1. Introduction
This Privacy Policy explains how SOLDOFI SOLUTIONS PRIVATE LIMITED (“Soldofi”, “we”, “us” or “our”) collects, uses, stores, discloses and otherwise processes personal information in connection with Soldofi’s websites, applications, integrations, APIs and related services (collectively, the “Services”).
Soldofi provides software designed to support business finance and accounting workflows, including supplier management, invoice processing, accounts payable management, approval workflows, payment planning, reconciliation, reporting, accounting-system integrations and related financial administration.
This Privacy Policy applies to personal information that Soldofi processes for its own purposes and explains Soldofi’s practices where it processes information on behalf of business customers.
Where a Soldofi customer determines the purposes and means of processing personal information contained in its business records, that customer generally acts as the controller, Data Fiduciary, business or equivalent responsible party under applicable privacy law, and Soldofi generally processes that information on the customer’s behalf.
Our Data Processing Addendum provides additional terms governing such processing.
This Privacy Policy is a transparency notice and does not itself create consent where consent is not the appropriate legal basis for processing.
2. Information We Collect
The information we process depends on how the Services are used.
2.1 Account and User Information
We may process information such as:
- name
- business email address
- company or organisation
- job title or business role
- account identifiers
- authentication information
- user preferences
- roles and permissions
- organisation and tenant membership
- authentication events; and
- security information associated with an account.
We do not need or intend to collect account passwords for third-party services connected through OAuth.
2.2 Business and Financial Information
Customers may provide, upload, generate or connect business information including:
- invoices
- credit notes
- supplier and vendor records
- customer records
- accounts payable information
- accounts receivable information
- accounting records
- bank-transaction information obtained from connected accounting systems
- payment-planning information
- reconciliation records
- remittance information
- supplier statements
- purchase and transaction references
- approval records
- workflow history
- comments
- reports
- supporting documents; and
- audit records.
Some business records may contain personal information about employees, directors, contractors, suppliers, customers or other individuals.
2.3 Supplier Information
Where supplier-management functionality is used, information may include:
- supplier name
- contact-person name
- business email address
- telephone number
- business address
- tax and business registration information
- bank or remittance details
- onboarding documentation
- verification information
- supplier communications
- approval history; and
- change and audit records.
Financial account and remittance information is treated as security-sensitive information even where it is not classified as a special or sensitive category of personal data under applicable law.
2.4 Connected Accounting Systems
When a customer connects an accounting platform such as Xero, Soldofi may access information authorised by the customer and permitted by the applicable integration.
Depending on the integration and enabled features, this may include:
- contacts and suppliers
- invoices
- payables and receivables
- credit notes
- bank transactions
- overpayments
- prepayments; and
- related accounting records.
Soldofi may also send authorised information back to a connected accounting system where a customer enables functionality that requires it.
For example, Soldofi’s current Xero integration is designed to allow approved invoices to be written to the customer’s accounting ledger.
The accounting system remains controlled by the customer.
2.5 Google Workspace and Gmail Information
Where a customer connects a Google Workspace or Gmail account, Soldofi may access Google user data only to provide the features authorised by the customer and permitted by the OAuth permissions granted to Soldofi.
Depending on the feature and permissions granted, this may include:
- email metadata
- sender and recipient information
- message content
- message threads
- attachments; and
- information required to send authorised messages from the connected account.
Soldofi’s intended use of connected mailboxes is to support business finance workflows, such as identifying relevant supplier communications, processing invoice-related information, associating communications with supplier or invoice records and sending authorised business communications.
Soldofi does not obtain the user’s Google password through the OAuth connection.
Soldofi requests access only through Google’s authorisation mechanisms.
Soldofi’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is not sold.
Google user data is not used for targeted advertising.
Google Workspace API data will not be used to create, train or improve a general-purpose artificial intelligence or machine-learning model where doing so would violate Google’s Limited Use requirements.
2.6 Microsoft 365 and Outlook Information
Where a customer connects a Microsoft 365 or Outlook account, Soldofi may access information authorised by the user or organisation through Microsoft’s OAuth and consent mechanisms.
Depending on the permissions granted and enabled features, this may include:
- mailbox information
- email metadata
- sender and recipient information
- message content
- message threads
- attachments; and
- information required to send authorised messages.
Soldofi does not require the user’s Microsoft password to establish an OAuth connection.
Customers or their administrators may revoke application access using mechanisms provided by Microsoft, subject to Microsoft’s platform functionality.
2.7 Website and Demo Information
When a person requests a demonstration or contacts Soldofi, we may collect:
- full name
- work email address
- company
- accounting system
- approximate number of legal entities
- approximate supplier invoice volume; and
- information voluntarily provided about the problem or workflow the person wants to address.
We use this information to respond to the request and communicate about Soldofi.
2.8 Technical, Security and Usage Information
We may process:
- IP address
- browser type
- device type
- operating system
- timestamps
- authentication events
- API requests
- application events
- security events
- diagnostic information
- error information
- audit logs; and
- information about use of the Services.
This information may be used to operate, secure, troubleshoot and improve the Services.
3. Information We Do Not Intend to Collect
Soldofi does not provide card-payment processing functionality and is not intended to store payment-card numbers, card verification codes, cardholder authentication data or other payment-card credentials.
Soldofi does not itself execute, transmit, settle or process customer payments and does not take custody of customer funds.
Payment-related functionality within Soldofi is intended to support activities such as review, planning, approvals, record keeping and reconciliation.
Actual payments are performed through external banking, accounting, payment or financial systems selected and controlled by the customer.
4. How We Use Information
We may process information to:
- provide and operate the Services
- create and administer accounts
- authenticate users
- enforce permissions and access controls
- process invoices and financial documents
- manage supplier records
- support approval workflows
- create and manage payment plans
- support reconciliation
- integrate with accounting systems
- connect authorised business mailboxes
- associate communications and documents with relevant records
- send authorised communications
- provide reporting
- maintain audit trails
- detect duplicate records and exceptions
- prevent fraud and misuse
- protect the confidentiality, integrity and availability of the Services
- troubleshoot errors
- provide customer support
- respond to demonstration and sales enquiries
- comply with legal obligations
- establish, exercise or defend legal claims
- administer contractual relationships; and
- improve the reliability, security and functionality of the Services.
5. Our Role as Controller and Processor
Soldofi may have different privacy roles depending on the processing activity.
5.1 Customer-Controlled Data
For personal information contained in invoices, supplier records, accounting records, connected mailboxes and other information submitted to Soldofi for processing as part of a customer’s business operations, the customer generally determines why that information is processed.
In those circumstances, the customer may act as the controller, Data Fiduciary, business or equivalent responsible entity, and Soldofi generally acts as its processor, Data Processor, service provider or equivalent.
Soldofi processes such information according to the customer’s instructions, the applicable agreement and the configuration of the Services, except where applicable law requires otherwise.
5.2 Soldofi-Controlled Processing
Soldofi may separately determine the purposes and means of processing certain information relating to:
- account administration
- business contacts
- website operation
- sales enquiries
- security
- fraud prevention
- service diagnostics
- legal compliance
- contractual administration; and
- Soldofi’s own corporate records.
For these activities, Soldofi may act as a controller, Data Fiduciary, business or equivalent responsible entity.
6. Artificial Intelligence and Automated Processing
Certain Soldofi features may use automated techniques, including artificial intelligence, machine learning, rules engines, document-processing technologies or similar systems.
Depending on the feature, these technologies may be used to:
- extract information from invoices and documents
- classify documents
- match records
- identify duplicates
- suggest coding or categorisation
- identify exceptions
- assist reconciliation
- associate messages or documents with relevant records
- detect anomalies; or
- produce workflow recommendations.
Automated output may be incomplete or incorrect and should be reviewed where appropriate.
Soldofi is designed as a business workflow system. Material financial approvals and decisions remain subject to customer-defined controls and authorised users.
Customer Data will not be used to train general-purpose Soldofi models unless Soldofi has established an appropriate lawful and contractual basis and provided any disclosure or choice required by applicable law and contract.
Where third-party artificial-intelligence or document-processing providers process Customer Data, their use will be governed by contractual restrictions appropriate to their role and, where applicable, they will be identified in Soldofi’s subprocessor information.
Where applicable law requires disclosure concerning automated decisions that could significantly affect an individual’s rights or interests, Soldofi or the relevant customer will provide additional information appropriate to the processing involved.
7. Legal Bases
Where laws such as the UK GDPR require a legal basis for processing, Soldofi may rely, as applicable, on:
- performance of a contract
- steps requested before entering a contract
- compliance with legal obligations
- legitimate interests
- consent; or
- another lawful basis permitted by applicable law.
Legitimate interests may include operating and securing the Services, preventing fraud, administering business relationships and improving the reliability of the Services, where those interests are not overridden by applicable individual rights.
Where Soldofi processes Customer Data solely on behalf of a customer, the customer is generally responsible for determining the appropriate legal basis for that processing.
8. How We Share Information
Soldofi does not sell personal information.
We may disclose information:
8.1 To Service Providers and Subprocessors
We may engage providers that support:
- cloud hosting
- databases and storage
- security
- email and communications
- monitoring
- customer support
- document processing
- artificial intelligence functionality
- accounting integrations; and
- other infrastructure required to provide the Services.
Providers receive information only as necessary for their functions and are subject to appropriate contractual obligations.
8.2 At the Customer’s Direction
Information may be disclosed to systems or recipients selected or authorised by the customer.
8.3 For Legal and Security Reasons
We may disclose information where reasonably necessary to:
- comply with applicable law
- respond to lawful legal process
- protect rights or property
- investigate fraud or abuse
- protect users or the public; or
- establish, exercise or defend legal claims.
8.4 Corporate Transactions
Information may be transferred as part of a merger, acquisition, financing, restructuring or sale of all or part of the business, subject to applicable law and contractual restrictions.
9. International Data Transfers
Soldofi operates a cloud-based service and information may be processed in countries other than the country in which it was originally collected.
Where required, Soldofi uses appropriate contractual, organisational and legal safeguards for international transfers.
Depending on the applicable jurisdiction, these safeguards may include:
- adequacy regulations or recognised adequate jurisdictions
- standard contractual clauses
- the UK International Data Transfer Agreement or UK Addendum
- contractual requirements imposed on subprocessors; or
- another legally recognised transfer mechanism.
Where Australian privacy law applies, Soldofi will take reasonable steps required by applicable law in relation to overseas recipients.
Soldofi will maintain information regarding material subprocessors and relevant processing locations where appropriate.
10. Security
Soldofi maintains administrative, technical and organisational measures designed to protect information against:
- unauthorised access
- accidental or unlawful destruction
- loss
- alteration
- unauthorised disclosure; and
- misuse.
Depending on the system and risk, measures may include:
- encryption in transit
- encryption or equivalent protections at rest
- access controls
- role and permission controls
- segregation of duties
- authentication controls
- secrets management
- audit logging
- environment separation
- vulnerability management
- backups
- monitoring
- incident response procedures; and
- supplier security controls.
No system can be guaranteed to be completely secure.
Customers remain responsible for protecting their credentials, configuring their users appropriately and maintaining appropriate security over systems outside Soldofi’s control.
11. Security Incidents and Personal Data Breaches
Soldofi maintains procedures for identifying, investigating and responding to suspected security incidents.
Where Soldofi processes personal information on behalf of a customer and becomes aware of a qualifying personal-data breach, Soldofi will notify the affected customer in accordance with applicable law and the applicable Data Processing Addendum.
Where Soldofi is responsible for notifying regulators or affected individuals, Soldofi will provide notifications within the periods required by applicable law.
12. Data Retention
Soldofi retains personal information only for as long as reasonably necessary for the purposes for which it was processed, including to:
- provide the Services
- satisfy contractual requirements
- maintain security and audit records
- comply with accounting, tax or legal obligations
- resolve disputes; and
- establish or defend legal claims.
Retention periods vary according to the type of information and its purpose.
Customer Data is retained in accordance with the applicable customer agreement, product configuration and Soldofi’s retention procedures.
Following termination or a valid deletion request, Customer Data will be deleted or returned in accordance with the applicable agreement, subject to:
- backup cycles
- legal retention requirements
- security requirements; and
- information that must be retained to establish or defend legal claims.
Backup copies may remain for a limited period until overwritten or deleted through normal backup lifecycle processes.
13. Account and Integration Disconnection
Customers may disconnect supported third-party integrations using functionality made available by Soldofi or the third-party provider.
Disconnecting an integration prevents future access once the relevant credentials or authorisations cease to be valid, but does not necessarily delete information previously imported into Soldofi.
Previously imported information remains subject to the customer’s retention settings, contractual arrangements and applicable law.
14. Privacy Rights
Privacy rights differ by jurisdiction and circumstances.
Where applicable, an individual may have rights concerning:
- access to personal information
- correction
- deletion or erasure
- restriction of processing
- objection to processing
- data portability
- withdrawal of consent
- information concerning processing
- complaints to a regulator; and
- certain automated decision-making.
Some rights are subject to exemptions and legal limitations.
Where Soldofi processes personal information solely on behalf of a customer, individuals should ordinarily submit requests to the relevant customer. Soldofi will provide reasonable assistance to customers as required by applicable law and the DPA.
Requests concerning information for which Soldofi acts independently may be sent to support@soldofi.com.
We may take reasonable steps to verify the identity and authority of a requester.
15. India
Where India’s Digital Personal Data Protection Act, 2023 and applicable rules apply, references in this Privacy Policy to a controller or processor should be understood, where appropriate, to include the corresponding concepts of a Data Fiduciary and Data Processor.
Subject to the applicable provisions being in force, Data Principals may have rights including rights concerning access to information, correction, erasure and grievance redressal.
Where consent is relied upon, Soldofi will implement consent and withdrawal mechanisms as required by applicable law.
16. United Kingdom
Where UK data-protection law applies, individuals may have rights under the UK GDPR and Data Protection Act 2018, including rights of access, rectification, erasure, restriction, portability and objection, subject to applicable conditions and exemptions.
Individuals may also have the right to complain to the UK Information Commissioner’s Office.
Where Soldofi processes personal information on behalf of a customer, the relevant customer ordinarily remains responsible for responding to the individual’s request.
17. Australia
Where the Australian Privacy Act 1988 and Australian Privacy Principles apply, individuals may request access to or correction of personal information as permitted by law.
Individuals may also submit privacy complaints to Soldofi.
We will investigate applicable complaints and respond within a reasonable period.
Where appropriate, a complaint may also be made to the Office of the Australian Information Commissioner.
Where Soldofi is likely to disclose personal information to overseas recipients, information regarding relevant locations will be maintained or disclosed where required and practicable.
18. United States
Privacy rights in the United States vary by state.
Where applicable state privacy laws apply, individuals may have rights such as:
- knowing or accessing personal information
- correction
- deletion
- portability
- opting out of certain processing; or
- appealing certain privacy decisions.
Soldofi does not sell personal information.
Soldofi does not use personal information obtained through the Services for cross-context behavioural advertising.
Where Soldofi acts as a service provider or contractor on behalf of a customer under applicable US privacy law, Soldofi processes personal information for the permitted business purposes specified in its agreement with that customer and subject to applicable contractual restrictions.
19. Cookies
Soldofi’s use of cookies and similar technologies is described in the Soldofi Cookie Policy.
The current Soldofi public website is designed to operate without advertising or cross-site tracking cookies.
If Soldofi introduces analytics, advertising or other non-essential tracking technologies, Soldofi will update its Cookie Policy and implement consent or choice mechanisms where required.
20. Children’s Privacy
Soldofi is a business-to-business service and is not directed to children.
Soldofi does not knowingly offer the Services directly to children.
If we become aware that personal information concerning a child has been collected in circumstances requiring deletion or parental authorisation, we will take appropriate steps consistent with applicable law.
21. Changes to This Privacy Policy
We may update this Privacy Policy as our Services, legal obligations or privacy practices change.
The “Last Updated” date will identify the latest version.
Where required by law or where a change materially affects how personal information is processed, we will provide additional notice.
22. Contact and Complaints
Privacy questions, rights requests and complaints may be directed to:
SOLDOFI SOLUTIONS PRIVATE LIMITED
P-303, INDRAPRASTH-6, PRAHALADNAGAR
Ahmedabad – 380015, Gujarat, India
Email: support@soldofi.com