Privacy Policy
We process invoices, bank statements and identity documents, so privacy is part of the product, not an afterthought. This page explains what we collect, why, and how long we keep it.
01What this policy covers
This policy explains how we handle two kinds of information: account data about the people who use the service, and the documents and extracted data that customers process through it. For customer documents, the customer decides what is processed and why, and we act on their instructions as a processor.
02Information we collect
- Account details: name, work email, company, designation, industry and team size given at signup or in a sales inquiry.
- Usage data: pages processed, features used, reviewer actions, login times, IP address and browser type.
- Customer documents: files you upload, such as invoices, purchase orders, bank statements, ID and address proofs and shipping papers.
- Extracted data: the fields, line items, transactions and confidence scores produced from those documents, and review history.
- Billing data: billing contact, tax registration details and payment records. Card details are held by our payment provider, not by us.
03How we use it
- To read, extract, review, approve and export documents as configured by the customer.
- To create and secure accounts, send login credentials and service messages.
- To measure page usage for billing and to send usage alerts.
- To provide support and investigate errors or misuse.
- To improve accuracy for the customer’s own account, for example learning a regular vendor’s invoice layout.
Customer documents and extracted data are never used to train models for other customers, and are never sold or used for advertising.
04Identity documents and consent
ID and address proofs are processed only where the customer confirms that the individual has given consent for a stated purpose. A consent record with purpose, time and retention is stored with each KYC file.
ID numbers are masked by default. Full values can be revealed only by roles the customer permits, and every reveal is logged. We do not use identity documents for any purpose other than the customer’s stated purpose.
05Retention and deletion
Customer documents and extracted data are kept for the retention period the customer sets, then deleted from active systems. Backups containing deleted data are overwritten within 30 days. Trial documents are deleted when the trial ends unless the trial converts to a paid plan.
Account and billing records are kept for as long as the account is active and afterwards as required by tax and accounting law.
06How we protect data
- Encryption in transit (TLS) and at rest.
- Role-based access for customer users, with masking of sensitive fields.
- Restricted, logged access for our own staff, granted only for support or operations the customer has requested.
- Audit trails on review, approval, export and reveal actions.
08Your choices and rights
You can ask to access, correct or delete your account data, or withdraw consent for marketing messages at any time. Where we process documents for a customer, requests from the people named in those documents are passed to that customer, who decides how to respond. To make a request, write to us through the Connect with sales page.
10Changes to this policy
If we change how we handle personal data in a material way, we will notify account owners by email before the change applies.