Effective 4 October 2026.
1. Scope and roles
These Data Processing Terms form part of the Tockly Terms of Use. They apply where a customer supplies personal information about invoice contacts, debtors, reminder recipients, horse owners, staff, suppliers or other people recorded in a workspace. The customer determines the purpose and instructions for that Customer Data and Tockly processes it to provide the service.
2. Instructions
The subject matter is Customer Data handled to provide the subscribing business’s selected Tockly features for the account’s duration and the retention periods in the Privacy Policy. Processing includes collection, organisation, storage, retrieval, AI-assisted proposal or transcription, communication, export and deletion. Instructions include authorised integrations, customer-selected Capture images or dictation, invoice and reminder workflows, animal records, calendar entries, notes, report sharing, statements and support. The customer’s lawful use and configuration are documented instructions. Data types and categories of people are described in the Privacy Policy; these may include customers, debtors, owners, staff, suppliers and recipients. We will inform the customer if, in our opinion, an instruction infringes applicable data-protection law, and need not execute an unlawful instruction.
3. Customer responsibilities
The customer must ensure its instructions are lawful, its data is accurate and proportionate, recipients are authorised or lawfully contactable, and any required privacy notices are given. The customer must not use Tockly for harassment, deceptive messaging, unlawful debt collection or unsolicited promotion.
4. Confidentiality and security
Tockly limits access to people and providers who need it to perform or secure the service. Tockly uses reasonable safeguards described on the Security & Data page and requires people acting under its authority to protect confidential information.
5. Service providers
The customer authorises Tockly to use the providers identified in the Privacy Policy, including OpenAI, Cloudflare, Resend, ClickSend, Microsoft, Google, GoDaddy, ExchangeRate-API, Stripe, Xero, MYOB and Intuit, and Meta where an available WhatsApp connection is expressly used. Processor access must be limited to the contracted purpose and appropriate confidentiality, security and data-protection obligations. Where required by applicable processor law, we will give prior notice of a new or replacement subprocessor and a reasonable opportunity to object on data-protection grounds before the change takes effect. Contact contact@tockly.ai to raise an objection; we will seek a reasonable alternative and explain available cancellation options if the objection cannot be resolved. We remain responsible for the obligations of our subprocessors to the extent required by applicable law.
6. Overseas processing
Overseas processing must comply with the safeguards described in the Privacy Policy, including New Zealand comparable-protection requirements and EU, UK or Australian transfer rules where applicable. Processing and international transfers must remain within lawful documented instructions. Provider terms do not displace Tockly’s own applicable duties. Customers may request information about relevant safeguards; additional arrangements needed for a particular customer must be agreed before restricted processing is undertaken.
7. Rights requests and incidents
Taking account of the nature of processing and information available to us, we will reasonably assist customers with access, correction, erasure, restriction, portability and objection requests; security duties; breach notifications; and required impact assessments or regulator consultations. We will notify the customer without undue delay after becoming aware of a personal-data breach affecting its Customer Data, provide available information and cooperate on containment and required notices. This does not shift either party’s statutory notification duties to the other.
8. Return and deletion
Customers can delete active invoices, contacts, attachments and Capture worksheets using available controls. Deleting a Capture worksheet does not reverse charges already approved into other records. Paid invoices imported from a connected accounting service, their attachments and their invoice-specific activity history are ordinarily removed from active storage 30 days after payment is recorded. Removing an issued Tockly invoice from the workspace archives it while the account exists; permanent account deletion can remove that archive. Customers must export the tax, clinical and audit records they are required to keep before permanent deletion. On verified account closure, processing stops except for restricted recovery, security, dispute and legal purposes. Retention and recovery periods are described in the Privacy Policy.
9. Information and review
Tockly will provide information reasonably necessary to demonstrate compliance with these Terms, subject to confidentiality, security and proportionality. Requests should first use available documentation and be sent to contact@tockly.ai.
At the customer’s choice on termination, we will return or delete Customer Data, using available exports or a verified request, except information law requires us to retain. Obtain exports before permanent account deletion. Issued invoices hidden from the workspace remain archived while the account exists; permanent deletion can remove them. Backups and legal exceptions follow the Privacy Policy. People authorised to process Customer Data must be bound to confidentiality. We will make information necessary to demonstrate compliance available and allow proportionate audits or inspections required by applicable processor law, subject to reasonable arrangements protecting other customers, security and confidentiality.