MTD for ITSA in action — watch our webinar with Accountants Therapy. Watch now →
← Back to home

Privacy Policy

Effective Date: 10 June 2024 · Last Updated: 29 Jan 2026

1. Introduction

At Briefcase Tech Ltd (“Briefcase,” “we,” “us,” or “our”), we are committed to protecting the privacy and security of your personal data. This Privacy Policy outlines how we collect, use, disclose, transfer, and store information about you when you use our website https://www.briefcase.so (the “Site”) and our Software as a Service platform and related services (collectively, the “Services”).

By accessing or using our Services, you acknowledge that you have read, understood, and agree to the collection and use of your information as described in this Privacy Policy.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person as defined under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
  • Customer: The accounting firm or business that subscribes to and uses our Services.
  • End User: A client or third party whose data (e.g., invoices, receipts) is processed by the Customer through our Services.
  • Data Controller: The entity that determines the purposes and means of processing Personal Data. The Customer is the Data Controller.
  • Data Processor: The entity that processes Personal Data on behalf of the Data Controller. Briefcase is the Data Processor.
  • Sub-Processor: A third party appointed by the Data Processor to process Personal Data on behalf of the Data Controller.

3. Scope of this Privacy Policy

This Privacy Policy applies to:

  • Personal Data we collect from Customers and End Users through use of our Services.
  • Personal Data collected through our Site, communications, and interactions with you.

4. Information We Collect

4.1 Information Provided by Customers

  • Account Information: Name, email address, postal address, phone number, company name, username, and password.
  • Financial Information: Payment details processed via Stripe.
  • Customer Data: Invoices, receipts, and historical ledger data from connected Xero or QuickBooks accounts, which may contain Personal Data of End Users.

4.2 Information Collected Automatically

  • Technical Information: IP address, browser type, operating system, and device information.
  • Usage Information: Pages viewed, features used, time spent on our Services.
  • Cookies and Similar Technologies: See Section 12 for more details.

4.3 Information from Third Parties

  • Third-Party Integrations: When you connect your account with third-party services like Xero or QuickBooks, we receive accounting context such as supplier names, chart of accounts, VAT registration details, and historical transaction metadata.

5. How We Use Your Information

5.1 Provision of Services

  • To provide, maintain, and improve our Services.
  • To automate processing of invoices and receipts, extract necessary information, and post to accounting platforms such as Xero or QuickBooks.
  • To integrate with connected third-party accounting platforms and provide contextual insights and historical data.

5.2 Communication

  • To communicate with you about your account, transactions, or updates.
  • To provide customer support and respond to enquiries.

5.3 Legal and Compliance

  • To comply with applicable legal obligations, including financial and data protection regulations.
  • To enforce our Terms of Service and other agreements.

5.4 Marketing Communications

We may send you marketing communications in two ways:

  • Soft Opt-In: If you sign up for our Services, we may send you product updates, offers, or tips related to Briefcase under the “soft opt-in” basis permitted by the UK Privacy and Electronic Communications Regulations (PECR). You can opt out at any time using the unsubscribe link in any message or by contacting support@briefcase.so.
  • Explicit Consent: If you separately sign up to receive our newsletter or marketing emails (e.g. via a form on our website), we will only send you communications based on your explicit consent. You can withdraw this consent at any time by unsubscribing or contacting us.

6. Legal Basis for Processing Personal Data

Our processing is based on the following legal grounds under the UK GDPR:

  • Contractual Necessity: Where processing is required to provide the Services.
  • Legitimate Interests: Where processing is necessary for our legitimate business interests, provided these are not overridden by your rights.
  • Consent: For marketing communications or optional features where explicit consent is required.
  • Legal Obligation: Where processing is necessary to meet statutory obligations.

7. Disclosure of Personal Data

7.1 Sub-Processors and Service Providers

We use trusted third-party Sub-Processors to support the delivery and maintenance of our Services. All are subject to strict contractual obligations, including confidentiality and data protection requirements. Below is a list of our current Sub-Processors, what they are used for, the types of data they process, where data is stored, and how long it is retained:

ProviderPurposeData ProcessedLocationRetention
Amazon Web Services (AWS)Core hosting and data storageAll Customer and End User data, including account information, invoices, and receiptsIrelandUntil account deletion or request for removal
StripePayment processingName, email address, billing address, and payment detailsUnited StatesAs per Stripe's Privacy Policy
OpenAIAI document processing and categorisationInvoices, receipts, and context from Xero or QuickBooksUnited StatesZero (data is not stored post-inference)
AnthropicAI document processing and categorisationInvoices, receipts, and context from Xero or QuickBooksUnited StatesZero (data is not stored post-inference)
GoogleAI document processing and categorisationInvoices, receipts, and context from Xero or QuickBooksUnited StatesZero (data is not stored post-inference)
BetterstackInfrastructure monitoring and diagnosticsSystem logs and metadataGermany90 days
MailgunEmail-based document uploadEmail addresses, message content, and attachments when documents are forwarded via emailGermany5 days
TemporalBackend workflow orchestrationMetadata on job execution and automation stateIreland30 days
WhatsApp Business (optional)Upload method for invoices and receipts via messagingPhone number, message content, and any attached filesGermanyAs per WhatsApp's Privacy Policy

This list of Sub-Processors may be updated from time to time. We will post the updated list here and may notify Customers of material changes. Continued use of the Services after such updates constitutes acceptance of the revised list.

7.2 Data Segregation

We never share data between End Users or Customers. Data is logically separated at the database level. Each Customer and End User is assigned a separate database record to ensure strict isolation. No data from one Customer or End User is used in automation, training, or processing for another.

7.3 Legal Requirements

We may disclose Personal Data if required to do so by law or in response to valid requests by public authorities.

7.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, Personal Data may be transferred. We will notify you of any such change.

8. International Data Transfers

Some Personal Data is processed outside the UK and EEA. In particular, we use Large Language Model (LLM) providers such as OpenAI (USA), Anthropic (USA), and Google (USA) for document processing and categorisation. These providers operate under bespoke zero data retention agreements, meaning customer data is not stored or used for model training.

All other Sub-Processors and their transfer locations are listed in Section 7.1.

9. Data Security

We implement robust technical and organisational measures to protect your data, aligned with best practices in cloud security and data protection. These include:

  • Encryption: Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access Controls: Role-based access control with audit logging.
  • Monitoring: Continuous infrastructure and application monitoring using Betterstack.
  • Minimisation: Only the data necessary for specific processing tasks is collected or shared.
  • Review: Output from large language models (LLMs) is reviewed internally by authorised staff only for debugging and improvement purposes.

10. Data Retention

  • We retain your and your End Users' data for the duration of your subscription.
  • If your subscription ends, we may delete all data (including invoices and receipts) after 30 days without further notice.
  • Some data may be retained where required to comply with legal or regulatory obligations.
  • You may request deletion at any time (subject to those obligations).

11. Your Rights

You have the following rights under UK GDPR:

  • Access: Request details of the data we hold on you.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of your data where processing is no longer necessary.
  • Restriction: Limit processing under certain circumstances.
  • Portability: Request a copy of your data in machine-readable format.
  • Objection: Object to data processing based on legitimate interests.
  • Withdraw Consent: Revoke consent where processing is based on consent.
  • Lodge a Complaint: File a complaint with the Information Commissioner's Office (ico.org.uk).

To exercise these rights, email support@briefcase.so.

12. Cookies and Similar Technologies

We use cookies to enhance user experience:

  • Session Cookies: Maintain login state and navigation.
  • Preference Cookies: Remember settings and choices.
  • Security Cookies: Help protect user accounts.

You can control or disable cookies through your browser settings.

13. Use of AI and Language Models

We use large language models (LLMs) to automate document extraction and categorisation as part of our Services.

13.1 What We Send and Why

We may send the following data to LLM providers to enable automated processing of financial documents:

  • Invoices, receipts, and attachments uploaded by the Customer.
  • Contextual information retrieved from your connected Xero or QuickBooks account, including supplier names, chart of accounts, line of business, and VAT registration details.

This data is strictly necessary for categorisation, VAT code assignment, and posting automation.

13.2 Providers and Safeguards

We currently work with:

  • OpenAI (USA)
  • Anthropic (USA)
  • Google (USA)

All providers operate under zero-data retention agreements with Briefcase. This means:

  • Your data is not stored after processing.
  • Your data is never used to train models.
  • Logs are not retained beyond the session.

13.3 Access and Oversight

LLM outputs are reviewed solely for debugging and product improvement. Reviews are conducted exclusively by authorised Briefcase employees.

14. Children's Privacy

Our Services are not intended for individuals under 16. We do not knowingly collect Personal Data from children. Please contact us if you believe we have received such data.

15. Third-Party Links and Services

Our Site may contain links to or integrations with third-party websites or services (e.g. Xero, QuickBooks, Stripe). These operate independently and are subject to their own privacy policies. We encourage you to review their terms directly.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time:

  • We may notify you of significant changes via email or within the Services.
  • The updated version will be posted with a new “Last Updated” date.
  • Continued use of the Services after changes become effective constitutes acceptance.

17. Contact Us

If you have questions about this Privacy Policy or your data:

Email: support@briefcase.so

18. Appendix: Data Processing Agreement (Controller–Processor Agreement)

This Privacy Policy incorporates a Data Processing Agreement (“DPA”) between the Customer (acting as Data Controller) and Briefcase (acting as Data Processor), setting out the parties' respective obligations in relation to the processing of Personal Data.

Subject Matter

The processing of Personal Data as necessary to provide the Services, including the automation of bookkeeping and accounting workflows.

Duration

For the duration of the Customer's use of the Services and thereafter until deletion of Personal Data in accordance with Section 10 (Data Retention).

Nature and Purpose of Processing

Automated processing of financial documents (including invoices and receipts) and related contextual accounting data in order to extract information, categorise transactions, apply tax logic, and post data to accounting platforms such as Xero or QuickBooks.

Types of Personal Data

Names, addresses, contact details, transaction data, invoice data, and contextual accounting data submitted by or on behalf of the Customer.

Categories of Data Subjects

Customers, End Users, suppliers, and employees.


Obligations of Briefcase (Processor)

Briefcase shall:

  • Process Personal Data only on documented instructions from the Customer, unless required to do so by applicable law (in which case Briefcase shall inform the Customer unless legally prohibited).
  • Ensure that all personnel authorised to process Personal Data are subject to appropriate confidentiality obligations.
  • Implement appropriate technical and organisational measures to protect Personal Data, as described in Section 9 (Data Security) of this Privacy Policy.
  • Assist the Customer, taking into account the nature of the processing, in complying with its obligations relating to:
    • data subject rights requests,
    • data protection impact assessments, and
    • consultations with supervisory authorities, where applicable.
  • Notify the Customer without undue delay of a Personal Data Breach and provide reasonable assistance to enable the Customer to meet its legal obligations.
  • Upon termination of the Services, delete or return all Personal Data in accordance with Section 10, unless retention is required by applicable law.
  • Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and support reasonable audit or information requests, subject to appropriate confidentiality, security, and proportionality safeguards.

Sub-processors

Briefcase may engage Sub-Processors to process Personal Data on behalf of the Customer. A current list of Sub-Processors, including the nature and location of their processing, is maintained in Section 7.1 of this Privacy Policy. Briefcase shall ensure that Sub-Processors are subject to data protection obligations no less protective than those set out in this DPA.

International Transfers

Where Personal Data is transferred outside the UK or EEA, Briefcase ensures that appropriate safeguards are in place in accordance with applicable data protection laws, including adequacy regulations or other lawful transfer mechanisms.


Obligations of the Customer (Controller)

The Customer shall:

  • Ensure a lawful basis for the processing of Personal Data and for instructing Briefcase to process such data.
  • Inform Data Subjects of the processing in accordance with applicable data protection laws.
  • Provide lawful, documented instructions to Briefcase for the processing of Personal Data.
  • Ensure that Personal Data provided to Briefcase is accurate and lawfully obtained.

Precedence

In the event of any conflict between this DPA and other sections of this Privacy Policy, this DPA shall prevail with respect to the processing of Personal Data carried out on behalf of the Customer.