Snapshot 39926
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Last Updated: July 2026
Acumatica, Inc.
DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the applicable End-User License
Agreement or Acumatica Subscription SaaS Agreement (the “Agreement”) between the Subscriber and Acumatica,
Inc. (“Acumatica”). This DPA reflects the parties’ agreement with respect to the Processing of Personal Data (as
defined below) to ensure compliance with the requirements of Data Protection Laws. This DPA will control with respect
to the subject matter herein in the event of any conflict with the Agreement. This DPA includes the Standard
Contractual Clauses, which are incorporated by reference below.
Definitions. Capitalized terms used herein and not otherwise defined in this DPA shall have the meaning set forth in
the Agreement:
“Data Controller” means the entity that determines the purposes and means of Processing Personal Data (in this
case, Subscriber) and shall include a "business" as such term is defined by the CCPA / CPRA and any similar or
analogous designation under Data Protection Laws.
"Data Exporter" means Subscriber or its Affiliate who transfers the Personal Data out of the EEA, Switzerland or the
United Kingdom.
"Data Importer" means Acumatica or its Affiliate who receives Personal Data from the EEA, Switzerland or the United
Kingdom.
"Data Processor" means the entity that Processes Personal Data on behalf of the Data Controller (in this case,
Acumatica) and shall include a "service provider" as such term is defined by the CCPA / CPRA and any similar or
analogous designation under Data Protection Laws.
"Data Protection Laws" means any data protection laws and regulations applicable to a party and its respective
Processing of Personal Data under the Agreement, including, where applicable, EU/UK Data Protection Law, US
Data Protection Law and the Swiss DPA.
"Data Subject" means the individual to whom Personal Data relates and shall include a "consumer" as such term is
defined by the CCPA / CPRA and any similar or analogous designation under Data Protection Laws.
"EEA" means the European Economic Area as constituted at the time of the transfer.
"EU/UK Data Protection Law" means: (i) Regulation 2016/679 of the European Parliament and of the Council on
the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such
data (General Data Protection Regulation) (the "EU GDPR"); (ii) the EU GDPR as saved into United Kingdom law
by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (the "UK GDPR"); (iii) the EU
e-Privacy Directive (Directive 2002/58/EC); and (iv) any and all applicable national data protection laws made under,
pursuant to or that apply in conjunction with any of (i), (ii) or (iii); in each case as may be amended or superseded
from time to time.
"Personal Data" means any Subscriber Data that is protected as "personal data", "personal information", "personally
identifiable information" or the like under Data Protection Laws that is Processed by Acumatica as a Data Processor
in connection with the Service.
"Processing", "Processes", or "Process" means any operation or set of operations performed upon Personal
Data, whether or not by automated means, such as collection, recording, organization, storage, adaptation, or
alteration, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.
"Restricted Transfer" means: (i) where the EU GDPR applies, a transfer of personal data from the EEA to a country
outside of the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the
UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not based on
adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (iii) where the
Swiss DPA applies, a transfer of personal data from Switzerland to any other country which is not determined to
Last Updated: July 2026
provide adequate protection for personal data by the Federal Data Protection and Information Commission or Federal
Council (as applicable).
"Standard Contractual Clauses" or "EU SCCs" means the contractual clauses annexed to the European
Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of
personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council,
as amended, superseded or replaced from time to time.
"Sub-processor" means any third-party Data Processor that Processes Personal Data for Acumatica.
"Subscriber" means the entity procuring the SaaS services under the Agreement.
"Subscriber Data" means any data or information provided by the Subscriber to Acumatica for Processing under the
Agreement.
"Subscriber Data Incident" means a confirmed breach of security leading to any accidental or unlawful destruction,
loss, alteration, unauthorized disclosure of, or access to Personal Data Processed in environments controlled by
Acumatica or its Sub-processors.
"Swiss DPA" means the Swiss Federal Act on Data Protection 1992 (including as amended or superseded).
"UK Addendum" means the International Data Transfer Addendum (version B1.0) issued by Information
Commissioners Office under S.119(A) of the UK Data Protection Act 2018, as amended, superseded or replaced from
time to time.
"US Data Protection Law" means (i) the California Consumer Privacy Act (the “CCPA”), as amended by the California
Privacy Rights Act ("CPRA") when effective, as well as any regulations and guidance that may be issued thereunder;
and, where applicable, (ii) the Virginia Consumer Data Protection Act ("CDPA") when effective; (iii) the Colorado
Privacy Act ("CPA") when effective; (iv) the Utah Consumer Privacy Act when effective (“UCPA”); (v) the Connecticut
Data Privacy Act ("CTDPA") when effective; in each case as may be amended or superseded from time to time.
Processing of Personal Data. Subscriber controls the categories of Data Subjects and any Personal Data
Processed under this Agreement, the details of which are set out in Annex I. Acumatica has no knowledge of, or
control over, the specific Personal Data that Subscriber provides for Processing in the course of the Services.
Subscriber is solely responsible for: (a) the accuracy, quality, and legality of the Subscriber Data and the means by
which it acquired the Subscriber Data; and (b) ensuring that its submission of Personal Data to Acumatica and
instructions for the Processing of Personal Data comply with Data Protection Laws. Acumatica is not responsible
determining if Subscriber's Processing instructions are compliant with applicable law; however, Acumatica will inform
Subscriber without delay if, in Acumatica’s opinion, Subscriber’s instructions violate Data Protection Laws, and
Acumatica shall not be required to comply with such instructions. Taking into account the nature of the Processing,
Subscriber agrees that it is unlikely that Acumatica would become aware if Personal Data Processed by Acumatica
is inaccurate or outdated. To the extent Acumatica becomes aware of such inaccurate or outdated data, Acumatica
will inform the Subscriber of this.
Processing Instructions. Acumatica will Process Personal Data on behalf of and in accordance with Subscriber’s
lawful documented instructions. For these purposes, Subscriber instructs Acumatica to Process Personal Data to (i)
perform the Services in accordance with the Agreement (including this DPA and all documents incorporated into the
Agreement) and (ii) to comply with Subscriber’s other reasonable instructions communicated to Acumatica to the
extent those instructions are consistent with the Agreement ("Permitted Purposes"). The parties agree that the
Agreement (including this DPA) sets out Subscriber's complete and final instructions to Acumatica in relation to the
Processing of Personal Data and Processing outside the scope of these instructions (if any) shall require prior written
agreement between the parties. Apart from such Processing, Acumatica will not Process Personal Data to or for
third parties unless required to do so by applicable law; if such a requirement arises Acumatica will make reasonable
efforts to inform Subscriber in advance of the required Processing, unless such notice is prohibited by law.
Purpose Limitation. Subscriber is disclosing the Personal Data to Acumatica only for the Permitted Purposes.
Acumatica shall comply with all applicable requirements of Data Protection Laws and provide the same level of privacy
protection under Data Protection Laws. Acumatica shall inform Subscriber as soon as reasonably practicable, unless
prohibited from doing so under applicable law, if (i) it becomes aware or believes that any processing instruction from
Last Updated: July 2026
Subscriber violates Data Protection Laws; (ii) it is makes a determination that it can no longer meet its obligations
under Data Protection Laws and/or this DPA for any reason; and/or (iii) it is required by applicable law to process
Personal Data for any other purpose other than in accordance with Subscriber's processing instructions. In the event
of any such non-compliance and/or if Subscriber is aware or has reason to believe that Acumatica has breached or
will breach its obligations under Data Protection Laws and/or this DPA, but without prejudice to any other right or
remedy available to Subscriber under the Agreement and this DPA:
(a) Subscriber shall have the right to take any reasonable and appropriate steps to ensure that
Acumatica uses the Personal Data in a manner consistent with Subscriber’s obligations under Data
Protection Laws;
(b) Acumatica shall work with Subscriber and promptly take all reasonable and appropriate steps to
remediate (if remediable) any non-compliance; and/or
(c) Subscriber may, upon written notice, elect to suspend or terminate the processing of Personal Data
under the Agreement and/or terminate the Agreement without any further liability or obligation to
Acumatica.
Limited Processing under US Data Protection Law: Acumatica represents and warrants that it shall not create,
collect, receive, access, use, or otherwise process the Personal Data for any purpose other than the Permitted
Purposes or in violation of any Data Protection Laws. Acumatica further represents and warrants that it shall not “sell”
Personal Data, as such term is defined under the CCPA / CPRA (regardless of whether the CCPA / CPRA applies),
CDPA, CPA, or other US Data Protection Law, and will also not “share” Personal Data within the meaning of the CPRA
(regardless of whether the CPRA applies). Acumatica shall process the Personal Data solely and exclusively for the
purposes for which the Personal Data, or access to it, is provided pursuant to the terms and conditions of the
Agreement and this DPA. Acumatica shall not retain, use, or disclose Personal Data outside of the direct business
relationship between Acumatica and Subscriber for any purpose other than the Permitted Purposes, nor shall
Acumatica retain, use, or disclose Personal Data for any purposes other than the Permitted Purposes or as otherwise
permitted under Data Protection Laws. To the extent required by Data Protection Laws, Acumatica certifies that it
understands the foregoing restrictions and will comply with them. In all cases, Acumatica will comply with any
applicable restrictions under Data Protection Laws on combining personal data received from Subscriber with personal
data that Acumatica receives from, or on behalf of, another person or persons, or that Acumatica may collect from any
interaction between it and a data subject.
Data Subject Requests. Acumatica shall, to the extent legally permitted and where the Subscriber is identified or
identifiable from the request, promptly notify Subscriber if Acumatica receives: (i) a request from a Data Subject
seeking to exercise any of its rights under Data Protection Law in connection with the Processing of Personal Data,
including rights of access, rectification, restriction, erasure, data portability, objection or opt-out (“Data Subject
Request”) and (ii) any other correspondence, enquiry or complaint received from a Data Subject, regulator, data
protection authority, Attorney General or other third party in connection with the processing of the Personal Data. In
addition, to the extent Subscriber does not have the ability to address a Data Subject Request because it does not
have custody or control of the necessary information technology systems (and Acumatica does) and taking into
account the nature of the Processing, Acumatica shall provide Subscriber with commercially reasonable assistance
(including by appropriate technical and organizational measures, in so far as is possible) to enable Subscriber to
respond to a Data Subject Request. To the extent Subscriber requires any additional assistance, Subscriber shall be
responsible and will indemnify Acumatica for any costs arising from Acumatica providing such assistance.
Acumatica Personnel. Acumatica shall ensure its personnel engaged in the Processing of Personal Data are
informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities,
are subject to a duty of confidentiality (whether contractual or statutory) and that they will only Process Personal Data
for the Permitted Purposes. Acumatica shall ensure that access to Personal Data is limited to those personnel who
require access to perform services or Process Personal Data in accordance with the Agreement.
Sub-processors. Subject to compliance with this paragraph, Subscriber expressly authorizes Acumatica to use Sub-
processors, including those listed in Annex III of this DPA (the "Sub-processor List").
Acumatica shall ensure that: (a) Sub-processors shall be bound by a written agreement, including data protection
and security measures, no less protective of Personal Data than the Agreement and this DPA; (b) Acumatica shall
be liable for any breach of this DPA caused by an act, error or omission of its Sub-processors to the extent Acumatica
would have been liable had such breach been caused by Acumatica; and (c) Acumatica will notify Subscriber in
writing if it adds a new Sub-processor to the Sub-processor List at least thirty (30) days in advance. If within thirty
(30) days of receipt of such notice, Subscriber objects, in writing, to Acumatica’s appointment of a new Sub-processor
Last Updated: July 2026
on reasonable grounds relating to data protection, the parties will discuss such concerns in good faith with a goal of
achieving resolution, failing which Subscriber may terminate the Agreement and this DPA without further liability upon
written notice to Acumatica. Upon request, Acumatica will provide an up-to-date Sub-processor List.
Security. Acumatica shall implement and maintain appropriate technical and organizational safeguards designed to
protect the confidentiality, integrity, and security of Subscriber Data, including protection from Subscriber Data
Incidents, as further described in Annex II of this DPA ("Security Measures"). Acumatica may update the Security
Measures from time to time, provided that any updates shall not materially diminish the overall security of Subscriber
Data. Acumatica shall notify Subscriber without undue delay after becoming aware of Subscriber Data Incident.
Acumatica shall make reasonable efforts to identify the cause of such Subscriber Data Incidents and take steps it
deems necessary and reasonable to remediate the cause of such incidents to the extent doing so is within
Acumatica’s control. To the extent that a Subscriber Data Incident is caused by Subscriber, its affiliates, or users, the
Subscriber will be responsible for any costs Acumatica incurred while meeting these Security obligations.
Data Protection Impact Assessments. Upon Subscriber’s request, Acumatica shall provide Subscriber with
reasonable cooperation and assistance to the extent needed for Subscriber to fulfil its obligations under the GDPR or
applicable Data Protection Laws to conduct a data protection impact assessment related to Subscriber’s use of the
Service, but only where Subscriber does not have access to relevant information that is only available from Acumatica.
To the extent required by the GDPR or applicable Data Protection Laws, in connection with the tasks in this section,
Acumatica will provide reasonable assistance to Subscriber in cooperation, or prior to consultation, with any
Supervisory Authority. For the avoidance of doubt, this section shall also apply where a risk assessment, data
protection assessment or other similar assessment is required under US Data Protection Law, including, if necessary,
to assist Acumatica to consult with a data protection agency or Attorney General.
Return or deletion of Subscriber Data: Upon termination or expiry of the Agreement, on Subscriber's written
request Acumatica shall delete all Personal Data in its possession or control in accordance with the Agreement, save
that this requirement shall not apply to the extent Acumatica is required by applicable law to retain some or all of the
Personal Data, or to Personal Data it has archived on back-up systems, which data Acumatica shall securely isolate
and protect from any further processing and delete in accordance with its deletion practices, except to the extent
required by applicable law.
Data Transfers. Where Subscriber makes a Restricted Transfer of Personal Data to Acumatica, then the Standard
Contractual Clauses shall be deemed incorporated into and form an integral part of this DPA as follows:
a. in relation to Personal Data protected by the EU GDPR, the EU SCCs will be completed as follows:
• Module Two will apply;
• in Clause 7, the optional docking clause will apply;
• in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes shall be
as set out in the section headed " Sub-processors" above;
• in Clause 11, the optional language will not apply;
• in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Irish law;
• in Clause 18(b), disputes shall be resolved before the courts of Ireland;
• Annex I of the EU SCCs shall be deemed completed with the information set out in Annex I to this
Agreement;
• Annex II of the EU SCCs shall be deemed completed with the information set out in Annex II to this
Agreement, as updated in accordance with this DPA.
b. in relation Personal Data protected by the UK GDPR, the Standard Contractual Clauses:
• shall apply as completed in accordance with paragraph (a) above; and
• shall be deemed amended as specified by the UK Addendum, which shall be deemed executed between
the transferring Subscriber and Acumatica, and incorporated into and form an integral part of this DPA.
In addition, Tables 1 to 3 in Part 1 of the UK Addendum shall be deemed completed with the information
set out in the DPA (including its Annexes) and Table 4 in Part 1 shall be deemed completed by selecting
"importer"; and
• any conflict between the terms of the Standard Contractual Clauses and the UK Addendum shall be
Last Updated: July 2026
resolved in accordance with Section 10 and Section 11 of the UK Addendum.
c. In relation to transfers of Personal Data protected by the Swiss DPA, the Standard Contractual Clauses
shall apply completed in accordance with paragraph (a) above with the following modifications:
• references to “Regulation (EU) 2016/679” and specific articles therein shall be interpreted as references
to the Swiss DPA and the equivalent articles or sections therein;
• references to “EU”, “Union”, “Member State” and “Member State law” shall be replaced with references
to “Switzerland” and “Swiss law” and references to the “competent supervisory authority” and
“competent courts” shall be replaced with references to the “Swiss Federal Data Protection Information
Commissioner” and “competent Swiss courts”; and
• the Standard Contractual Clauses shall be governed by the laws of Switzerland and disputes shall be
resolved before the competent Swiss courts.
d. If there is any conflict between the body of this DPA and the Standard Contractual Clauses, the Standard
Contractual Clauses will prevail.
Audit. Upon Subscriber's written request, and subject to obligations of confidentiality, Acumatica shall provide
Subscriber a summary copy of its most recent SOC II audit report ("Report") so that Subscriber (or its third-party
auditors) can audit and verify Acumatica's compliance with this DPA. If the Report does not, in Subscriber's
reasonable judgement, provide sufficient information to confirm Acumatica's compliance with this DPA, then
Acumatica shall provide written responses (on a confidential basis) to all reasonable requests for information made
by Subscriber, including responses to information security and audit questionnaires that are necessary to confirm
Acumatica's compliance with this DPA.
Subscriber will not exercise its audit rights more than once in any twelve (12) calendar month period, except (i) if
and when required by instruction of a competent data protection authority (or other relevant authority competent for
enforcing Data Protection Laws); or (ii) Subscriber believes a further audit is necessary due to a Subscriber Data
Incident suffered by Acumatica.
Subscriber acknowledges and agrees that it shall exercise its audit rights under this DPA (including, where
applicable, the Standard Contractual Clauses) by instructing Acumatica to comply with the audit measures
described in this Section.
Onsite Audits: Except where otherwise required by Data Protection Laws or a data protection authority, the parties
agree that the audits right in the "Audit" section of this DPA satisfies Subscriber's requirements. Where Data
Protection Laws or a data protection authority requires it, Subscriber may provide Acumatica with thirty (30) days'
prior written notice requesting that a third party conduct an audit of Acumatica's relevant systems; provided that (i)
any such audit shall be conducted at Subscriber's expense; (ii) the parties shall mutually agree upon the scope,
timing and duration of such audit; (iii) the audit shall not unreasonably impact Acumatica's regular operations; and
(iv) in no event shall Subscriber obtain any access to data of any other Subscriber or third party.
Last Updated: July 2026
ANNEX I - DATA PROCESSING DESCRIPTION
This Annex forms part of the DPA and describes the processing that Acumatica will perform on behalf of the
Subscriber.
A. LIST OF PARTIES
Controller(s) / Data exporter(s):
1. Name: Subscriber, as defined in the Subscription SaaS
Services Agreement (“Agreement”)
Address: As set out in the Agreement and applicable Order
Forms.
Contact person’s name, position and The administrator contacts registered by the Subscriber
contact details: when creating an account with Acumatica.
Activities relevant to the data Subscriber (data exporter) will use Acumatica's (data
transferred under these Clauses: importer's) enterprise resourcing planning platform for
personnel management purposes.
Signature and date: This Annex I shall be deemed executed upon execution
of the Agreement.
Role (controller/processor): Controller
Processor(s) / Data importer(s): [Identity and contact details of the processor(s) /data importer(s), including any
contact person with responsibility for data protection]
1. Name: Acumatica, Inc. (“Acumatica”).
Address: 3933 Lake Washington Blvd NE #350, Kirkland,
Washington 98033, USA.
Contact person’s name, position and Acumatica's legal counsel with responsibility for privacy
contact details: can be contacted at [email protected].
Activities relevant to the data transferred Acumatica (data importer) is a provider of a cloud-
under these Clauses: based enterprise resource planning platform.
Signature and date: This Annex I shall be deemed executed upon execution
of the Agreement.
Role (controller/processor): Processor
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is The Data Exporter may submit Personal Data to
transferred: the Service, the extent of which is determined
and controlled by the Data Exporter in its sole
discretion.
The Personal Data may include but is not limited
to Personal Data concerning the Data Exporter’s
end users including employees, contractors and
the personnel of the Subscriber and its
suppliers, collaborators, and subcontractors.
Data Subjects also includes individuals
attempting to communicate with or transfer
Personal Data to the Data Exporter’s end users.
Categories of personal data transferred: The Data Exporter may submit Personal Data to
the Acumatica Service, the extent of which is
determined and controlled by the Data Exporter
Last Updated: July 2026
in its sole discretion, and which may include, but
is not limited to the following categories of
Personal Data:
• First and last name
• Title
• Position
• Employer
• Contact information (company, email,
phone, physical business address)
• ID data (username, user ID)
• Professional life data
• Professional skills information
• Personal life data
• Employee compensation information
• Connection data
• Localisation data
• Website and platform usage information
• Email data
• Communications data (e.g. contained in
live chat customer support inquiries)
• System usage data
• Application integration data
• Transaction information (including
amount, status and payment terminal ID)
• Other electronic data submitted, stored,
sent, or received by end users via the
Acumatica Service
Sensitive data transferred (if applicable) and The Data Exporter may submit special
applied restrictions or safeguards that fully take into categories of Personal Data to the Acumatica
consideration the nature of the data and the risks Service, the extent of which is determined and
involved, such as for instance strict purpose controlled by the Data Exporter in its sole
limitation, access restrictions (including access discretion, and which may include, but is not
only for staff having followed specialised training), limited to the following categories of sensitive
keeping a record of access to the data, restrictions Personal Data:
for onward transfers or additional security
measures: • Health and medical information
• Other electronic sensitive data submitted,
stored, sent, or received by end users via
the Acumatica Service
Any such special categories of data will be
protected in accordance with the measures set out
in Annex II.
The frequency of the transfer (e.g. whether the data Continuous for the duration of the Acumatica
is transferred on a one-off or continuous basis): Service.
Nature of the processing: The provision of the Acumatica Service to
Subscriber in accordance with the Agreement.
Purpose(s) of the data transfer and further The Permitted Purposes (as defined in the DPA)
processing: shall include Processing or providing support
services to the Subscriber for Subscriber’s end
users. The Data Exporter also instructs the Data
Importer to process Personal Data in countries
in which the Data Importer or its Sub-processors
Last Updated: July 2026
maintain facilities as necessary for it to provide
the Service.
The period for which the personal data will be Data processing will be for the term specified in the
retained, or, if that is not possible, the criteria used Agreement. For the term of the Agreement, and for
to determine that period: a reasonable period of time after the expiry or
termination of the Agreement, the Data Importer will
provide the Data Exporter with access to, and the
ability to export, the Data Exporter’s Personal Data
Processed pursuant to the Agreement, following
which the Personal Data will be deleted.
For transfers to (sub-) processors, also specify The nature and duration of the processing are as
subject matter, nature and duration of the set out above and in the Agreement.
processing:
The subject matter of the processing concerns the
processing of the Personal Data about the
categories of Data Subjects, each as set out in this
Annex I.
C. COMPETENT SUPERVISORY AUTHORITY
Identify the competent supervisory authority/ies in The competent supervisory authority will be
accordance (e.g. in accordance with Clause 13 determined in accordance with Clause 13 of these
SCCs) Standard Contractual Clauses.
Last Updated: July 2026
ANNEX II – TECHNICAL AND ORGANIZATIONAL SECURITY
MEASURES
Description of the technical and organizational measures implemented by the processor(s) / data
importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into
account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms
of natural persons.
1. As a “Software as a Service” (“SaaS”) provider, Acumatica’s approach to information security is a risk
management imperative we share with our customers.
2. Our information security program is designed to be consistent with internationally accepted standards and
involves a layered, defense-in-depth approach to protecting the confidentiality, integrity, and, availability of
systems and data, deploying administrative, technical, and physical controls.
3. Our ERP solutions are designed and developed pursuant to secure software development lifecycle
processes, for example, strict control over access to source code, rigorous code review and testing, and
securely segregated development, test, and production environments.
4. We require our entire team to review and certify compliance with a comprehensive set of information security
policies, which we then monitor and enforce.
5. We provide regular training to raise awareness regarding cybersecurity and data privacy issues and strive to
maintain a corporate culture where employees are vigilant for cyber-threats and prepared for cybersecurity
incidents.
6. By hosting our SaaS in Amazon Web Services, we provide our customers with the security benefits that
come with the most advanced cloud computing infrastructure on the planet. Aside from the formidable
infrastructure security provided by Amazon, Acumatica has architected its services so that customer
environments are securely segregated. Administrative access to Acumatica’s AWS services is strictly limited
to a small number of Acumatica personnel on the basis of “need to know” and “least privilege” and requires
the use of Multi-Factor Authentication.
7. These Acumatica employees, as well as those who support customers and may need to access customer
databases for support purposes, can only do so through encrypted channels via an Acumatica IP address.
This means that Acumatica’s access to a customer database for support purposes requires a connection
through either an Acumatica physical facility or office or the Acumatica VPN, which uses TLS 1.2 or IPSEC.
The data associated with such activity is logged by our security personnel.
8. Availability of customer data is ensured through a system of redundant backups across AWS regions, daily,
weekly, monthly, and quarterly. The backups are encrypted as well as regularly tested. Retention of the
various backups is scheduled to provide recovery under multiple different scenarios and varying historical
timing implications.
9. Acumatica uses leading-edge technology to ensure that the person who is trying to access your company’s
data is exactly who they say they are. For example, user logins can be limited to specific IP addresses, which
means that no one without a recognizable IP address will be able to access the system. A variety of password
protection measures can be put in place as well. You can decide how often users are prompted to change
their passwords. Password complexity requirements can help ensure only difficult-to-crack passwords are
chosen. Even one-time password and single-sign-on solutions can be installed, which means a unique multi-
factor method of access is required to gain access at every log-in attempt.
10. Acumatica allows customers to control user access to their data, functions, and features that are necessary
to the user’s role using a role-based access control approach.
11. Acumatica offers data encryption as the main feature. Acumatica uses the same encryption technology that
protects financial institutions as well as the United States military. Sensitive fields such as credit card and
social security numbers within your SQL databases are encrypted. For internal systems Advanced
Encryption Standard (AES) 128, 192, or 256-bit encryption. External access to Acumatica portal is via TLS
Last Updated: July 2026
12. Acumatica has a fully staffed, highly trained, 24/7 security operations center already. It’s their responsibility to
monitor and protect your data.
ANNEX III – LIST OF SUB-PROCESSORS
Subscriber expressly authorizes Acumatica to use the following Sub-processors in accordance with this DPA.
Entity Name Details of Processing Activity Location(s) of Processing
Activity
Amazon Web Services Cloud infrastructure provider United States, Canada, United
(Infrastructure as a service), Kingdom and Singapore
including service hosting and
data storage
Microsoft Corporation Cloud infrastructure provider United States
(Microsoft Azure) (Infrastructure as a service),
including service hosting and
data storage
Plaid Financial Ltd, an For customers who choose to United Kingdom
authorized payment institution link their banking account with
regulated by the Financial their Acumatica account:
Conduct Authority (firm Open banking connection and
reference number 804718) management, which provides
under the Payment Services regulated account information
Regulations 2017 services through Acumatica as
its agent. Their privacy
statement is accessible at:
https://plaid.com/legal/#end-
user-privacy-policy
Elasticsearch, Inc. Logging and analytics tool for United States
support and debugging
purposes.
Intercom, Inc. (doing business Customer engagement and United States, Ireland, Australia
as Fin) support platform including live
chat, automated messaging, and
help desk ticketing to facilitate
communication with Acumatica
end users and to help resolve
customer support inquiries.