Skip to main content

Trust and legal

Data Processing Addendum

How Nummbas handles the personal data about your customers, suppliers and contractors that it processes for you.

Effective October 1, 2026. Last updated October 1, 2026.

On this page

Key points

  • Our role. We handle information about your customers, suppliers and contractors for you and on your instructions. We do not sell it or use it to train AI models. See section 3.
  • Nothing to sign. This addendum applies automatically when that information includes personal data.
  • Your part. You need a lawful reason to collect this data, and your privacy notice must say that you use providers such as Nummbas.
  • Who helps us. We give at least 30 days' notice before a new provider starts handling this data, or less if a replacement is urgent. You can object. See section 7.
  • Security and breaches. Schedule 2 lists our security measures. We tell you without undue delay if a breach affects this data.
  • Deleting data. When you disconnect a service we delete the data we synced from it straight away. After you close your account you can ask us to restore it for 90 days, and then we delete it. Both have exceptions. See section 11.
  • Where data goes. Our servers and database are in Singapore, hosted by Render. Some providers handle this data in other countries. The transfer clauses that European Union, UK and Swiss law can require are built in. See section 13.

About this addendum

Who we are. Nummbas is operated by Implemit Pty Ltd (ABN 22 690 942 495, ACN 690 942 495), trading as Nummbas, of Level 25 Capital Square Tower 3, 1 Spring St, Perth WA 6000, Australia. "We", "us" and "our" mean Implemit Pty Ltd. "You" means the business named on the Nummbas account.

What this addendum is. This Data Processing Addendum (the "Addendum") is part of the agreement between you and us that the Nummbas Terms of Service (the "Terms") set out. It applies automatically from the moment the data you connect, upload or enter includes Customer Personal Data. If you need a signed copy, email customersupport@nummbas.com.
What it does not cover. Information about you and your team as account holders is covered by our Privacy Policy. That policy is a notice and is not part of the Terms or this Addendum.

If documents conflict. On the handling of Customer Personal Data, this Addendum takes priority over the rest of the Terms. The Transfer Clauses take priority over this Addendum for the transfers they cover.

Definitions

How to read this section. Other capitalized terms, such as "Services", have the meaning given in the Terms.

TermMeaning
"Customer Personal Data"Personal data about your customers, suppliers, contractors, staff and other people that we process for you to provide the Services. It does not include account information about you and your team. "Personal data" includes "personal information" under Australian law.
"Data Protection Laws"The privacy and data protection laws that apply to our processing of Customer Personal Data. They can include the Privacy Act 1988 (Cth), the EU General Data Protection Regulation (the "GDPR"), the UK GDPR and the Swiss Federal Act on Data Protection. "Controller", "processor" and "personal data breach" have the meanings given in the GDPR and the UK GDPR.
"matching code"A code made by a one-way calculation from a shopper's email address or, on some platforms, a customer ID, buyer ID or username. It lets us recognize the same shopper across your stores without storing the email address with the order. We treat it as personal data and do not use it to match shoppers across businesses.
"Subprocessor"Another provider that we engage to process Customer Personal Data for you. Our Subprocessor List names them.
"Transfer Clauses"The "Standard Contractual Clauses" approved by European Commission Implementing Decision (EU) 2021/914, and the "UK Addendum" to them (the International Data Transfer Addendum, version B1.0, issued under section 119A of the UK Data Protection Act 2018, with its Part 2 mandatory clauses, or any version that replaces it), where section 13 says they apply.

Roles and your instructions

Our role. Where the GDPR, the UK GDPR or another law that uses the same two roles applies, you are the controller of Customer Personal Data and we are your processor. If you handle this data for another business, you confirm that it has authorized your instructions to us. The Transfer Clauses here assume you are the controller, so contact us first if you need transfer terms for that data.

Your instructions. We process Customer Personal Data only on your documented instructions. Your instructions are the Terms and this Addendum, the way you set up and use the Services, and any other written instruction consistent with them that you send to customersupport@nummbas.com.

Legal limits. If a law that applies to us requires us to process Customer Personal Data in another way, we tell you first, unless that law forbids it. If a court, regulator or other authority asks us for Customer Personal Data, we direct it to you where the law allows and disclose only the minimum the request requires. We tell you straight away if we believe an instruction breaks Data Protection Laws, and we may pause work on it until you confirm or change it.

What we do not do. We do not sell Customer Personal Data, use it to train AI models or share it with other businesses that use Nummbas. We do not use it to advertise to your customers or to contact them for our own purposes.

One shared list. If an invoice or purchase order email bounces or is reported as spam, the recipient's address goes on a list of addresses we do not send to. One list covers every business, and no business can see it. Email us to have an address taken off.

AI providers. Anthropic and Google process Customer Personal Data as our Subprocessors for the AI features of the Services. The Subprocessor List sets out what each receives. Our Privacy Policy sets out what each states about training and retention.

Your responsibilities

Your data and notices. You confirm that you have the right to give us the Customer Personal Data you connect, upload or enter. You are responsible for having a lawful reason to collect it and to have us process it. You give your customers, suppliers, contractors and staff the privacy notices the law requires. Those notices must say that you use service providers such as Nummbas and that their information may be handled outside their own country. We rely on them to tell these people how we handle their information.

Only what is needed. Please do not upload or enter personal data that the Services do not need.

Confidentiality

Our people. We make sure that the people we authorize to process Customer Personal Data have committed to keep it confidential, or are under a legal duty to do so.

Security

Our measures. We use the measures in Schedule 2 to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction or damage. We may change them over time, but a change will not materially reduce the overall protection.

Subprocessors

Your general authorization. You authorize us to use the Subprocessors on the Subprocessor List, and to add or replace Subprocessors as this section allows. Before a Subprocessor processes Customer Personal Data, we put a written contract in place that requires it to protect the data to a standard that matches, in substance, our duties under this Addendum. We remain responsible to you for what our Subprocessors do with the data.

Notice of changes. We give you at least 30 days' notice before a new Subprocessor starts, by updating the Subprocessor List and emailing the account owner. If we must replace a Subprocessor urgently, for example because of a security risk, the notice may be shorter. It always comes before the new Subprocessor starts.

Your right to object. You can object on reasonable data protection grounds by emailing customersupport@nummbas.com within the notice period, and we work with you to find a solution. If we cannot resolve your objection within 30 days, you may cancel the part of the Services that needs the new Subprocessor, or the whole subscription if the Services cannot reasonably be used without that part. If the replacement was urgent and you object, you may cancel at once. The Terms say when fees are refunded.

Personal data breaches

We tell you. We tell you without undue delay after we become aware of a personal data breach that affects Customer Personal Data, including a breach at a Subprocessor. We email the account owner. As far as we know at the time, we say what happened and when, the kinds of personal data and people affected and roughly how many, the likely consequences, what we have done and plan to do, and who to contact. We follow up as we learn more.

What each of us does. We take reasonable steps to contain the breach, find its cause and reduce its effects. You decide whether to notify a regulator or the people affected, and we give you the information you reasonably need. We do not notify your customers for you unless you ask us in writing or the law requires us to.

Requests from individuals

Your tools. In the product you can disconnect a service, delete a Nummbas-FO conversation, and correct or archive a Nummbas Books contact.

Requests that arrive through a platform. When Shopify asks us to erase a shopper, or eBay tells us that a buyer in your orders has deleted their account, we treat that as your instruction. We clear the person's matching code, country and region from your synced orders. For Shopify, this works where the request includes the shopper's email address and the code was made from that address.

What is not automatic. Those steps change synced orders only. They do not reach payment records with the same matching code, the discount codes, tracking numbers and campaign details recorded for an order, or Nummbas Books records. Requests for a copy of a person's data, including those Shopify passes to us, are not automatic either. For these, and for any request you cannot complete yourself, email customersupport@nummbas.com with the email address the person used with your store. We remove the data, or mask it in Nummbas Books where the law does not require you to keep the record. For a copy request, we send you what we hold for that person's orders within 30 days.

Requests that reach us directly. If a person asks us about Customer Personal Data we hold for you, we pass the request to you without undue delay. We do not answer it ourselves unless the law requires us to. Where Australian law does, we answer within 30 days.

Other help we give you

Assessments and regulators. We give you the information we hold that you reasonably need for a data protection impact assessment or a transfer risk assessment, or to consult or answer a regulator about our processing. We do not charge for reasonable help under this section or section 9.

Deleting and returning data

When you disconnect a service. When you disconnect a service, or uninstall Nummbas from your Shopify store, we delete the data we synced from it straight away. Shipping label records and the record of the connection are deleted about 30 days later. Figures already written into a daily brief, an insight, a Nummbas-FO answer or a report stay. So does the copy Nummbas Books keeps, as an accounting record, of each record it has copied into your books.

When you close your account. Cancelling your subscription does not close the account or delete its data. When you close the account, sign-in access ends straight away for you and your team, and your share links stop working. You can ask us to restore the account for 90 days.

How deletion works today. After the 90 days, an automatic step deletes your account and its data, including the data we synced from your connections and your Nummbas Books records and files. Where an account has a plan billed through Shopify, Wix or BigCommerce that our records show has not ended, the step cannot complete, so none of that account's data is deleted automatically. We delete that account when you ask. Email customersupport@nummbas.com. We act without undue delay and confirm in writing when the deletion is complete.

What we keep after deletion. We keep security logs for 12 months, backups for 7 days, and the list of email addresses we do not send to. We also keep anything a law that applies to us requires, protect it under this Addendum and use it for nothing else. Copies held by our Subprocessors are deleted on the schedule in their own terms, or on our request where they offer that.

Getting your data back. While your plan is active, you can download your Nummbas Books records and the reports your plan includes. Ask us for anything else while your account is open and for 90 days after you close it. When the Services end, we return or delete Customer Personal Data as you ask. If you give no instruction, we handle it as this section describes.

Information and audits

Information and audits. On request, we give you the information you reasonably need to check that we are meeting this Addendum. If that is not enough, if a regulator requires it, or after a personal data breach that affected your data, you or an independent auditor who is bound by confidentiality and is not our competitor may audit our processing of your Customer Personal Data. Give us at least 30 days' written notice, or the shorter period a regulator requires, and agree the scope and timing with us. An audit takes place in business hours, without disrupting the Services, at most once in 12 months unless a regulator requires it or it follows a breach. It does not cover other businesses' data, information that would put security at risk, or our hosting provider's data centers. Each of us pays its own costs. You share the report with us in confidence, and we fix any failure it shows within a reasonable time.

International transfers

Where we process Customer Personal Data. Our servers and database are in Singapore, hosted by Render. We are based in Perth, Australia. Our Subprocessors work in the places shown on the Subprocessor List, which include the United States and the European Union. You instruct us to process Customer Personal Data in those places.

Transfers from Europe to us. Where the law requires a safeguard for your transfer of Customer Personal Data to us, the Transfer Clauses apply between you and us as part of this Addendum, with the selections in Schedule 3. The Standard Contractual Clauses apply under the GDPR and, with the Swiss changes, under the Swiss Federal Act on Data Protection. The UK Addendum applies under the UK GDPR.

Our onward transfers. Where the law requires a safeguard for our transfer to a Subprocessor, we rely on the data protection terms in our contract with that provider. Contact us for details of the safeguard that applies to a particular provider.

Signing. Accepting the Terms has the same effect as signing the Transfer Clauses on the date you accept. For an account opened before the effective date shown at the top of this page, we are bound by this Addendum and the Transfer Clauses from that date.

Australia

How Australian law treats this data. Australian privacy law does not divide organizations into controllers and processors. Under it, we are responsible in our own right for the Customer Personal Data we hold, from every country, as well as acting for you. We handle it in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. That law also keeps us accountable for how our overseas Subprocessors handle it. We work with you on any notification that the Notifiable Data Breaches scheme requires.

United States

Service provider terms. Where a US state privacy law treats you as a "business" or a "controller" of Customer Personal Data, we act as your "service provider" or "processor". You disclose the data to us, and we process it, only for the business purposes in Schedule 1 and within our direct business relationship with you. We do not sell it, share it for cross-context behavioral advertising, or combine it with personal data from other sources, except for the list of email addresses we do not send to and as those laws allow. We comply with the parts of those laws that apply to us and give the data the level of privacy protection they require. We tell you if we can no longer do so. You may take reasonable steps to check how we use the data, and to stop and fix any use this Addendum does not allow.

Liability, changes and other terms

Term and liability. This Addendum applies for as long as we hold Customer Personal Data for you. The limits and exclusions of liability in the Terms apply to claims between you and us under this Addendum. They do not apply to liability under the Transfer Clauses, to what either of us owes an individual under Data Protection Laws, or to any right the law does not allow to be excluded.

Changes to this Addendum. We change this Addendum in the way the Terms describe for changes to the Terms. We change the text of the Transfer Clauses only to replace them with a version that the European Commission or the UK regulator has issued.
Governing law and language. The clause of the Terms on governing law and courts applies to this Addendum. Schedule 3 names the law and courts for the Transfer Clauses. The English version of this Addendum controls.

Contact and our representative

How to contact us. For questions about this Addendum, email customersupport@nummbas.com. To report a security concern, email cyberteam@nummbas.com.
Our representative. Since September 30, 2026, DataRep (Data Protection Representative Limited, 77 Camden Street Lower, Dublin, D02 XE80, Ireland) has been our representative in the European Union, the European Economic Area, the United Kingdom and Switzerland. People and regulators there can email datarequest@datarep.com with "Nummbas" in the subject line or use the form at www.datarep.com/data-request. Our Privacy Policy lists DataRep's postal addresses.

Schedule 1: Details of the processing

How to read this schedule. Nummbas Books, PayPal and marketplace connections are covered where they are available on your account.

ItemDetails
Purpose and natureTo provide, secure and support the Services. We collect the data from the services you connect and from what you upload or enter, store and analyze it, and show it to you and your team. We send it to our AI providers for AI features such as Nummbas-FO answers, the daily brief and receipt reading, and we send the emails you ask for.
The people concernedYour customers, including shoppers, marketplace buyers and invoice recipients. Your suppliers and contractors. Your staff and other people named in your bank transactions, accounting records and documents. People you allow to email receipts to Nummbas Books.
Stores, payment services and marketplacesOrder and payment details, such as references, line items and amounts, and the country and the state or region of an order. For most platforms, a matching code in place of the shopper's email address, which we do not store as a field of the synced order or payment. From stores, discount codes and tracking numbers and, where Shopify or WooCommerce records them, the landing page, referrer and campaign details for an order. From BigCommerce, the customer ID in plain form. From Stripe, the description of each payment as your checkout wrote it, which can include a name or an email address.
Other connected servicesFrom shipping tools, the cost, carrier and tracking number of a shipment. From email marketing, support, returns and subscription tools, counts and totals only, though we read individual records during a sync. From banks, through Plaid, account names, the last digits of account numbers, balances, and transactions with their descriptions and the name of the other party. From QuickBooks and Xero, reports, transactions, supplier names with totals and unpaid bills and, if you import your accounts into Nummbas Books, your contacts and past entries.
Nummbas BooksNames, email addresses and postal addresses of your customers, suppliers and contractors, bank payee names and tax IDs. Invoices, bills, receipts and other documents, and emails sent to your Nummbas Books receipts address. For invoice emails, the recipient's address, the subject and whether the email was delivered. Online invoice payment attempts and, for Stripe and Square, the contact's email address, which we send to your own Stripe or Square account. Nummbas Books' own copies of synced records, which can hold a description, the name of the other party and, for a Stripe payment, the name on the shipping details or the card.
InventoryNames, email addresses, the extra email addresses you copy on purchase orders, phone numbers and postal addresses of your suppliers. For purchase order emails, the recipient's address, the subject and whether the email was delivered.
Nummbas-FOYour questions, conversation history and memory notes, the files you attach and the reports it generates. The business data needed to answer a question, which can include orders, bank costs, and the names of your contractors, customers and suppliers with amounts paid or owed. We do not send AI providers matching codes, or shopper email addresses from your synced orders and payments.
Share links and invoice payment pagesThe number of views of a share link and the time of the last one, not who opened it. Page performance, click and error data from these pages, while the visitor has analytics tools on in Cookie preferences.
Sensitive dataWe do not ask for special categories of personal data, such as health information, though bank transactions and documents can reveal them. Nummbas Books can hold US Social Security numbers for contractors.
How long we keep itThe transfer and the processing are continuous while your account is open. Synced data is kept while the connection exists, or for 25 days if a marketplace connection loses its access and is not reconnected. Stock records you create in Inventory, such as deliveries, counts and purchase orders, are kept when a store is disconnected, because they are your business's own records. Files attached in Nummbas-FO and reports it generates are kept for 7 days. Nummbas Books records are accounting records with no set expiry. Everything else is kept until you delete it or the account is deleted, as section 11 describes.

Schedule 2: Security measures

How to read this schedule. These are the measures we use on the effective date of this Addendum.

AreaWhat we do
EncryptionYour data is encrypted in transit between your browser or the mobile apps and our servers, and between our application and its database. Our database and its backups, which our hosting provider keeps for 7 days, are encrypted at rest. We separately encrypt the access tokens for the services you connect. Nummbas Books encrypts a tax ID when it is saved, and keeps its type and last four characters readable.
Sign-inPasswords must be at least 12 characters and are stored only in a scrambled form that cannot be reversed. Two-factor authentication is turned on when an account owner signs up and when a team member accepts an invitation, and users cannot turn it off.
Separation between businessesAccess checks in the application keep each business's records separate. For requests made by signed-in users, database rules also limit each query to that user's business on most tables that hold a business's records.
AccessFour roles limit what each member of your team can see and do. Our own access is limited to authorized staff. Staff who hold our highest admin role can open your account as the account owner, for up to 15 minutes at a time, to troubleshoot, and we log each time they do. Staff who operate our systems can reach the database and logs to run, secure and repair the Services.
LogsWe keep a security activity log and a staff log for 12 months.

Schedule 3: Transfer Clauses

When this schedule applies. This schedule applies where section 13 says the Transfer Clauses apply.
ItemSelection
ModuleModule Two (controller to processor).
Clauses 7 and 11The optional wording is not used.
Clause 9 (Subprocessors)Option 2, general written authorization. The notice period is 30 days, or the shorter period section 7 allows for an urgent replacement.
Clause 13 and Annex I.CThe supervisory authority that Clause 13 identifies for your situation.
Clauses 17 and 18Option 1. The law of Ireland and the courts of Ireland.
Annex I.A (the parties)You are the data exporter and a controller, with the details on your Nummbas account. We are the data importer and a processor. Our details are in section 1 and section 17, with our representative's.
Annex I.B and Annex IISchedule 1 and Schedule 2. Subprocessors process the data for the purposes on the Subprocessor List, for as long as we process it for you.
UK AddendumTable 1: as Annex I.A, starting when the Transfer Clauses take effect for you under section 13. Tables 2 and 3: the Standard Contractual Clauses with the selections above, Schedule 1, Schedule 2 and the Subprocessor List. Table 4: either of us may end the UK Addendum as its terms allow.
SwitzerlandReferences to the GDPR are read as references to the Swiss Federal Act on Data Protection. The Swiss Federal Data Protection and Information Commissioner supervises the part of a transfer that Swiss law governs. "Member State" is not read in a way that stops people in Switzerland from claiming their rights there.