Legal

Data Processing Terms

The terms governing Tockly’s processing of Customer Data for subscribing businesses.

Last updated 13 September 2026

1. Scope and roles

These Data Processing Terms form part of the Tockly Terms of Use. They apply where a customer supplies personal information about invoice contacts, debtors or reminder recipients. The customer determines the purpose and instructions for that Customer Data and Tockly processes it to provide the service.

2. Instructions

Tockly will process Customer Data to import and organise records, store attachments, schedule and deliver reminders, record responses, support integrations, secure the service, provide support and comply with law. The customer’s use and configuration of Tockly are its documented instructions.

3. Customer responsibilities

The customer must ensure its instructions are lawful, its data is accurate and proportionate, recipients are authorised or lawfully contactable, and any required privacy notices are given. The customer must not use Tockly for harassment, deceptive messaging, unlawful debt collection or unsolicited promotion.

4. Confidentiality and security

Tockly limits access to people and providers who need it to perform or secure the service. Tockly uses reasonable safeguards described on the Security & Data page and requires people acting under its authority to protect confidential information.

5. Service providers

The customer authorises Tockly to use the providers identified in the Privacy Policy, currently including OpenAI, Cloudflare, Resend, Microsoft, GoDaddy, ExchangeRate-API, Xero, MYOB and Intuit where connected. Tockly will update its public information before adding a provider that materially changes the processing of Customer Data.

6. Overseas processing

Providers may process Customer Data through infrastructure outside New Zealand. Tockly will take reasonable steps required by applicable law for overseas disclosures. Customers remain responsible for determining whether their own instructions require additional local safeguards.

7. Rights requests and incidents

Taking account of the nature of the processing, Tockly will provide reasonable assistance with verified privacy-rights requests concerning Customer Data. Tockly will investigate suspected breaches and notify affected customers where required or where customer action is reasonably needed.

8. Return and deletion

Customers can delete active invoices, contacts and attachments using available controls. Paid invoices, their attachments and their invoice-specific activity history are automatically removed from active storage 30 days after payment is recorded. On verified account closure, processing stops except for restricted recovery, security, dispute and legal purposes. Retention and recovery periods are described in the Privacy Policy.

9. Information and review

Tockly will provide information reasonably necessary to demonstrate compliance with these Terms, subject to confidentiality, security and proportionality. Requests should first use available documentation and be sent to contact@tockly.ai.