Legal
Privacy policy
This policy explains what personal data Accruna collects, why we collect it, how long we keep it, who else processes it, and what you can ask us to do with it. It is written to be read rather than to be survived.
Effective date: 1 January 2026 · Last reviewed: 1 January 2026
1. Who we are
Accruna is an accounting firm that uses specialised software agents to maintain client ledgers, with experienced accountants responsible for judgement, review and sign-off. In this policy, "Accruna", "we", "us" and "our" refer to the Accruna firm operating the website at accruna.xyz.
For the personal data described in sections 3 and 4, we act as a data controller — we decide why and how that data is used. For the financial data described in section 6, we generally act as a processor on behalf of our client, who is the controller. That distinction matters, and section 6 explains it.
2. Scope of this policy
This policy covers:
- Visitors to this website, including anyone who submits an enquiry form
- Prospective clients who contact us, book a demo or request a security review
- Individuals at client organisations who interact with us during an engagement
- Individuals whose personal data appears incidentally in a client's accounting records
- Suppliers, contractors and partners we work with
It does not cover third-party websites we link to, or the separate privacy practices of our clients' own systems.
3. What we collect
Information you give us
- Contact details — name, work email, company name and role, submitted through our forms or by email
- Enquiry content — the message you write, plus any optional context such as transaction volume, entity count or systems used
- Demo scheduling information — your preferred timeline, who will attend, and any questions you want covered
- Documents you choose to share — for example a security questionnaire, a trial balance or a bank statement shown during a demo
- Correspondence — emails exchanged before, during or after an engagement
Information we collect automatically
- Technical data — IP address, browser type and version, operating system, screen size and language settings
- Usage data — pages viewed, referring pages and time on page, used in aggregate to understand which content is useful
- Server logs — request timestamps and response codes, retained for security and reliability purposes
Information we receive from others
- Referrals — if someone introduces you to us, we may receive your name and contact details from them
- Public professional information — a company website or public profile used to prepare for a conversation you have requested
Information we do not collect
- Special category data such as health, biometric or political data, unless it appears incidentally in a document you or a client provide
- Payment card numbers — we do not take payments through this website
- Bank credentials — our integrations use provider-authorised connections, never stored internet banking logins
4. Why we use it
| Purpose | Data used | Why |
|---|---|---|
| Responding to enquiries | Contact details, enquiry content | To answer your question and take the next step you asked for |
| Preparing and running demos | Scheduling information, context you provide | So the session is useful rather than generic |
| Providing accounting services | Client contact details, financial records | To perform the engagement you have contracted us for |
| Security reviews | Contact details, questionnaire responses | To answer procurement and assurance questions |
| Improving the website | Usage and technical data, aggregated | To see which pages help and which do not |
| Keeping our systems secure | Server logs, technical data | To detect abuse, debug faults and maintain availability |
| Meeting legal obligations | Records required by law | Accounting, tax, anti-money-laundering and professional record-keeping duties |
| Marketing to business contacts | Contact details | To share relevant product information where we have a lawful basis, with opt-out available in every message |
We do not sell personal data. We do not use client financial data to train third-party AI models. Section 7 sets out the limited circumstances in which data is shared with others.
5. Our legal bases
Where the GDPR or equivalent law applies, we rely on the following bases:
6. Client financial data
This is the most sensitive category we handle, so it is worth being precise about the roles involved.
When we provide accounting services, the client is the controller of the financial data and Accruna is the processor. We act only on the client's documented instructions, as set out in the engagement letter and the data processing terms attached to it.
In practice this means:
- We access client financial systems through connections the client authorises, scoped as narrowly as the work allows
- We do not use client financial data for our own purposes, for marketing, or to train models for other clients
- We do not disclose client financial data to third parties except to sub-processors necessary to deliver the service, or where legally compelled
- We notify the client without undue delay if we become aware of a personal data breach affecting their data
- We assist the client in responding to data subject requests relating to data we process on their behalf
If your personal data appears in a client's books — for example you are an employee, a customer or a supplier of theirs — the client is responsible for that data and for your requests about it. We will pass any request we receive to the relevant client and assist them in responding. You are welcome to contact us as well, and we will do what we can to help.
7. Who we share it with
We share personal data only in these circumstances:
| Recipient | What is shared | Safeguards |
|---|---|---|
| Infrastructure and hosting providers | Data stored or processed on our behalf | Contractual confidentiality and security terms; no use for their own purposes |
| Integration and connectivity providers | Only the data needed to establish and maintain authorised connections | Scoped credentials, encrypted storage, revocable at any time |
| Professional advisers | Information necessary for legal, regulatory or audit advice | Professional confidentiality obligations |
| Your own advisers | Only where you instruct us to share it | Your instruction is the basis; scoped access where possible |
| Authorities and regulators | Only what is legally required | We assess each request for legal validity and notify you unless prohibited |
| A successor entity | Data relevant to a merger or acquisition of our business | Continued protection under this policy, with notice of any change |
A current list of sub-processors is available on request, along with the purpose and location of each. We will tell you before adding a sub-processor that affects your data.
8. How long we keep it
Retention is driven by what the data is for and by record-keeping obligations that apply to an accounting firm.
Where a client's engagement ends, we revoke all credentials, export any working data to the client on request, and confirm deletion in writing once the retention period has elapsed.
9. Security
We apply the controls described on our security page, which include:
- Encryption of data in transit and at rest
- Role-based, least-privilege access for people and software agents alike
- An audit trail recording actor, timestamp and before-and-after values
- Human approval requirements for payments, journal postings and policy overrides
- Credential revocation on role change, departure or connection retirement
No system is perfectly secure. If a breach occurs that affects your personal data, we will notify affected parties and the relevant authority where required, without undue delay, and we will tell you what happened rather than only what we are obliged to disclose.
10. International transfers
We aim to keep data within the region agreed during scoping. Where a transfer outside your region is necessary — for example because a sub-processor operates there — we put appropriate safeguards in place, such as standard contractual clauses, and we will tell you the destination and the safeguard used.
Specific residency requirements should be raised before contracting. They are usually accommodating, but they affect architecture and should not be a mid-engagement surprise.
11. Your rights
Depending on where you are, you may have the right to:
- Access the personal data we hold about you and receive a copy
- Correct data that is inaccurate or incomplete
- Erase data where there is no continuing lawful reason for us to hold it
- Restrict processing while a dispute about accuracy or lawfulness is resolved
- Object to processing based on legitimate interests, including direct marketing
- Port data you provided to us, in a structured machine-readable format
- Withdraw consent at any time where consent is the basis for processing
- Complain to your local data protection authority
To exercise any of these, email hello@accruna.xyz. We will respond within the timeframe required by applicable law, normally within 30 days. We may ask you to verify your identity, and we will tell you if a legal record-keeping obligation prevents us from fulfilling a request in full.
Where your data appears in a client's accounting records, we will forward your request to that client, since they are the controller of it.
12. Cookies and analytics
This website is deliberately light on tracking. We do not use advertising cookies, and we do not sell or share data with ad networks.
- Essential storage — a browser session value that remembers whether you dismissed the announcement bar. This is functional only and is not used for tracking.
- Aggregate analytics — if aggregate measurement is enabled, it is configured to avoid identifying individuals and is not combined with the contact details you submit.
You can block or clear cookies and local storage through your browser settings. The website will continue to work; you may simply see the announcement bar again.
13. Children
This website and our services are intended for businesses and their representatives. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Automated processing
Accruna uses software agents extensively, so it is worth being clear about what that means for individuals.
- Agents assist with categorising transactions, matching balances and preparing analyses in client accounting records. These are business records, not profiles of individuals.
- Agents may identify anomalies in expense claims, such as a missing receipt or spend outside a client's policy. The outcome is a review request routed to a named human — an agent cannot approve or reject a claim, and cannot impose a consequence on an individual.
- We do not use automated processing to make decisions with legal or similarly significant effects about individuals, and we do not build behavioural profiles of individuals for marketing.
Where a client uses our output in a decision about one of their people, the client is the decision-maker and is responsible for the lawfulness of that decision.
15. Changes to this policy
We review this policy at least annually and whenever our practices change materially. The effective date at the top of this page always reflects the current version. If a change materially affects how we handle personal data, we will make that clear on this page and, where appropriate, notify clients directly.
16. How to contact us
For any question about this policy, a request relating to your personal data, or a security concern:
- Emailhello@accruna.xyz
- Websiteaccruna.xyz
- Contact formaccruna.xyz/contact.html
- Security enquiriesaccruna.xyz/security.html
If you are not satisfied with our response, you have the right to complain to the data protection authority in your jurisdiction.
Questions about this policy?
We will answer privacy and data handling questions in writing, including anything your procurement or legal team needs documented.