Privacy Policy
Last updated 23 September 2026
This policy explains what personal data [Company legal name] ("Tenet", "we") collects when you use Tenet, why, and what rights you have. Tenet is accounts-payable software used by businesses. For the invoices and documents a customer uploads, the customer is the controller and we process that data on their behalf under our Data Processing Addendum.
1. Data we collect
- Account data — name, work email, hashed password, role, workspace name, sign-in times.
- Customer content — invoices, purchase orders, goods receipts and other documents you upload or forward, the data we extract from them (supplier names, amounts, line items, tax details), and your corrections and approvals.
- Accounting connection data — when you connect Xero, the organisation identifier, chart of accounts, tax rates and contacts we need to post bills, and encrypted OAuth tokens.
- Usage and device data — IP address, browser type, request logs and error reports, used to run, secure and debug the service.
2. How we use it
- To provide Tenet: extract and validate invoices, match them to purchase orders and receipts, route approvals, and post approved bills to your accounting system.
- To send service emails: invitations, password resets, exception assignments and approval reminders. You can turn off reminder emails in Settings.
- To secure the service: authentication, rate limiting, fraud and abuse prevention, audit logs.
- To support you and to improve reliability, using logs and error reports.
We do not sell personal data, do not use customer content for advertising, and do not use customer content to train general-purpose AI models. AI providers listed on our subprocessors page process documents only to return results to Tenet.
3. Legal bases (UK and EEA)
We process account and usage data to perform our contract with you and for our legitimate interests in running a secure service. Customer content is processed on the customer's instructions as their processor.
4. Sharing
We share data only with the service providers that host and operate Tenet (our subprocessors), with accounting systems you choose to connect, when required by law, or in a merger or acquisition subject to this policy.
5. Where data is stored
Tenet runs on Google Cloud in the United States. Where data moves outside the UK, EEA or Australia, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
6. Retention
Customer content is kept while the workspace is active. After a workspace is closed we delete customer content within 30 days, and from backups within a further 35 days, unless the law requires us to keep it longer. Audit records needed for financial controls may be retained for as long as the customer instructs.
7. Security
Data is encrypted in transit (TLS) and at rest. Accounting OAuth tokens are additionally encrypted with AES-256-GCM. Access is role-based within each workspace and workspaces are isolated from each other. See our security overview.
8. Your rights
Depending on where you live — including under the UK GDPR, EU GDPR, the Australian Privacy Act, the New Zealand Privacy Act 2020 and US state privacy laws such as the CCPA — you may have the right to access, correct, delete or export your personal data, and to object to or restrict some processing. If your data is in a customer's workspace, we will pass your request to that customer. Email [email protected]. We do not discriminate against anyone for exercising these rights.
You can complain to your local regulator — for example the UK ICO, the Office of the Australian Information Commissioner, or the New Zealand Office of the Privacy Commissioner.
9. Cookies
Tenet uses only cookies and browser storage that are necessary to keep you signed in. We do not use advertising or cross-site tracking cookies.
10. Changes and contact
We will post changes here and notify workspace admins of material changes. Contact: [Company legal name], [Registered address], [email protected].