
Pyro
This DPA explains what Pyro does with personal data that reaches it through your use of the service, and what Pyro promises you about it. It is written to be readable. Where a term has a specific legal meaning under the GDPR, that meaning applies.
This DPA forms part of, and is subject to, the Pyro Terms and Conditions (the Agreement). If this DPA and the Agreement conflict on the subject of personal data, this DPA wins.
Processor: Trevor St. John, an individual trading as "Pyro" Based in Malta. Postal address available on request. Contact for data protection matters: support@pyroplatform.com
Customer: the accounting firm, business or other organisation that has accepted this DPA through the Pyro application, as identified by the firm record and the accepting user recorded at the time of acceptance.
Together, the Parties.
Terms not defined here have the meaning given in the GDPR.
| Term | Meaning |
|---|---|
| GDPR | Regulation (EU) 2016/679, and where applicable the UK GDPR and the Data Protection Act (Cap. 586, Laws of Malta). |
| Personal Data | Any information relating to an identified or identifiable natural person that Pyro processes on Customer's behalf under the Agreement. |
| Customer Data | All data Customer or its Authorised Users submit to Pyro, or that Pyro retrieves from a connected Xero organisation at Customer's instruction — including uploaded invoices and bills, extracted values, and accounting records. |
| Client | An end client of the Customer whose accounting records the Customer processes using Pyro. |
| Subprocessor | A third party engaged by Pyro that processes Personal Data in order to deliver the service. |
| Authorised User | An individual the Customer has invited to its firm in Pyro. |
| Applicable Data Protection Law | The GDPR and any other data protection law applicable to a Party's processing. |
3.1 In respect of Personal Data, Customer is the controller (or, where Customer is itself acting as a processor for its own Clients, Customer is a processor and Pyro is a subprocessor). Pyro acts as processor on Customer's behalf in either case.
3.2 Customer is responsible for establishing a lawful basis for the processing, for the accuracy and lawfulness of the Customer Data it submits, and — where Customer acts as a processor for its Clients — for having the authority from those Clients to engage Pyro as a subprocessor.
3.3 Pyro determines the means by which it delivers the service (its architecture, its choice of infrastructure providers and AI models) but does not determine the purposes of the processing. Pyro does not use Customer Data for its own purposes.
3.4 Each Party complies with its own obligations under Applicable Data Protection Law.
Subject matter. Automated reading of invoices, bills and related accounting documents submitted by the Customer; proposing an accounting classification and VAT treatment for each line; and, where the Customer instructs it, creating draft entries in the Customer's connected Xero organisation.
Duration. For as long as Customer's account is active, and thereafter only as described in section 13 (Deletion and return).
Nature of the processing. Collection, storage, structuring, analysis (including analysis by third-party AI models — see section 8), retrieval, transmission to Xero at Customer's instruction, and erasure.
Purpose. Solely to provide the service described in the Agreement, and to comply with Pyro's legal obligations.
Pyro does not ask for special category data and the service is not designed to receive it. In practice the following Personal Data reaches Pyro:
From Authorised Users (Customer's own people)
From documents Customer uploads Whatever appears on the face of an invoice or bill, which typically includes:
From a connected Xero organisation
Categories of data subject: Customer's Authorised Users; Customer's Clients; and the suppliers, customers, employees and representatives of those Clients whose details appear on processed documents.
Note: because the personal data arrives inside accounting documents rather than through structured fields, Pyro cannot fully predict or control what a given document contains. Customer should not upload documents containing special category data (health, biometric, political, religious or similar) or criminal offence data, as the service is not designed for it.
6.1 Pyro processes Personal Data only on Customer's documented instructions. The Agreement, this DPA, and Customer's use of the application's own features together constitute those instructions.
6.2 Pyro will tell Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend that processing until the issue is resolved.
6.3 If Pyro is required by EU or member state law to process Personal Data beyond Customer's instructions, Pyro will inform Customer of that requirement before processing, unless the law forbids it on important grounds of public interest.
7.1 Pyro keeps Personal Data confidential and does not disclose it except as this DPA allows, or where legally compelled.
7.2 Pyro is currently operated by a single individual. Access to production systems is limited to that individual. Any person Pyro later gives access to Personal Data will be bound by written confidentiality obligations and given access only to the extent needed.
7.3 Pyro does not sell Customer Data, does not share it for advertising, and does not use it to train its own or anyone else's models.
8.1 Customer generally authorises Pyro to engage the Subprocessors listed below. Pyro remains fully liable to Customer for their performance.
8.2 Current Subprocessors
| Subprocessor | What it does | Personal Data it handles | Where |
|---|---|---|---|
| Supabase (Supabase Inc.) | Database and encrypted file storage — the system of record | All stored Customer Data, including uploaded documents | AWS eu-west-3, Paris, France (EU) |
| Vercel (Vercel Inc.) | Application hosting; runs Pyro's server code | All data in transit during a request; not stored persistently by Vercel | EU-proximate edge region; Vercel is US-headquartered |
| Anthropic (Anthropic PBC / Anthropic Ireland Ltd) | AI reading of invoice content — the "Nova" and "Atlas" tiers | The content of documents sent for reading | United States |
| OpenAI (OpenAI, L.L.C. / OpenAI Ireland Ltd) | AI reading of invoice content — the "Apex" tier | The content of documents sent for reading | United States |
| Google (Google LLC / Google Ireland Ltd) | AI reading of invoice content — the "Pulse" tier | The content of documents sent for reading | Not restricted to a single country or region — see 8.3 |
| Stripe (Stripe, Inc. / Stripe Payments Europe Ltd) | Subscription billing and wallet payments | Billing contact and payment data. Pyro never receives card numbers — Stripe collects them directly | United States / Ireland |
8.3 AI subprocessor commitments. Under the terms currently in force with each provider:
commercial API, and deletes API inputs and outputs within 30 days, other than content retained for safety or legal reasons.
retains API inputs and outputs for up to 30 days for abuse monitoring before deletion, unless legally required to retain them.
Services to improve its products. Unlike Anthropic and OpenAI, Google does not publish a fixed number of days for how long it retains this content — its terms state only that prompts and responses are logged "for a limited period of time" for abuse-detection purposes, and that content may be processed or cached "in any country in which Google or its agents maintain facilities" (i.e. not a US-only commitment the way Anthropic's and OpenAI's are).
Pyro does not currently hold a zero-data-retention arrangement with any of these three providers. Pyro does not claim that these providers store nothing.
Resolved, 2026-09-01. Pyro calls the Gemini API directly (generativelanguage.googleapis.com), which is governed by the Gemini API Additional Terms of Service (ai.google.dev/gemini-api/terms), not Google Cloud Platform's general terms — the Cloud DPA at cloud.google.com/terms/data-processing-addendum does not list the Gemini API among its covered services, so it does not apply here. The Gemini API Terms incorporate its own DPA (business.safety.google/processorterms) automatically by use, the same "applies by using the service" structure as Anthropic's — no separate signature or console toggle to complete, as confirmed against Google's own published terms.
8.4 Changes. Pyro will give Customer at least 30 days' notice before adding or replacing a Subprocessor, by email to the firm owner and by updating the published subprocessor list. Customer may object on reasonable data protection grounds within that period. If the Parties cannot resolve the objection, Customer may terminate the Agreement for the affected service without penalty, and receive a pro-rata refund of prepaid fees.
8.5 Xero is not a Subprocessor. Xero is the Customer's (or its Client's) own accounting system, under the Customer's own separate agreement with Xero. Pyro reads from and writes to it only at Customer's instruction, using a connection Customer authorises. Pyro is not sending Customer's data to a third party of Pyro's choosing when it posts a draft to Xero — it is returning data to Customer's own system.
⚠️ LAWYER REVIEW. The characterisation in 8.5 is reasonable but arguable; a cautious adviser might prefer to list Xero as a subprocessor anyway. Have this checked.
Pyro maintains the following technical and organisational measures. This list describes what is actually implemented — it is not aspirational.
Encryption
by the underlying cloud provider).
encrypted at the application layer using AES-256-GCM before being written to the database, so they are not readable from the database alone.
Access control
password system and stores no passwords.
permitting policies, so that only the server's privileged service credential can read or write. A leaked public API key yields no data.
is enforced in application code on every request.
the hosting platform and is not present in the source code.
Segregation of AI processing
provider workspace and API key, so that one firm's usage is separated from another's at the provider.
Logging and monitoring
changes, wallet adjustments) are written to an append-only log that the application never updates or deletes.
Data minimisation
Pyro does not transmit its wider database to them.
are not sent to any AI provider at all.
What Pyro does NOT currently claim Pyro is transparent about the limits of its current programme. Pyro does not hold ISO 27001 certification, has not completed a SOC 2 audit, has not undergone an independent penetration test, and does not operate a 24/7 staffed security team. Pyro is a small operation and says so rather than implying otherwise.
10.1 Customer Data is stored in the European Union (Paris, France).
10.2 Personal Data is transferred outside the EEA to the United States when a document is sent to Anthropic or OpenAI for reading, and in connection with hosting and payment services. When a document is sent to Google (the "Pulse" tier), the transfer is not confined to the United States — see 8.3.
10.3 These transfers rely on the Standard Contractual Clauses approved by the European Commission, incorporated into Pyro's agreements with all three AI providers — Anthropic, OpenAI and Google (see the resolution note at 8.3 for how Google's applies). Pyro will provide evidence of the executed terms on request.
10.4 Customer may reduce cross-border AI processing by asking Pyro to restrict its firm to the locally-processed extraction path, where the documents involved match learned supplier layouts. Pyro will tell Customer honestly what that means in practice for coverage.
11.1 Pyro will notify Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer's Personal Data.
11.2 The notification will describe, so far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point.
11.3 Pyro will provide reasonable assistance to Customer in meeting Customer's own notification duties to a supervisory authority or to data subjects.
11.4 Notification is not an admission of fault by either Party.
12.1 Data subject rights. Where a data subject contacts Pyro directly, Pyro will not respond substantively but will forward the request to Customer without undue delay. Pyro will assist Customer in responding to requests for access, rectification, erasure, restriction, portability and objection, using the application's own functions where possible.
12.2 DPIAs and consultation. Taking into account the nature of the processing and the information available to it, Pyro will provide reasonable assistance to Customer with data protection impact assessments and any prior consultation with a supervisory authority.
12.3 Pyro may charge a reasonable fee for assistance that is disproportionate or repetitive, having first told Customer and given Customer the chance to withdraw the request.
13.1 On request during the term. Customer may delete a client and its documents at any time from within the application. This removes the stored document files, the extracted data, the learned coding history and the audit trail for that client.
13.2 On termination. Within 30 days of the Agreement ending, Pyro will delete Customer's Personal Data, unless Customer asks in writing for it to be returned first, in which case Pyro will provide it in a commonly used electronic format before deleting.
13.3 Backups. Data may persist in encrypted infrastructure backups after deletion from the live system. Such data is not actively processed and is overwritten on the provider's ordinary backup cycle.
13.4 Legal retention. Pyro may retain Personal Data where required by law, and will tell Customer what it is retaining and why.
13.5 Automatic retention, set by Customer. Customer may set a retention period in the application, after which Pyro automatically deletes the stored source documents it uploaded. A daily job carries this out. Only the source file is deleted; the extracted accounting record — supplier, amounts, VAT treatment, coding — is kept, because that is Customer's own accounting data and the same source file is already attached to the corresponding draft in Customer's Xero organisation.
13.6 No retention period is set by default. Pyro does not choose a deletion policy on Customer's behalf. Until Customer sets a period, documents are kept until deleted under 13.1 or 13.2. This is deliberate: Customer is the controller, only Customer knows its own statutory retention obligations, and deleting a firm's records on an assumption would be a worse failure than keeping them. Customer can set, change or remove the period at any time; the shortest period Pyro accepts is 30 days.
14.1 Pyro will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including this document, its subprocessor list, and its internal data-hosting and incident-response statements.
14.2 Customer may, no more than once in any 12 months and on 30 days' written notice, request additional written information or a remote interview with the person operating Pyro. This is the realistic form of audit for an operation of Pyro's size; Pyro does not offer on-site inspection of its infrastructure providers, whose own audit reports Customer may request directly from them.
14.3 A supervisory authority's statutory audit powers are unaffected by 14.2.
15.1 Each Party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
15.2 Nothing in this DPA limits either Party's liability to a data subject under Article 82 GDPR, or any liability that cannot lawfully be limited.
⚠️ LAWYER REVIEW. Because Pyro is currently an individual rather than a limited company, liability under this DPA is personal and unlimited except as the Agreement limits it. This is a significant commercial exposure and should be reviewed before the DPA is offered to customers.
This DPA takes effect when Customer accepts it and continues for as long as Pyro processes Personal Data on Customer's behalf. Sections that by their nature should survive termination (confidentiality, deletion, liability) do so.
This DPA is governed by the laws of Malta, and the courts of Malta have exclusive jurisdiction, without prejudice to any mandatory rights a data subject has to bring proceedings elsewhere.
Data protection questions, data subject requests forwarded by Customer, and breach correspondence:
support@pyroplatform.com Trevor St. John, trading as Pyro Malta · postal address available on request
Customer may also complain to the Maltese supervisory authority, the Office of the Information and Data Protection Commissioner (IDPC), https://idpc.org.mt.
| Subject matter | Automated extraction and accounting classification of invoices and bills, and creation of draft entries in Customer's Xero organisation |
| Duration | Term of the Agreement, plus up to 30 days for deletion |
| Nature | Collection, storage, structuring, automated analysis, transmission, erasure |
| Purpose | Delivery of the Pyro service |
| Personal data | As set out in section 5 |
| Data subjects | Authorised Users; Customer's Clients; suppliers, customers and representatives appearing on processed documents |
| Controller | Customer (or Customer's Client, where Customer is itself a processor) |
| Processor | Trevor St. John trading as Pyro |
| Subprocessors | As set out in section 8.2 |
| Transfers | To the United States under Standard Contractual Clauses, as set out in section 10 |
Pyro DPA v1.2 — effective 1 September 2026. Superseded versions are retained and available on request.