LEGAL & TRUST
Privacy Policy
Updated 9 September 2026 · AIONA Grade & AIONA Bookkeeping
On this page
- 1. Information We Collect
- 2. How We Use Your Information
- 3. Automated Processing and Artificial Intelligence
- 4. Data Storage and Security
- 5. Service Providers and Connected Services
- 6. Data Retention
- 7. Your Rights (UK GDPR)
- 8. Cookies, Local Storage, and Tracking
- 9. International Data Transfers
- 10. Children's Privacy
- 11. Changes to This Privacy Policy
- 12. Contact Us
AIONA Ltd, trading as AIONA ("we", "our", or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our intelligent accounting software platform ("AIONA" or the "Service"). This policy covers the website, AIONA Grade and AIONA Bookkeeping. We act as controller for account administration, billing, support and service security. For personal data in client accounting records and Grade reviews processed on your practice’s instructions, we act as processor (or sub-processor where your practice acts for a controller), under our Data Processing Agreement. Your practice determines the lawful basis for that client-data processing.
AIONA Ltd is registered in England & Wales under company number 16606520, registered office 128 City Road, London, United Kingdom, EC1V 2NX. We are registered with the UK Information Commissioner's Office (ICO) as a data controller, registration number ZC189017.
1. Information We Collect
1.1 Information You Provide
- Account Information: Your name, email address, a hashed password, and your role (admin, accountant, or auditor) when you create or are invited to an account.
- Practice and Company Information: The name and registration details of your accounting practice and of the client companies you manage - company registration number, registered address, VAT number and scheme, SIC codes, accounting period details, and chart of accounts.
- Financial Documents: Invoices, receipts, bills, bank statements, and other financial documents you upload or forward to us, and the text and figures we extract from them.
- Contacts: Details of your suppliers and customers (who may be individuals) - name, email, phone, address, and VAT/registration numbers.
- Transaction and Ledger Data: Journal entries, bank transactions, payments, reconciliations, and the reports generated from them.
- Identity Verification: Email verification is the gate at signup: we send a code to your address and record that it was confirmed. We do not collect identity documents, selfies or biometric data, and we do not use a third-party identity-verification provider.
1.2 Information We Collect Automatically
- Security and Login Data: Each sign-in attempt records your IP address, browser/user-agent, time, and outcome, to protect your account and detect abuse. Refresh tokens are stored with the IP and user-agent that created them.
- Service Usage: Logs needed to operate, secure, and debug the Service.
- Cookies and Local Storage: See §8. We authenticate you using tokens stored in your browser's local storage (not advertising cookies), and we do not currently use third-party analytics or advertising trackers.
1.3 Information from Third Parties
- Companies House: Public company-register data (registration details, status, officers, filing history) we retrieve to verify and enrich the companies and suppliers you work with.
- HMRC (when you connect it): VAT obligations, liabilities, and submission results for Making Tax Digital.
- Xero (when you connect it): Accounting records available through the permissions you authorise, including accounts, contacts, invoices, bills, payments and their source lines. In Grade we also store review periods, grades, findings, source references and exported report data to provide review history and the practice scorecard. Connecting Xero authorises access; it does not transfer ownership of the records.
- Your bank (when you connect an Open Banking feed): Account details, balances, and transaction history, retrieved through our Open Banking provider with your consent. Bank feeds are provided by TrueLayer Limited, the FCA-authorised account information service provider; AIONA receives only the read-only data you instruct TrueLayer to share.
1.4 Waitlist and Pre-Launch Contact Data
If you join the waitlist on our website, we collect your work email address and, optionally, your name and business name. We use these solely to contact you about AIONA's availability, early access, and launch. The lawful basis is your consent, which you can withdraw at any time using the unsubscribe link in any email we send, or by writing to support@aionatech.com - we will then stop contacting you and delete your waitlist record. Every waitlist email we send identifies AIONA Ltd as the sender and includes a way to opt out. Waitlist records are deleted no later than 12 months after our public launch unless you have opened an account.
2. How We Use Your Information
We process your information to:
- Provide, maintain, secure, and improve the Service;
- Extract data from your documents and suggest how transactions should be coded to your chart of accounts;
- Generate accounting records and reports (trial balance, profit & loss, balance sheet, and others);
- Perform bank reconciliation and month-end processing, and prepare VAT returns in MTD 9-box format for your approval (live submission to HMRC is pending HMRC software recognition);
- Run integrity and assurance checks (for example, flagging a dissolved or insolvent supplier via Companies House, or a VAT figure that does not reconcile to a valid UK rate);
- Maintain an immutable, tamper-evident audit trail for compliance and security;
- Verify your email address and protect account access;
- Send you service, security, and administrative messages and respond to your support requests;
- Contact people who joined our waitlist about availability and early access (with consent);
- Detect, prevent, and address fraud, abuse, security incidents, and technical problems.
Our lawful bases under UK GDPR Article 6 for processing as controller are below. Processing of client accounting data as processor follows your documented instructions under the DPA.
| Purpose | Lawful basis |
|---|---|
| Administering accounts, subscriptions and support for individual business customers | Performance of a contract where you are a party; legitimate interests in administering the business relationship where you represent an organisation |
| AIONA’s own statutory record-keeping and other legal obligations that apply to AIONA, including applicable HMRC fraud-prevention requirements (§3.5) | Legal obligation |
| Security logging, fraud and abuse prevention, debugging, and service improvement | Legitimate interests |
| Waitlist and optional marketing updates | Consent |
3. Automated Processing and Artificial Intelligence
3.1 Document Data Extraction (OCR)
When you upload or forward a document, we extract its text and key fields. A first pass runs on our own servers using local optical character recognition (Tesseract). For structured extraction of invoices, receipts, and statements we use Google Cloud Document AI (configured in the EU region). Each of these processes the document's image/PDF content to return fields such as vendor, dates, totals, VAT, and line items.
3.2 Automated Classification - Human in the Loop
We use automated techniques (including AI) to classify documents and suggest how each line maps to your chart of accounts. These are suggestions only. No document affects your ledger until a person reviews and approves it; any automatic posting is a per-supplier setting you switch on yourself. We therefore do not make decisions producing legal or similarly significant effects about you by solely automated means within the meaning of UK GDPR Article 22. We keep a log of these classification inputs and outputs (for example, the vendor name and line description sent, and the account suggested) so that coding decisions are auditable and so the system can learn from your corrections.
3.3 AI Assistant
The in-app AI Assistant is powered by large language models provided by Anthropic (the Claude family), accessed through Anthropic's API. When you ask the Assistant a question, your query and a relevant, company-scoped slice of your accounting data (which may include supplier and customer names, document text, and figures) are sent to Anthropic to generate a response. The Assistant is read-only and is restricted to the single company you are working in. We do not keep a server-side transcript of your Assistant conversations; conversation context is held in your browser session for the duration of the chat. We use these AI services under terms that prohibit them from using your data to train their models.
3.4 Other AI Analysis
Some compliance and benchmarking features analyse public company-register information (from Companies House) and aggregated financial ratios. These analyses are deterministic or use the same Anthropic AI assistant described above; they operate on public-register and aggregated data, not on your private ledger content.
3.5 HMRC Fraud Prevention Data (Making Tax Digital)
When you connect AIONA to HMRC and use Making Tax Digital features (for example retrieving VAT obligations or submitting a VAT return), HMRC requires all MTD software, by law, to send certain information about the device and connection being used alongside each API request. This helps HMRC detect and prevent fraud, is a condition of using HMRC's APIs, and cannot be switched off while using HMRC-connected features. The data transmitted with each HMRC request includes:
- a random device identifier generated by AIONA and stored in your browser (not a hardware serial number);
- your device's public IP address and the time we observed it, and - where your browser makes them available - your device's local network IP addresses;
- your browser's user-agent string, screen size, colour depth and scaling factor, window size, and timezone;
- a one-way hashed identifier for your AIONA user account (HMRC receives the hash, not your email or name);
- details of the server making the request on your behalf, including our server's public IP address and our software name and version.
This data is sent only to HMRC, only when you use HMRC-connected features, and only for HMRC's fraud-prevention purposes. The lawful basis is legal obligation. HMRC's own use of this data is described in HMRC's transaction monitoring privacy notice.
4. Data Storage and Security
4.1 Where Your Data Is Stored
- The Service - application and database - is hosted on Fly.io infrastructure in London, United Kingdom (region lhr). Google Cloud is retained for document file storage (Cloud Storage, region europe-west2, London) and document data extraction (Document AI, EU region). The application's static assets are served via Google Firebase Hosting, and the public marketing website (aionatech.com) is hosted and delivered by Netlify. Error monitoring is provided by Sentry (EU region); reports are scrubbed of personal data before transmission.
- Your structured data (accounts, ledger, transactions, contacts, extracted document text) is held in a PostgreSQL database.
- Original uploaded document files are stored in Google Cloud Storage europe-west2 (London, UK).
- We take regular backups to protect against data loss.
4.2 Security Measures
- All traffic is encrypted in transit using TLS, with HTTP Strict Transport Security and a content security policy enforced.
- Data is encrypted at rest using our infrastructure providers' server-side encryption (Google Cloud Storage and the database platform). Sensitive integration tokens (for example, HMRC OAuth tokens) are additionally encrypted at the application level.
- Passwords are hashed with bcrypt; we never store them in plain text.
- Accounts are protected by sign-in rate limiting and automatic lockout after repeated failed attempts.
- Access is governed by role-based permissions (admin, accountant, read-only auditor). Each tenant's data is isolated from every other tenant, enforced in application logic on every query and by database row-level security policies on tenant tables.
- Posted journal entries are immutable: database triggers prevent them being altered or deleted, and every change is recorded in an append-only audit trail secured with SHA-256 integrity hashes.
- Sign-in uses a password plus email verification, and two-step verification (an authenticator app, with single-use recovery codes) can be switched on per account or required for everyone in a practice.
5. Service Providers and Connected Services
We do not sell your personal or financial data. The table covers processors and connected services. Providers processing client personal data on our behalf are engaged under data-processing terms consistent with UK GDPR Article 28. Xero, HMRC, Companies House, payment providers and banking providers may act as independent controllers for their own services; connecting them does not make them AIONA sub-processors for all purposes. Data is shared only for the relevant purpose and feature.
| Processor | Purpose | Region | When |
|---|---|---|---|
| Fly.io | Cloud hosting of the application and database | UK (London) | Always |
| Google Cloud | Document storage (Cloud Storage) and document data extraction (Document AI) | EU / UK | Whenever you upload or process documents |
| Anthropic | AI Assistant and automated transaction-coding suggestions (Claude models) | United States | When AI features are used |
| Resend | Transactional email (verification codes, password resets, invitations, notices) and inbound email capture (invoices and receipts sent to a client's AIONA documents address) | United States | Always for outbound email; inbound only when you use email-in capture |
| Stripe | Subscription billing and card payment processing | US / UK / EU | On paid plans |
| Sentry (Functional Software, Inc.) | Application error monitoring - crash reports, which may include your IP address, browser details, and the screen or action in use when an error occurred (configured not to capture personal data by default) | United States | When error monitoring is enabled |
| Xero | Read-only import of accounting data (accounts, contacts, invoices, payments). AIONA does not write back to Xero. | Global | Only when you connect Xero |
| HMRC | VAT and Making Tax Digital submissions and obligation tracking | UK | Only when you authorise filing |
| Companies House | Company-register lookups and supplier verification | UK | During onboarding and supplier checks |
| TrueLayer | Open Banking bank feed (account and transaction data). TrueLayer Limited is the FCA-authorised account information service provider; AIONA is not FCA-regulated and receives only the read-only data you instruct TrueLayer to share | UK / EU | Only when you connect a bank feed |
5.1 Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of AIONA, our users, or others.
5.2 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you in advance of any such transfer and of any resulting change to how your data is processed.
6. Data Retention
We retain your data for as long as your account is active and as needed to provide the Service. Our standard retention policy for Bookkeeping financial records and supporting documents is 7 years, to support customers’ record-keeping requirements. Statutory requirements vary by business and record type; this is not a blanket legal requirement for all personal data. Customer instructions for return or deletion are governed by the DPA. Grade review records remain available while the account remains open, including after subscription cancellation; request return or deletion by contacting support. Disconnecting Xero does not itself delete saved reviews.
When you close your account, personal identifiers are removed from those retained financial records - your name and email are replaced with an anonymous reference while the underlying accounting entries (debits, credits, dates) are preserved subject to the retention arrangements above. Login history and refresh tokens are permanently deleted, as there is no legal obligation to retain them.
Sign-in and security logs are retained for up to 24 months from creation. Logs of automated classification inputs and outputs (§3.2) are retained for the same period as the accounting records they explain, so that coding decisions remain auditable.
7. Your Rights (UK GDPR)
Under the UK General Data Protection Regulation, you have the right to:
- Access & Portability: Obtain a copy of your personal data in a structured, machine-readable format. You can export this yourself at any time from Settings → Privacy & Data; ledger and report data can also be exported as CSV and Excel.
- Rectification: Correct inaccurate or incomplete data, via Settings → Profile or by contacting us.
- Erasure: Request deletion of your data, subject to the legal retention obligations described in §6. Use Settings → Privacy & Data → Danger Zone.
- Restriction & Objection: Limit or object to certain processing, including processing based on legitimate interests.
- Withdraw Consent: Withdraw consent for any processing that relies on it (for example, marketing updates) at any time.
- Complain: Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe your rights have been breached.
To exercise any of these rights, contact us at support@aionatech.com. We normally respond within one month. If a lawful extension applies, we explain the reason and revised deadline. For client records we process for your practice, contact the practice first; we assist it with your request under the DPA.
8. Cookies, Local Storage, and Tracking
AIONA keeps you signed in using authentication tokens stored in your browser's local storage, together with a small number of strictly necessary interface preferences. The Cookie Policy explains the purposes of this storage. Any consent exemption depends on the specific purpose and applicable conditions, rather than on whether a technology is called a cookie. Full details are in our Cookie Policy.
We do not currently use advertising cookies or third-party analytics trackers. If we introduce optional analytics in the future, we will only enable them after you opt in through a consent banner, and we will add a control in the application for changing your choice at any time.
9. International Data Transfers
The Service is hosted in the United Kingdom, and we keep your data in the UK and EU wherever practicable. Some of our sub-processors are based outside the UK - in particular Anthropic, Resend, Stripe, and Sentry are based in the United States. Where personal data is transferred outside the UK, we rely on one or more of the following safeguards:
- A UK adequacy decision, where one applies;
- The UK Extension to the EU - U.S. Data Privacy Framework, where the recipient is certified under it;
- The UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum, for transfers to jurisdictions without adequacy;
- Supplementary technical and organisational measures (encryption in transit and at rest, access controls, and minimisation of the data shared).
10. Children's Privacy
AIONA is a business tool intended for use by people aged 18 or over. We do not knowingly collect personal information from children.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email and surfaced in the app for at least 30 days before they take effect. Minor, clarifying updates will be reflected in the "Last Updated" date only. Your continued use of AIONA after a material change takes effect constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
AIONA Ltd
Email: support@aionatech.com
Registered in England & Wales, company number 16606520
Registered office: 128 City Road, London, United Kingdom, EC1V 2NX
This Privacy Policy is effective as of 3 July 2026.