Akuna Solutions Pty Ltd
ACN 627 179 917
Ground Level, 465 Victoria Avenue, Chatswood, NSW 2067, Australia
Data Processing Agreement
Add-On Products for Sage Intacct™
Introduction
This Data Processing Agreement (“DPA”) supplements and forms part of the Terms of Service (Add-On Products) (the “Agreement”) between Akuna Solutions Pty Ltd (ACN 627 179 917) (“Processor”, “Akuna”, “we”, “us”, or “our”) and the Customer (“Controller” or “you”). Capitalised terms not defined in this DPA have the meaning given in the Agreement.
In the event of any conflict or inconsistency among the following documents, the order of precedence shall be: (1) any Standard Contractual Clauses or other legally mandated instruments required by applicable Data Protection Laws for the cross-border transfer of Personal Data; (2) this DPA; and (3) the Agreement (Terms of Service).
By accepting the Agreement or using the Services, you accept this DPA.
1. Subject Matter, Role of the Parties, and Duration
- Role of the parties. In relation to the Customer’s Personal Data processed via the Add-Ons, the Customer is the Controller and Akuna is the Processor. If the Customer acts as a Processor on behalf of an end-client, Akuna acts as a Sub-processor.
- Subject matter and nature. Akuna provides software Add-Ons that integrate with and extend the Customer’s Sage Intacct™ environment. Consistent with Section 3 of the Agreement, Customer Data is not persistently stored outside Sage Intacct: Personal Data is processed transiently to perform calculations, validations, transformations, or to render results, and is not retained in a persistent database once that processing is complete. Configuration metadata (which may be stored within and/or outside Sage Intacct), authentication tokens, and logs are the limited exceptions described in Section 3 of the Agreement and this DPA.
- Duration. This DPA remains in effect concurrently with the term of the Agreement. On termination or expiry of the Agreement, Akuna will cease processing and will delete any residual Personal Data held in connection with the Add-Ons in accordance with the deletion timetable in Sections 11 and 17 of the Agreement, subject to any legally mandated retention. Records already written by an Add-On into the Customer’s Sage Intacct environment persist in Sage Intacct and are not affected by termination (Section 3.2 of the Agreement).
2. Definitions
- Data Protection Laws: Any applicable local, national, or international laws relating to privacy and data protection, including the Australian Privacy Act 1988 (Cth), the EU GDPR, the UK GDPR and UK Data Protection Act 2018, Singapore’s Personal Data Protection Act 2012 (PDPA), and the CCPA/CPRA, in each case to the extent applicable to the processing under this DPA.
- Personal Data: Any information relating to an identified or identifiable natural person that is synchronised, inputted, or extracted via the Services by or on behalf of the Customer.
- Telemetry and Usage Data: System data related to how the Customer interacts with the Services (e.g. feature usage, load times, errors), which is aggregated and does not identify, and cannot reasonably be used to re-identify, any individual or the Customer.
- Sub-processor: Any third-party infrastructure or service provider engaged by Akuna to Process Personal Data, including the provider(s) of the Hosting Platform.
3. Categories of Data and Data Subjects
As the Add-Ons process the data the Customer chooses to connect through its Sage Intacct environment, the Customer determines the scope of the data. Categories of Data Subjects may include:
- the Customer’s employees, authorised users, and administrators; and
- the Customer’s clients, vendors, or business partners, to the extent their data exists within the connected Sage Intacct environment.
Types of Personal Data processed may include contact information (names, email addresses, phone numbers), system data (usernames, role-based permissions, IP addresses), and financial or operational data that may indirectly contain personal identifiers (e.g. expense claims, invoice contacts). Akuna does not intentionally collect, nor do the Add-Ons require, special categories of Personal Data (such as health, genetic, or ethnic-origin data).
4. Obligations of the Customer (Controller)
As the Controller, the Customer is solely responsible for the accuracy, quality, and legality of the Personal Data made available to Akuna via the Add-Ons. The Customer warrants that it has a valid lawful basis under applicable Data Protection Laws to collect the Personal Data and to have it processed by Akuna for the provision of the Services, and that its instructions to Akuna comply with applicable law.
5. Obligations of Akuna (Processor)
Akuna warrants and agrees that it shall:
- Documented instructions. Process Personal Data only on the Customer’s documented instructions (which include the Agreement and the Customer’s standard use and configuration of the Services), unless required to do otherwise by law, in which case Akuna will inform the Customer of that legal requirement where permitted.
- Confidentiality. Ensure that personnel authorised to process Personal Data are bound by obligations of confidentiality consistent with Section 18 of the Agreement.
- Data security. Implement and maintain the technical and organisational measures described in Section 11 of the Agreement, including encryption in transit and at rest where applicable, access controls, and logging, to protect Personal Data against unauthorised access, loss, or destruction.
- Data subject rights. Promptly notify the Customer if it receives a request directly from a Data Subject, and assist the Customer by appropriate technical and organisational means, insofar as possible, in responding to such requests.
- Assistance. Provide the Customer with reasonable assistance in relation to data protection impact assessments and consultations with supervisory authorities, taking into account the nature of the processing and the information available to Akuna.
- Fees for assistance. Akuna may charge the Customer reasonable fees, at its prevailing rates, for the assistance described above (including responding to Data Subject requests, supporting data protection impact assessments and regulator consultations, and supporting audits under Section 9).
- No training on Customer Data. Not use Customer Data to train general-purpose or cross-customer AI or machine-learning models, except as expressly permitted by this DPA or with the Customer’s consent, consistent with Section 13 of the Agreement.
6. Telemetry and Usage Data
Akuna collects Telemetry & Usage Data to ensure system stability, bill for the Services accurately, and improve product performance. Where such data is genuinely aggregated and cannot reasonably be used to identify any individual or the Customer, it is not Personal Data, and Akuna acts as an independent Controller of it and may use it for its own legitimate business purposes. Akuna will not seek to re-identify individuals from Telemetry & Usage Data.
7. Sub-processors
The Customer grants Akuna general authorisation to engage Sub-processors to deliver the Services, including the provider(s) of the Hosting Platform on which the Add-Ons run.
- List of sub-processors. Akuna maintains an up-to-date list of its active Sub-processors at https://akunasolutions.com/sub-processors/ .
- Changes and objections. Akuna will update that list when adding or replacing a Sub-processor. It is the Customer’s responsibility to review the list from time to time for changes. The Customer may reasonably object to a new Sub-processor in writing within 30 days of the list being updated, and Akuna will work with the Customer in good faith to resolve the objection. If the objection is not resolved within 30 days of being lodged, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused portion of the Subscription Term. This right is one of the refund exceptions cross-referenced in Section 5.4 of the Agreement.
- Selection and responsibility. Akuna binds each Sub-processor to data-protection obligations at least as protective as those in this DPA. The Customer acknowledges that it has had the opportunity to review the list of Sub-processors and is responsible for satisfying itself as to their suitability for the Customer’s requirements.
8. Personal Data Breach Notification
In the event of a confirmed Personal Data Breach affecting the Customer’s Personal Data, Akuna shall, consistent with Section 11 of the Agreement:
- notify the Customer without undue delay after becoming aware of the breach, and within the timeframes required by applicable Data Protection Laws;
- provide a description of the breach, the categories of data affected, and the approximate number of Data Subjects impacted, to the extent known;
- outline the remediation measures taken or proposed to mitigate the breach’s effects; and
- provide a point of contact for ongoing updates.
9. Audits and Compliance
On written request, Akuna will make available documentation reasonably necessary to demonstrate compliance with this DPA. Where that documentation does not satisfy the Customer’s regulatory requirements, Akuna will permit an audit by the Customer or a mutually agreed independent auditor, at the Customer’s expense, during normal business hours, on reasonable advance notice, and subject to confidentiality obligations. Akuna may charge reasonable fees, at its prevailing rates, for time spent supporting such audits.
10. International Data Transfers
Where processing involves a transfer of Personal Data to a jurisdiction not recognised as providing an adequate level of protection under the applicable Data Protection Laws, Akuna will ensure the transfer is governed by a valid transfer mechanism, including the relevant Standard Contractual Clauses or other legally mandated framework approved by the appropriate authority, which are incorporated into this DPA by reference. The Customer is responsible for satisfying itself as to the acceptability of the locations in which Personal Data is processed, having regard to the Sub-processor list.
11. Governing Law
Consistent with the Agreement, this DPA is otherwise governed by the laws of New South Wales, Australia, and disputes are resolved as set out in Section 21.1 of the Agreement.
Published 1 August 2026.
