Legal Policy

Privacy Policy for Busynes

Last Updated: June 21, 2026

Busynes ("we," "us," or "our") is committed to protecting the privacy and security of your personal and corporate financial data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our modular SaaS ecosystem and automated invoice parsing platform (collectively, the "Service").

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Busynes acts as a Data Controller for your account registration and billing data, and a Data Processor for the invoice and receipt data you upload to our secure vault.


analytics 1. Information We Collect

A. Account & Billing Data (Provided by You)

  • Identity Information: Full name, business email address, company name, and corporate registration details.
  • Billing Information: Payment card details, billing address, and transaction history (collected and processed securely via our third-party payment processor, Stripe).

B. Uploaded Document Data (Processed on Your Behalf)

  • Invoices, Receipts, and Financial Documents: Any PDF, JPEG, or PNG files you upload to our S3 Invoice Vault. This includes extracted metadata such as supplier names, invoice numbers, tax/VAT details, line-item descriptions, and transaction totals.

settings_suggest 2. How We Process and Use Your Information

We process your data strictly under the following legal bases:

  • Performance of a Contract: To provision your B2B account, process your uploaded documents via our AI extraction pipeline, and calculate your dashboard totals.
  • Consent: To send you our Weekly Efficiency Report or promotional updates (which you can opt-out of at any time).
  • Legal Obligation: To comply with UK tax, accounting, and corporate reporting laws.
shield We never sell, rent, or lease your corporate financial data or account information to third parties.

gpp_good 3. Data Storage, Security, and Transfers

A. Location

All account data, database logs, and S3-uploaded invoices are stored securely in the Amazon Web Services (AWS) London Region (eu-west-2). This ensures your corporate financial data does not leave the United Kingdom without your explicit authorization.

B. Security Measures

We implement bank-grade security protocols to protect your data, including:

  • Encryption in Transit: All data sent between your browser and our servers is encrypted using TLS 1.3.
  • Encryption at Rest: All files in our S3 Invoice Vault and database records in DynamoDB are encrypted using AES-256 standard encryption keys.
  • Least Privilege Access: Our OIDC-authenticated deployment roles ensure restricted access to resources.

assignment_ind 4. Your Rights Under UK GDPR

As a UK-registered business or resident, you have the following rights:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request corrections to any inaccurate data.
  • Right to Erasure ("Right to be Forgotten"): Request the complete deletion of your account and uploaded S3/DynamoDB documents.
  • Right to Data Portability: Export your transaction logs in a structured, machine-readable format (CSV).

To exercise any of these rights, please contact our support team at support@busynes.com.