Rooby
  • For Accountants
  • For Businesses
  • Product
  • Pricing
Log In Start Free Trial

Data Processing Agreement

Last updated: May 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the accountancy firm or individual practitioner accessing Rooby (“the Controller”) and Rooby of 51–59 Rose Lane, Norwich, NR1 1BY (“the Processor” or “Rooby”).

By using Rooby, the Controller agrees to the terms of this DPA. If you require a countersigned copy, email hello@rooby.co.uk.

1. Definitions

In this DPA:

  • “Personal Data” has the meaning given in UK GDPR Article 4.
  • “Processing” has the meaning given in UK GDPR Article 4.
  • “Data Subject” means the individual to whom Personal Data relates.
  • “Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • “UK GDPR” means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, as amended.
  • “Services” means the Rooby tax forecasting and financial health monitoring platform.

2. Roles of the parties

The Controller determines the purposes and means of processing the Personal Data of its clients and their associated individuals. The Processor processes that Personal Data solely on the Controller’s behalf and in accordance with the Controller’s documented instructions, as set out in this DPA and the Rooby Terms of Service.

3. Subject matter, duration, and nature of processing

Subject matter: The Processor accesses financial data from the Controller’s clients’ Xero organisations, via read-only OAuth 2.0 authorisation granted by the Controller, to provide live corporation tax forecasting, VAT forecasting, client tax provision portal, and extraction scenario modelling.

Duration: Processing continues for the duration of the Controller’s active subscription and for up to 30 days following account closure, after which Personal Data is deleted in accordance with clause 9.

Nature: Collection, storage, analysis, display, and deletion. The Processor does not write to, modify, or delete any data within Xero.

4. Types of personal data processed

The Processor may process the following categories of Personal Data on behalf of the Controller:

  • Director and officer information, names, roles, and ownership percentages of directors and shareholders, sourced from Xero and the Companies House public register
  • Financial transaction data, profit and loss figures, revenue, expenses, bank transaction records, VAT positions, aged debtor and creditor information (including customer and supplier names and amounts), and balance sheet data drawn from connected Xero organisations
  • Company registration data, registered company name, company number, SIC codes, registered address, and incorporation date sourced from the Companies House public register
  • Tax liability data, estimated corporation tax and VAT liabilities, calculation inputs and adjustments, and forecast snapshots generated by the Processor
  • Client portal user data, email addresses and account credentials of any individuals granted read-only portal access by the Controller
  • Notes and documents, any notes, correspondence, or document uploads added by the Controller’s team in relation to their clients

5. Categories of data subjects

The Personal Data relates to the following categories of Data Subject:

  • Directors, shareholders, and authorised persons of the Controller’s clients
  • Customers and suppliers of the Controller’s clients (as their names appear in financial data)
  • Individuals granted access to the Rooby client portal by the Controller

6. Processor obligations

6.1 Documented instructions

The Processor shall process Personal Data only on documented instructions from the Controller. The Controller’s instructions are: (a) to process Personal Data as necessary to provide the Services; and (b) to comply with applicable law. If the Processor is required by law to process Personal Data otherwise, it will notify the Controller before doing so, unless prohibited by law.

6.2 Confidentiality

The Processor shall ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.

6.3 Security

The Processor shall implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing, accidental loss, destruction, or damage. The measures currently in place are set out in Schedule 2.

6.4 Sub-processors

The Controller provides general authorisation for the Processor to engage sub-processors. The Processor’s current sub-processors are listed in Schedule 1. The Processor will notify the Controller of any intended changes to sub-processors by updating Schedule 1, giving the Controller reasonable opportunity to object. The Processor shall impose data protection obligations on sub-processors equivalent to those in this DPA.

6.5 Data subject rights

The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures to fulfil the Controller’s obligations to respond to Data Subject rights requests under UK GDPR (including access, rectification, erasure, restriction, portability, and objection).

6.6 Assistance with compliance

The Processor shall assist the Controller in ensuring compliance with its obligations under UK GDPR Articles 32–36, including in relation to security, breach notification, data protection impact assessments, and prior consultation with the ICO, taking into account the nature of processing and the information available to the Processor.

6.7 Personal data breach notification

The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting Personal Data processed under this DPA. The notification will include, to the extent available: a description of the nature of the breach; the categories and approximate number of data subjects and records affected; likely consequences; and measures taken or proposed to address the breach.

6.8 Deletion on termination

On termination of the Services, the Processor shall delete all Personal Data processed under this DPA within 30 days, unless the Processor is required by law to retain any such data. Certain non-personal audit records (e.g. account deletion confirmations and marketing suppression logs) are retained indefinitely for legal compliance purposes. The Controller may request confirmation of deletion at hello@rooby.co.uk.

6.9 Audit

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, provided such audits are conducted on reasonable notice and at the Controller’s cost.

7. Controller obligations

The Controller warrants and represents that:

  • It has the legal authority to grant the Processor access to its clients’ Xero data and to process the Personal Data described in this DPA
  • It has provided all required notices to, and obtained all required consents from, Data Subjects as necessary to permit the processing described in this DPA
  • Its instructions to the Processor will not cause the Processor to breach applicable data protection law

8. International transfers

All Personal Data is stored and processed within the UK or in jurisdictions covered by UK GDPR adequacy decisions. Specifically: financial data is stored in Supabase (London, UK); application functions run on Vercel (London, UK); email notifications are delivered via Brevo (France, EU, covered by UK GDPR adequacy); payment processing is handled by Stripe UK Ltd. No Personal Data is transferred to countries outside the UK or EU in the course of providing the Services.

9. Data retention and deletion

The Processor retains Personal Data for the duration of the Controller’s active subscription. Upon account closure or cancellation, Personal Data is deleted within 30 days. Audit trail records (which do not contain client financial data) are retained indefinitely for legal compliance. The Controller may request earlier deletion at any time by contacting hello@rooby.co.uk.

10. Governing law

This DPA is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

Schedule 1: Sub-processors

The following sub-processors are engaged by Rooby to process Personal Data on behalf of the Controller:

Sub-processor Purpose Location
Supabase Database, authentication, and file storage London, UK
Vercel Application hosting and serverless processing London, UK
Brevo Transactional email (account notifications and alerts) France, EU (UK GDPR adequacy)
Stripe UK Ltd Payment processing (billing data only, no client financial data) UK
Xero Source of client financial data via OAuth read access Processed under Xero’s own data processing terms
Companies House UK public company register (director and company data lookup) UK

This list is maintained and updated whenever a sub-processor is added or changed. Email hello@rooby.co.uk to request the current version at any time.

Schedule 2: Technical and organisational security measures

Rooby implements the following measures to protect Personal Data:

  • Encryption in transit: TLS 1.3 for all connections between the client browser, Rooby servers, and the Xero API
  • Encryption at rest: AES-256 encryption for all stored financial data
  • Token security: OAuth refresh tokens are encrypted using a key management service (KMS); encryption keys are stored separately from the tokens they protect and are never stored in application code or logs
  • Access control: Row-level security enforced at the database layer; each firm’s data is logically isolated; team member access is scoped to assigned clients
  • Audit trail: All data access, calculations, and user actions are logged with user ID, timestamp, and action type
  • Read-only Xero access: Rooby requests only read scopes from Xero; it cannot create, modify, or delete any data in a client’s Xero organisation
  • Breach response: Rooby maintains an incident response procedure; affected Controllers will be notified within 72 hours of a confirmed breach in accordance with UK GDPR Article 33
  • Dependency and security reviews: Regular reviews of application dependencies and security posture; SOC 2 certification is on the roadmap as the business scales
Privacy Policy · Terms of Service · Back to homepage
Rooby

Live tax forecasting for accountants and the businesses they advise.

Built for UK accountants and their clients.

Product

Product walkthrough Pricing Changelog Security Blog

Who it's for

For Accountants For Businesses

Legal

Privacy Policy Terms of Service Data Processing Agreement

Contact

hello@rooby.co.uk

© 2026 Rooby. All rights reserved.