Legal

Privacy policy

This policy explains what personal data Accruna collects, why we collect it, how long we keep it, who else processes it, and what you can ask us to do with it. It is written to be read rather than to be survived.

Effective date: 1 January 2026  ·  Last reviewed: 1 January 2026

1. Who we are

Accruna is an accounting firm that uses specialised software agents to maintain client ledgers, with experienced accountants responsible for judgement, review and sign-off. In this policy, "Accruna", "we", "us" and "our" refer to the Accruna firm operating the website at accruna.xyz.

For the personal data described in sections 3 and 4, we act as a data controller — we decide why and how that data is used. For the financial data described in section 6, we generally act as a processor on behalf of our client, who is the controller. That distinction matters, and section 6 explains it.

2. Scope of this policy

This policy covers:

  • Visitors to this website, including anyone who submits an enquiry form
  • Prospective clients who contact us, book a demo or request a security review
  • Individuals at client organisations who interact with us during an engagement
  • Individuals whose personal data appears incidentally in a client's accounting records
  • Suppliers, contractors and partners we work with

It does not cover third-party websites we link to, or the separate privacy practices of our clients' own systems.

3. What we collect

Information you give us

  • Contact details — name, work email, company name and role, submitted through our forms or by email
  • Enquiry content — the message you write, plus any optional context such as transaction volume, entity count or systems used
  • Demo scheduling information — your preferred timeline, who will attend, and any questions you want covered
  • Documents you choose to share — for example a security questionnaire, a trial balance or a bank statement shown during a demo
  • Correspondence — emails exchanged before, during or after an engagement

Information we collect automatically

  • Technical data — IP address, browser type and version, operating system, screen size and language settings
  • Usage data — pages viewed, referring pages and time on page, used in aggregate to understand which content is useful
  • Server logs — request timestamps and response codes, retained for security and reliability purposes

Information we receive from others

  • Referrals — if someone introduces you to us, we may receive your name and contact details from them
  • Public professional information — a company website or public profile used to prepare for a conversation you have requested

Information we do not collect

  • Special category data such as health, biometric or political data, unless it appears incidentally in a document you or a client provide
  • Payment card numbers — we do not take payments through this website
  • Bank credentials — our integrations use provider-authorised connections, never stored internet banking logins

4. Why we use it

Purposes for processing personal data
Purpose Data used Why
Responding to enquiriesContact details, enquiry contentTo answer your question and take the next step you asked for
Preparing and running demosScheduling information, context you provideSo the session is useful rather than generic
Providing accounting servicesClient contact details, financial recordsTo perform the engagement you have contracted us for
Security reviewsContact details, questionnaire responsesTo answer procurement and assurance questions
Improving the websiteUsage and technical data, aggregatedTo see which pages help and which do not
Keeping our systems secureServer logs, technical dataTo detect abuse, debug faults and maintain availability
Meeting legal obligationsRecords required by lawAccounting, tax, anti-money-laundering and professional record-keeping duties
Marketing to business contactsContact detailsTo share relevant product information where we have a lawful basis, with opt-out available in every message

We do not sell personal data. We do not use client financial data to train third-party AI models. Section 7 sets out the limited circumstances in which data is shared with others.

Where the GDPR or equivalent law applies, we rely on the following bases:

Contract
To take steps before entering an engagement and to perform it once agreed — including running demos, scoping, onboarding and delivering the accounting service.
Legitimate interests
To respond to business enquiries, keep our systems secure, improve the website, and communicate with business contacts in a way they would reasonably expect. We balance these against your rights and honour opt-outs promptly.
Legal obligation
To keep records required by accounting, tax, anti-money-laundering and professional regulation, and to respond to lawful requests from authorities.
Consent
Where we ask for it specifically — for example, where a client consents to being named as a reference. Consent can be withdrawn at any time.

6. Client financial data

This is the most sensitive category we handle, so it is worth being precise about the roles involved.

When we provide accounting services, the client is the controller of the financial data and Accruna is the processor. We act only on the client's documented instructions, as set out in the engagement letter and the data processing terms attached to it.

In practice this means:

  • We access client financial systems through connections the client authorises, scoped as narrowly as the work allows
  • We do not use client financial data for our own purposes, for marketing, or to train models for other clients
  • We do not disclose client financial data to third parties except to sub-processors necessary to deliver the service, or where legally compelled
  • We notify the client without undue delay if we become aware of a personal data breach affecting their data
  • We assist the client in responding to data subject requests relating to data we process on their behalf

If your personal data appears in a client's books — for example you are an employee, a customer or a supplier of theirs — the client is responsible for that data and for your requests about it. We will pass any request we receive to the relevant client and assist them in responding. You are welcome to contact us as well, and we will do what we can to help.

7. Who we share it with

We share personal data only in these circumstances:

Categories of recipients
Recipient What is shared Safeguards
Infrastructure and hosting providersData stored or processed on our behalfContractual confidentiality and security terms; no use for their own purposes
Integration and connectivity providersOnly the data needed to establish and maintain authorised connectionsScoped credentials, encrypted storage, revocable at any time
Professional advisersInformation necessary for legal, regulatory or audit adviceProfessional confidentiality obligations
Your own advisersOnly where you instruct us to share itYour instruction is the basis; scoped access where possible
Authorities and regulatorsOnly what is legally requiredWe assess each request for legal validity and notify you unless prohibited
A successor entityData relevant to a merger or acquisition of our businessContinued protection under this policy, with notice of any change

A current list of sub-processors is available on request, along with the purpose and location of each. We will tell you before adding a sub-processor that affects your data.

8. How long we keep it

Retention is driven by what the data is for and by record-keeping obligations that apply to an accounting firm.

Enquiries that do not proceed
Retained for up to 24 months so we can pick up the thread if you return, then deleted.
Demo records and correspondence
Retained for up to 24 months from the last contact, then deleted unless an engagement begins.
Client engagement records
Retained for the engagement plus the period required by applicable professional and tax record-keeping rules, after which they are deleted or returned.
Website logs
Retained for a short period for security and troubleshooting, then deleted or aggregated.
Marketing preferences
Kept until you opt out, plus a minimal suppression record so we do not contact you again in error.

Where a client's engagement ends, we revoke all credentials, export any working data to the client on request, and confirm deletion in writing once the retention period has elapsed.

9. Security

We apply the controls described on our security page, which include:

  • Encryption of data in transit and at rest
  • Role-based, least-privilege access for people and software agents alike
  • An audit trail recording actor, timestamp and before-and-after values
  • Human approval requirements for payments, journal postings and policy overrides
  • Credential revocation on role change, departure or connection retirement

No system is perfectly secure. If a breach occurs that affects your personal data, we will notify affected parties and the relevant authority where required, without undue delay, and we will tell you what happened rather than only what we are obliged to disclose.

10. International transfers

We aim to keep data within the region agreed during scoping. Where a transfer outside your region is necessary — for example because a sub-processor operates there — we put appropriate safeguards in place, such as standard contractual clauses, and we will tell you the destination and the safeguard used.

Specific residency requirements should be raised before contracting. They are usually accommodating, but they affect architecture and should not be a mid-engagement surprise.

11. Your rights

Depending on where you are, you may have the right to:

  • Access the personal data we hold about you and receive a copy
  • Correct data that is inaccurate or incomplete
  • Erase data where there is no continuing lawful reason for us to hold it
  • Restrict processing while a dispute about accuracy or lawfulness is resolved
  • Object to processing based on legitimate interests, including direct marketing
  • Port data you provided to us, in a structured machine-readable format
  • Withdraw consent at any time where consent is the basis for processing
  • Complain to your local data protection authority

To exercise any of these, email hello@accruna.xyz. We will respond within the timeframe required by applicable law, normally within 30 days. We may ask you to verify your identity, and we will tell you if a legal record-keeping obligation prevents us from fulfilling a request in full.

Where your data appears in a client's accounting records, we will forward your request to that client, since they are the controller of it.

12. Cookies and analytics

This website is deliberately light on tracking. We do not use advertising cookies, and we do not sell or share data with ad networks.

  • Essential storage — a browser session value that remembers whether you dismissed the announcement bar. This is functional only and is not used for tracking.
  • Aggregate analytics — if aggregate measurement is enabled, it is configured to avoid identifying individuals and is not combined with the contact details you submit.

You can block or clear cookies and local storage through your browser settings. The website will continue to work; you may simply see the announcement bar again.

13. Children

This website and our services are intended for businesses and their representatives. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

14. Automated processing

Accruna uses software agents extensively, so it is worth being clear about what that means for individuals.

  • Agents assist with categorising transactions, matching balances and preparing analyses in client accounting records. These are business records, not profiles of individuals.
  • Agents may identify anomalies in expense claims, such as a missing receipt or spend outside a client's policy. The outcome is a review request routed to a named human — an agent cannot approve or reject a claim, and cannot impose a consequence on an individual.
  • We do not use automated processing to make decisions with legal or similarly significant effects about individuals, and we do not build behavioural profiles of individuals for marketing.

Where a client uses our output in a decision about one of their people, the client is the decision-maker and is responsible for the lawfulness of that decision.

15. Changes to this policy

We review this policy at least annually and whenever our practices change materially. The effective date at the top of this page always reflects the current version. If a change materially affects how we handle personal data, we will make that clear on this page and, where appropriate, notify clients directly.

16. How to contact us

For any question about this policy, a request relating to your personal data, or a security concern:

If you are not satisfied with our response, you have the right to complain to the data protection authority in your jurisdiction.

Also see: our terms of service for the terms governing use of this website and our engagements, and our security overview for the technical controls behind this policy.

Questions about this policy?

We will answer privacy and data handling questions in writing, including anything your procurement or legal team needs documented.