About this summary
This page summarizes the data processing agreement (DPA) that SS Support Network LLC, trading through its LedgerBPO division, signs with clients whose engagements involve personal data. It is written so that a business owner, practice manager or compliance lead can see the main commitments without reading the full document.
This page is a summary only. It is not the agreement. The executed DPA, together with the master services agreement and any statement of work, governs the relationship, and if anything here differs from the signed documents, the signed documents control. A copy of the full DPA template is available on request before you sign anything.
Roles
The client is the controller (or “business” under US state privacy laws). The client decides why and how personal data is processed, and owns the data and the systems it lives in.
LedgerBPO is the processor (or “service provider”). We process personal data only on the client’s documented instructions, inside the client’s own software, and only for the purpose of delivering the contracted services. Where an accounting firm engages us to support its own clients, the firm remains the controller or processor towards its clients, and we act as the firm’s sub-processor.
Subject matter, duration, nature and purpose
The subject matter is the accounting, bookkeeping, invoicing, accounts receivable, accounts payable, reconciliation, month-end close, reporting, payroll support and billing-call services described in the statement of work.
The duration is the term of the services agreement, plus the wind-down period needed to return or delete data.
The nature of the processing is access, viewing, recording, organization, matching, correction, retrieval, transmission to the client and, at the end, deletion. We do not make automated decisions about individuals and we do not use client data to train models or for our own purposes.
The purpose is to keep the client’s financial records current and correct, to bill and collect what the client is owed, to pay what the client approves, and to report to the client.
Categories of data and data subjects
Depending on the service, personal data may include names, business and personal contact details, invoice and payment history, bank account details visible in feeds and statements, payroll data such as salary, tax identifiers and deductions, and, for healthcare billing, patient names, dates of birth, insurance identifiers and treatment or trip details that are protected health information.
Data subjects may include the client’s employees and contractors, customers and their contacts, vendors and their contacts, patients or service users, and, for accounting-firm engagements, the firm’s own clients.
Special category, sensitive or health data is processed only where the service requires it and only with the additional safeguards the DPA sets out, including a business associate agreement for US healthcare clients.
Our obligations as processor
We process personal data only on the client’s documented instructions, including on international transfers, unless the law requires otherwise, in which case we tell the client before processing where the law allows.
Everyone who accesses client data is bound by confidentiality. Staff sign a confidentiality agreement on joining, and we sign a client-specific NDA where the client requires one. Access is limited to the named accountant or billing agent, the backup and the team lead assigned to the account, plus quality reviewers where the Two-Tier Review applies.
We maintain technical and organizational security measures appropriate to the risk. The core measures are:
- Multi-factor authentication on every account used to reach client data.
- Least-privilege access: staff see only the clients and functions assigned to them, and access is removed the day an assignment ends.
- Access logs kept for logins and, where the client’s software supports it, for actions taken.
- Encryption in transit and at rest for data we hold, and use of the client’s own encrypted platforms for everything else.
- Managed devices with disk encryption, endpoint protection and remote wipe.
- No local downloads of client data; work is done inside the client’s systems or our secured environment.
- Background checks on all staff before they are assigned to client work.
- A per-client NDA on request, and HIPAA training for staff on healthcare accounts.
- Read-only bank feeds wherever the client’s bank and software allow it; we never hold payment authority.
- A documented incident response plan that is tested.
Certifications are listed on our security page only when they are held.
Sub-processors
We use a small number of sub-processors. The client is told which ones apply at signing and is notified before any change, with the right to object.
Affiliates: SS Support Network LLC operates a second office in Pakistan, where part of the delivery team is based. Staff at that office are employed under the same confidentiality, background-check and security requirements as the US team. Our sister brands, SS Support Network (healthcare BPO) and TransportBPO (ground-transportation BPO), share management and systems and may be treated as affiliates for this purpose.
Cloud and tooling providers: website hosting by Hostinger (data centers in the United States and Europe); analytics and tag management by Google (Google Analytics 4, Google Tag Manager) and Microsoft (Clarity), loaded only after consent; call booking by Calendly; bot protection on forms by Cloudflare Turnstile. Business email, document storage and communication tools are listed with their locations in the sub-processor schedule attached to each signed DPA.
The client’s own software (QuickBooks Online, Xero, Zoho Books, Sage, Bill.com, Karbon, clearinghouses and similar) is contracted by the client, not by us, and is not our sub-processor.
International transfers
Client data will be accessed from the United States and from our second office in Pakistan. The DPA includes the transfer mechanism that applies to the client’s jurisdiction.
For UK clients, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses is incorporated, supported by a transfer risk assessment. For EU clients, the EU Standard Contractual Clauses (controller-to-processor module, or processor-to-processor for accounting firms) are incorporated with the same assessment.
For Australian clients, the DPA records the disclosure to our second office in Pakistan and to US providers under Australian Privacy Principle 8, and binds us to handle the data in line with the Australian Privacy Principles. For Canadian clients, the DPA supports the client’s accountability under PIPEDA and, for Quebec clients, provides the information needed for the client’s privacy impact assessment under Law 25.
For US clients, the DPA includes the service-provider terms required by the CCPA/CPRA and comparable state laws.
Assistance to the client
We help the client respond to data subject requests received about data we process, within the time the client needs to meet its own deadline. We help with data protection impact assessments, transfer risk assessments and regulator enquiries where our processing is in scope. We tell the client promptly if an instruction appears to breach applicable data protection law.
Deletion and return
At the end of the engagement, the client chooses return or deletion. Because we work inside the client’s systems, most data never leaves them; we simply remove our users. Working papers, reconciliation files and correspondence that we hold are returned in a standard format and then deleted from our systems within 30 days and from rolling backups within a further 30 days, unless the law requires us to keep a copy. We confirm deletion in writing on request.
Audits and information requests
The client may ask for the information needed to demonstrate compliance with the DPA, including our security policies, staff training records and sub-processor list. The client, or an auditor it appoints who is bound by confidentiality, may audit our processing on reasonable notice, no more than once a year unless a regulator requires it or a breach has occurred. Audits are carried out remotely or at our offices during business hours and must not disrupt other clients’ data.
Breach notification
We notify the client without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the client’s data. The notice describes what happened, the data and people affected as far as known, the likely consequences and the steps taken. We then cooperate with the client on its own notifications to regulators and individuals.
HIPAA and healthcare clients
For US healthcare clients, including home care, NEMT, medical practices, DME and dental, we sign a business associate agreement (BAA) as a separate document. The BAA sits alongside the DPA and sets out the permitted uses and disclosures of protected health information, safeguards, breach reporting and termination terms required by HIPAA. Our healthcare staff are HIPAA trained.
Liability and term
Liability under the DPA is governed by the liability provisions of the master services agreement. The DPA lasts as long as we process personal data for the client and survives termination of the services agreement until all data is returned or deleted.
Getting the full document
To receive the full DPA template, the BAA template or our sub-processor list, email privacy@ledgerbpo.com or ask your sales contact. Questions about how the DPA applies to your country can also go to our Compliance Desk.