 2026 | Applies to B2B customers using Accwisely on behalf of their own clients
This Data Processing Addendum (the "DPA") forms part of the Terms of Service between you ("Customer") and Accwisely.com ("Accwisely") where Customer uses the Service to process personal data on behalf of Customer's own clients (the "End Clients").
This DPA applies where Customer is acting as a data controller in respect of personal data of End Clients, and Accwisely is acting as a data processor (referred to as a "data intermediary" under the PDPA) on Customer's behalf. Where Customer is a single-entity organisation using the Service to process its own records, references to "End Clients" are read as references to Customer's own business, and Customer remains the organisation responsible for the personal data it submits. Where this DPA conflicts with the Terms of Service, this DPA prevails in respect of the processing of personal data.
This version 2.0 replaces version 1.0. Acceptance of this DPA within the Service supersedes any earlier acceptance; the Service may require re-acceptance when a new version is published.
1. Definitions
- "Personal Data" has the meaning given to "personal data" in the Personal Data Protection Act 2012 of Singapore (the "PDPA").
- "Customer Personal Data" means personal data uploaded to or processed through the Service by Customer (or at Customer's direction, including through a Messaging Channel) on behalf of End Clients.
- "Module" means a functional component of the Service listed in a Schedule to this DPA. The Schedules describe the subject matter, nature, and purpose of processing for each Module. Only the Schedules corresponding to Modules that Customer activates or uses apply to Customer.
- "Source Documents" means accounting source documents submitted for processing under Schedule 2, including invoices, receipts, bank statements, payroll records, and similar documents, together with their contents.
- "End Customer" means a customer or debtor of an End Client to whom an invoice or related communication is addressed under Schedule 4.
- "Messaging Channel" means a third-party messaging service (currently Telegram) through which Customer or an End Client interacts with the Service, as described in Schedule 3.
- "AI Sub-processor" means a Sub-processor providing machine-learning model services used for the automated extraction, classification, transcription, or drafting functions described in clause 6.
- "Sub-processor" means any third party engaged by Accwisely to process Customer Personal Data.
- "Data Breach" means a breach of security leading to the unauthorised or accidental destruction, loss, alteration, disclosure of, or access to Customer Personal Data.
2. Roles and instructions
Customer is the data controller of Customer Personal Data and is responsible for the lawful basis on which it collects and discloses such data to Accwisely, including any consent or notification required from End Clients and their data subjects. Accwisely processes Customer Personal Data only as a data intermediary, on Customer's documented instructions, which are deemed to consist of (a) the Terms of Service, (b) this DPA including its Schedules, and (c) Customer's actual use of the Service, including instructions given through a Messaging Channel by a user whose account has been verified and bound to Customer's organisation.
Accwisely will inform Customer if, in its opinion, an instruction infringes the PDPA or other applicable law, but is not obliged to perform legal review of Customer's instructions.
3. Modules, subject matter and scope
The Service comprises the Modules described in the Schedules to this DPA:
- Schedule 1 — Financial statements generation;
- Schedule 2 — Document capture and data extraction;
- Schedule 3 — Continuous bookkeeping and messaging-channel intake;
- Schedule 4 — Invoicing and invoice delivery.
For all Modules:
- Subject matter of processing: provision of the Service to Customer.
- Duration: for the term of Customer's account with Accwisely, plus any retention period set out in the Privacy Policy, this DPA, or required by law (see clause 12).
- Nature, purpose, categories of personal data, and categories of data subjects: as set out in the applicable Schedule.
Only the Schedules for Modules Customer activates or uses apply. Each Schedule applies from the date the relevant Module is made available to and activated by Customer; a special term that describes a Module capability applies from the date that Module (including that capability) is made available. Activating a Module after accepting this DPA does not require a new acceptance unless the Service so requires (for example, on publication of a new DPA version).
4. Confidentiality
Accwisely ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and have received appropriate training.
5. Security
Accwisely maintains reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data against unauthorised or unlawful processing, accidental loss, destruction, damage, or alteration, consistent with the Protection Obligation in section 24 of the PDPA. These safeguards include access controls with tenant isolation enforced at the database layer, encryption in transit, encryption at rest by our hosting provider, password hashing, and operational logging. Additional safeguards specific to sensitive categories of data are described in Schedule 2.
6. Automated processing and AI Sub-processors
Certain Modules use machine-learning models operated by AI Sub-processors to perform automated extraction, classification, transcription, or drafting, as described in the applicable Schedule and in the AI Use & Output Notice at accwisely.com/ai-use. In respect of such processing:
- Accwisely does not permit AI Sub-processors to use Customer Personal Data to train their generalised (foundation) models, and engages AI Sub-processors on terms consistent with this commitment.
- Where the Service computes totals, subtotals, tax, or other derived amounts, it does so in Accwisely's own deterministic code. Machine-learning models are used to read and extract values appearing in Source Documents and instructions (including monetary values), to classify, and to draft — never to perform the Service's arithmetic — and extracted values are presented for Customer's review under this clause before use.
- All AI-assisted output is produced as a draft for review. No filing, ledger posting, or delivery to a third party occurs without a human confirmation step by Customer or its authorised user.
- Accwisely remains responsible for AI Sub-processors as Sub-processors under clause 7.
7. Sub-processors
Customer authorises Accwisely to engage Sub-processors for the provision of the Service. The current list of Sub-processors — including the hosting, database, content-delivery, error-monitoring, product-analytics, transactional-email, and AI-model providers — is published at accwisely.com/security and is also available on request.
Accwisely will give Customer reasonable advance notice (where reasonably practicable, at least thirty (30) days) before engaging a new Sub-processor and will give Customer the opportunity to object on reasonable grounds. If Customer reasonably objects, the parties will work in good faith to find a solution; if no solution is found, Customer's sole remedy is to terminate the affected portion of the Service.
Accwisely remains liable for the acts and omissions of its Sub-processors as if they were its own.
For the avoidance of doubt, a Messaging Channel operated by a third party (currently Telegram) that Customer or an End Client chooses to use to communicate with the Service is a communication channel selected by Customer, not a Sub-processor engaged by Accwisely; clause 10 and Schedule 3 describe its treatment.
8. Data subject rights
Accwisely will, taking into account the nature of the processing, provide reasonable assistance to Customer to enable Customer to respond to access, correction, and other requests from data subjects of End Clients under the access and correction provisions of the PDPA. Accwisely will not respond directly to such requests unless legally required, but will redirect requests received directly to Customer where the requester can be identified as relating to a Customer account.
If Accwisely receives a legally binding demand from a public authority for disclosure of Customer Personal Data, Accwisely will, unless legally prohibited from doing so, notify Customer before disclosure and disclose only what is required to comply.
9. Data Breach notification
Accwisely will notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware, of any Data Breach affecting Customer Personal Data, consistent with its duty as a data intermediary under section 26C(3) of the PDPA. The notification will include, to the extent reasonably available, the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach. Accwisely will provide reasonable assistance to Customer in Customer's assessment of whether the breach is a notifiable data breach under section 26B of the PDPA and in any notification Customer is required to make to the Personal Data Protection Commission or to affected individuals.
10. Cross-border transfer
Customer Personal Data may be transferred to and processed in jurisdictions outside Singapore where Accwisely's Sub-processors are located. Accwisely takes reasonable steps to ensure that any such transfer is subject to enforceable obligations to provide a standard of protection comparable to the PDPA, in accordance with section 26 of the PDPA and the Personal Data Protection Regulations 2021.
Where Customer or an End Client communicates with the Service through a Messaging Channel, the transmission of that communication across the Messaging Channel's own infrastructure (which may be located outside Singapore) is governed by the Messaging Channel operator's terms and privacy policy and is initiated by Customer's or the End Client's choice of channel. Accwisely's obligations under this clause apply from the point the communication is received by the Service.
11. Audit
Customer may, on reasonable prior notice and not more than once in any twelve-month period, request a summary of Accwisely's security and data protection controls for the purpose of verifying compliance with this DPA. Accwisely will respond with reasonable information including, where applicable, summaries of any independent third-party audit reports.
12. Retention, return and deletion
On termination of Customer's account, Accwisely will delete or return all Customer Personal Data within a reasonable period, save where retention is required by law. De-identified or aggregated data derived from Customer Personal Data may be retained.
In respect of accounting records processed under Schedule 3 (continuous bookkeeping):
- Customer acknowledges that End Clients are required by law — including section 199 of the Companies Act 1967 and, where applicable, section 46 of the Goods and Services Tax Act 1993 — to retain accounting records for at least five (5) years. The Service is designed to support this: ledger records are retained for the retention period stated in Schedule 3 unless Customer instructs deletion following a complete export.
- If Customer's subscription to the bookkeeping Module lapses, ledger records are placed in a read-only state in which Customer may view and export them; they are not deleted by reason of the lapse alone.
- Customer may at any time export the ledger records of an End Client in a complete, machine-readable form ("export-everything"). Deletion at Customer's instruction is performed after Customer confirms it has completed any export it requires; responsibility for the End Client's statutory retention rests with Customer and the End Client.
- On termination of Customer's account, ledger records remain read-only and exportable for ninety (90) days from the effective date of termination, after which they are deleted unless Customer has elected in writing a continued read-only retention arrangement. Accwisely will confirm deletion in writing on Customer's request.
Source Documents processed under Schedule 2 are retained for the period stated in Schedule 2 and are deleted on expiry of that period or on Customer's earlier instruction.
13. Liability
Liability under this DPA is governed by the limitation-of-liability clause in the Terms of Service, including the separate, higher cap that applies to liability arising from breach of data protection or confidentiality obligations.
14. Versions and precedence
Accwisely may publish revised versions of this DPA from time to time. A revised version applies to Customer on Customer's acceptance within the Service; the Service may condition continued use of the affected Modules on acceptance of the current version. The version accepted by Customer is recorded against Customer's organisation. In the event of conflict, the order of precedence is: (1) the Schedules of this DPA; (2) the body of this DPA; (3) the Terms of Service.
Schedule 1 — Financial statements generation
- Nature and purpose: processing of trial balance data and related information to generate draft financial statements in Singapore format.
- Categories of personal data: identifying information of End Clients' directors, officers, and employees as appearing in the trial balance and supporting input.
- Categories of data subjects: End Clients' directors, officers, employees, and where applicable shareholders.
- Special terms: none beyond the body of this DPA.
Schedule 2 — Document capture and data extraction
- Nature and purpose: receipt, storage, automated extraction, classification, splitting, coding, and export of Source Documents and their contents, to support bookkeeping and financial statements preparation, including AI-assisted extraction under clause 6 with review and confirmation by Customer.
- Categories of personal data: names and contact details of End Clients' suppliers, customers, and counterparties appearing on Source Documents; identifying and financial information of End Clients' employees appearing on payroll records — which may include NRIC or FIN numbers, salary and remuneration details, CPF contribution details, and bank account numbers; account numbers and transaction descriptions appearing on bank statements.
- Categories of data subjects: End Clients' employees, directors, and officers; individual suppliers, customers, and counterparties of End Clients; other individuals named in Source Documents.
Special terms for this Module:
- Sensitive-document gate. The Service will not process documents under a document type designated as carrying sensitive personal data (including the payroll and bank statement document types) for a Customer organisation until that organisation has accepted the then-current version of this DPA within the Service. Where a document's type is determined by automatic classification after submission, the same acceptance requirement applies before extraction of sensitive-type data proceeds. This ordering is enforced in the Service itself.
- NRIC/FIN handling. NRIC and FIN numbers are processed only where they appear on Source Documents submitted by Customer and only for the purposes of this Schedule, consistent with the PDPC's Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers. They are not used as account identifiers, are excluded from durable pattern-learning as set out below, and are redacted from audit-log detail.
- No durable learning of sensitive values. The Service's per-vendor learning features (which remember document layouts and coding patterns to improve future extraction) do not store the values of fields designated or detected as sensitive (for example NRIC/FIN, salary, or bank account numbers). Audit records are figure-free and redact sensitive field identifiers.
- Human review. Extracted values are presented to Customer for review; export and downstream use follow Customer's confirmation, per clause 6.
- Retention. Source Document files and the values extracted from them are retained for seven (7) days from upload (or, where a document is split into constituent documents during review, seven (7) days from the split), after which they are automatically purged; Customer may delete a document at any time before then. Data that Customer has confirmed and exported — into the ledger, an export file, or the financial statements workflow — before the purge follows the retention applicable to that destination (for the ledger, Schedule 3).
Schedule 3 — Continuous bookkeeping and messaging-channel intake
- Nature and purpose: maintenance of accounting ledgers for End Clients, including recording of journal entries proposed by the Service or by Customer and posted following Customer confirmation; reconciliation; generation of reports and returns support; and receipt of documents, instructions, and queries through the web application or a Messaging Channel.
- Categories of personal data: as for Schedules 1 and 2, to the extent such data enters the ledger or is transmitted through a Messaging Channel; account identifiers of the messaging user (for example Telegram username and numeric user identifier) used to verify and bind that user to Customer's organisation; message content submitted to the Service.
- Categories of data subjects: authorised users of Customer; End Clients' personnel interacting with the Service through a Messaging Channel; the data subjects referred to in Schedules 1 and 2.
Special terms for this Module:
- Messaging Channel. The Messaging Channel is operated by its provider under that provider's own terms and privacy policy. Customer is responsible for its choice (and, where applicable, its End Clients' choice) to communicate with the Service through the Messaging Channel. Documents received through the Messaging Channel are processed under Schedule 2; instructions received through it are processed under this Schedule and clause 2.
- User binding. A messaging account must be verified and bound to Customer's organisation before the Service acts on its instructions. Approval of postings and other confirmations are attributed to the bound, identifiable user.
- Retention. Ledger records are retained for a minimum of five (5) years from the end of the financial year to which they relate, consistent with clause 12, unless Customer instructs deletion following a complete export. On subscription lapse, ledger records become read-only and exportable per clause 12.
Schedule 4 — Invoicing and invoice delivery
- Nature and purpose: creation of draft sales invoices for End Clients from Customer's instructions (including instructions given through a Messaging Channel, with AI-assisted drafting under clause 6); rendering of approved invoices; and, at Customer's per-invoice election, delivery of the approved invoice by (a) return within the Messaging Channel chat, (b) email to Customer's user, or (c) email to the End Customer.
- Categories of personal data: names, email addresses, and business contact details of End Customers and their personnel; names of End Clients' personnel appearing on invoices; invoice line descriptions to the extent they identify individuals.
- Categories of data subjects: End Customers who are individuals, and personnel of End Customers; End Clients' personnel.
Special terms for this Module:
- Delivery on instruction. Delivery of an invoice to an End Customer occurs only on Customer's approval of that invoice and selection of that delivery method. Customer is responsible for the accuracy of End Customer contact details and for its lawful basis to disclose them to Accwisely for delivery. Some End Customer contact details may constitute business contact information as defined in section 2(1) of the PDPA (to which certain Parts of the PDPA do not apply, per section 4(5)); Accwisely nonetheless applies the safeguards of this DPA to them.
- Payment QR codes. Where Customer enables PayNow QR on invoices, the QR code is generated from the End Client's Unique Entity Number and invoice reference supplied by Customer. Accwisely does not collect, process, or store bank account credentials for this feature, does not initiate or receive payments, and is not a party to any payment. Payment settlement occurs directly between the End Customer and the End Client through their banks.
- Email delivery. Emails to End Customers are sent through Accwisely's transactional-email Sub-processor identified at accwisely.com/security, on Customer's behalf.
- Drafts only. AI-assisted drafting under this Schedule produces drafts only; no invoice is issued, numbered as final, posted to a ledger, or delivered without Customer's approval, per clause 6.