Privacy Policy
Last updated: March 23, 2026
1. Data Controller
Estonian Accounting OU (hereinafter "we", "us", "our") is the data controller for your personal data within the meaning of the General Data Protection Regulation (GDPR).
- Address: Harju maakond, Tallinn, Estonia
- Registry code: 16839461
- Email: privacy@estonian-accounting.com
- Data Protection Officer (DPO): dpo@estonian-accounting.com
2. Scope
This Privacy Policy describes how we collect, use, disclose, and protect your personal data when you use our cloud-based accounting software (the "Service"). It applies to all users, including account holders, team members, and customer/vendor portal users.
3. Legal Basis for Processing
We process your personal data under the following legal bases pursuant to GDPR Article 6:
- Contract performance (Art. 6(1)(b)): managing your account, providing the accounting service, processing invoices, offering bank connections, and delivering other services for which we have entered into a contract with you.
- Legitimate interest (Art. 6(1)(f)): ensuring service security, preventing fraud, improving the service, usage analytics, and monitoring technical errors.
- Legal obligation (Art. 6(1)(c)): compliance with Estonian accounting and tax legislation, retention of accounting documents for the period prescribed by law.
- Consent (Art. 6(1)(a)): for AI-powered features, marketing communications, and non-essential cookies where applicable. You may withdraw your consent at any time.
4. Categories of Personal Data Collected
4.1 Account Data
Upon registration and use of your account, we collect: email address, name, password (stored securely as an Argon2 hash), two-factor authentication settings (TOTP), Smart-ID link data (personal code, country), and session management data.
4.2 Company Data
Creating a company requires: business name, registry code, VAT number, legal address, bank account details (IBAN), and contact information. This data is necessary for providing the accounting service and meeting tax obligations.
4.3 Financial Data
During use of the Service, we process: invoices (sales and purchase), bank transactions (via import and reconciliation), journal entries, asset depreciation calculations, cash transactions, prepayments, and other accounting documents. This also includes customer and vendor register data.
4.4 Employee Data
When using the payroll module, we process: personal identification codes, salary figures, income data, leave balances, work schedules, and social tax and income tax calculation data. This data is particularly sensitive and is processed strictly in accordance with contractual obligations.
4.5 Usage Data
We automatically collect: login times, page visits, features used, device and browser information, and IP addresses. This data is stored in activity logs and analytics events for the purpose of improving the service and ensuring security.
4.6 AI Interaction Data
When you use our AI features (chat assistant, document analysis, categorization, predictions), we process: conversation sessions, categorization decisions and feedback, AI-generated recommendations, and summarized input data. AI processing is performed via the Anthropic Claude API, and your data is not used for training AI models.
5. Data Processors and Sub-processors
We use the following third-party service providers to process your data:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner | Hosting, object storage, backups | Germany (EU) |
| Resend | Email delivery (invoices, reminders, notifications) | USA |
| Stripe | Subscription billing and payment processing | USA |
| Anthropic (Claude API) | AI features: OCR, chat assistant, categorization, predictions | USA |
| GoCardless (Nordigen) | Open banking connections (account data access) | UK / EU |
| SK ID Solutions | Smart-ID authentication (Estonian digital identity) | Estonia (EU) |
| Sentry | Error tracking and performance monitoring (if enabled) | USA |
6. Data Retention Periods
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account data | Until account deletion | Contract |
| Financial and accounting documents | 7 years (Estonian law) | Legal obligation |
| Analytics events | 90 days | Legitimate interest |
| AI conversations | 30 days | Consent |
| Session data | 30 days | Contract |
| Activity logs | 1 year | Legitimate interest |
| Employee data (payroll) | 7 years after employment ends | Legal obligation |
7. Your Rights (GDPR Articles 15-22)
Under the General Data Protection Regulation, you have the following rights:
- Right of access (Art. 15): You can download all of your personal data via Settings > Account > Export Data or by making a request to
POST /account/export-data. - Right to rectification (Art. 16): You can update your personal information at any time in your account settings.
- Right to erasure (Art. 17): You can delete your account and all associated data via Settings > Account > Delete Account or by making a request to
POST /account/delete. Accounting documents required by law will not be deleted until the retention period expires. - Right to data portability (Art. 20): Export your data in machine-readable JSON format or SAF-T XML format.
- Right to restriction of processing (Art. 18): You may request restriction of processing of your data in certain circumstances.
- Right to object (Art. 21): You may object to the processing of your data based on legitimate interest.
- Rights related to automated decision-making (Art. 22): You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you.
To exercise your rights, please contact privacy@estonian-accounting.com or use the relevant features in your account settings. We will respond to your requests within 30 days. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee).
8. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS)
- Secure password hashing (Argon2)
- Two-factor authentication (TOTP)
- Smart-ID authentication (Estonian digital identity)
- Session management with secure cookies
- Rate limiting and CSRF protection
- Role-based access control (RBAC)
- Activity logging and audit trail
- Regular backups
9. International Data Transfers
Your data is hosted in Germany (Hetzner, EU). However, some sub-processors involve data transfers outside the European Economic Area (EEA), primarily to the USA (Resend, Stripe, Anthropic, Sentry) and the UK (GoCardless).
For data transfers to non-EEA countries, we rely on:
- EU Standard Contractual Clauses (SCCs) pursuant to GDPR Article 46(2)(c)
- Supplementary measures (encryption, access controls, data minimization)
10. AI Data Processing
Our Service includes several artificial intelligence features that process your data via the Anthropic Claude API:
- Invoice OCR: Uploaded documents are processed in real time for data extraction. Documents are not retained by the AI provider beyond the processing session.
- Chat assistant: Conversation sessions are stored for 30 days and then automatically deleted.
- Categorization: Bank transaction categorization decisions and feedback are stored as learned rules to improve the service.
- Predictive analytics: Cash flow forecasts and trends are generated from aggregated financial data.
Your data is not used for AI model training. All AI processing is optional, and you may disable AI features at any time.
11. Cookies and Local Storage
We use only essential cookies necessary for the functioning of the Service:
- auth_session: Authentication session cookie (secure, HTTP-only)
- csrf_token: CSRF protection cookie
Additionally, we use browser local storage (localStorage) for storing preferences:
- Language preference (et/en)
- Dark/light theme selection
- Cookie consent state
We do not use third-party tracking cookies, advertising cookies, or social media plugins.
12. Children's Data
Our Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will delete it promptly. If you believe we have collected your child's data, please contact us at privacy@estonian-accounting.com.
13. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy at any time. In the event of material changes, we will notify you by email or through an in-service notification at least 30 days in advance. Continued use of the Service after the changes take effect constitutes your acceptance of the updated policy.
14. Contact
For privacy-related questions, contact us:
- Email: privacy@estonian-accounting.com
- Data Protection Officer: dpo@estonian-accounting.com
- Postal address: Harju maakond, Tallinn, Estonia
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate:
- Website: www.aki.ee
- Email: info@aki.ee