Legal

Privacy Policy

Last updated: 30 March 2026

Koovo Limited (“Koovo”, “we”, “us” or “our”) is committed to protecting personal data and handling it responsibly. This Privacy Policy explains how we collect, use, store, share and otherwise process personal data when you visit our website, request a demo, create an account, use our software, upload or connect documents and data sources, enable integrations, interact with our AI-assisted features, or otherwise engage with us. This policy is intended for users of our website and software platform, including bookkeeping firms, accountants, finance teams, consolidators, their personnel, prospective customers, and other business contacts. It also applies to personal data contained in documents and records processed through our platform, to the extent we act as a controller for that processing.

1. Who we are

Koovo Limited is a company incorporated in England and Wales. Company number: 16994171. Registered office: Shelton House, Shelton, Newark, Nottinghamshire, United Kingdom, NG23 5JQ. For privacy-related questions or to exercise your data protection rights, contact us at Privacy@Koovo.io.

2. Scope of this policy

This policy applies to personal data processed in connection with our website; demo requests, enquiries and marketing interactions; user accounts and platform administration; authentication and sign-in; billing and account management; document upload, import, syncing, OCR, extraction and bookkeeping workflows; third-party integrations; support, security, fraud prevention, analytics, product improvement and compliance activities; and AI-assisted features, model evaluation, model training, automation and related product development activities. It does not apply to third-party websites, products, platforms or services that we do not control.

3. Controller and processor roles

Koovo may act as either a data controller or a data processor, depending on the context and processing activity. We act as a controller for data used for our own business purposes, including website visitor data, prospect and customer contacts, user account and subscription information, billing, support, security, analytics, marketing, product development, quality assurance and model improvement. Where customers use our platform to process bookkeeping, accounting, tax, transaction or financial records relating to their own clients, staff, suppliers or customers, Koovo generally acts as a processor on the customer’s instructions. Customer-authorised accountants, bookkeepers, consolidators and other users may access data according to the permissions configured for the relevant account.

4. The personal data we collect

We may collect identity and account data, contact data, customer relationship data, billing and transaction data, technical, usage and security data, integration and connected-service data, document, transaction and bookkeeping data, AI input, output and model-improvement data, and consolidated or reporting data. This can include names, work email addresses, login information, organisation details, billing information, support communications, IP addresses, logs, connected-account information, invoices, receipts, transaction records, supplier and customer details, supporting business documents, uploaded text and images, prompts, AI-generated outputs, annotations, reviewer feedback, performance metrics and derived data used to test, validate, monitor, train, tune or improve our AI-assisted features, models and automation systems. We do not store full card details ourselves.

5. How we collect personal data

We collect personal data directly from you; automatically through your use of our website or platform; from your employer, firm or organisation; from authorised accountants, bookkeepers or consolidators; from identity and authentication providers; from payment providers and integration partners; from publicly available business sources where relevant; and from customers or authorised users who upload, sync, import, email or otherwise provide documents and data into the platform.

6. How we use personal data and our lawful bases

We only use personal data where we have a valid lawful basis under applicable data protection law. We use it to provide and operate our services; manage permissions and customer-authorised access; manage subscriptions and billing; provide support and respond to enquiries; secure systems and prevent fraud or misuse; improve, analyse and develop products and services; provide AI-assisted and automation features; train, tune, validate, test, evaluate, monitor and improve models and automation systems; communicate service updates; send marketing communications where permitted; and comply with legal and regulatory obligations. Depending on the activity, our lawful bases include contract performance, legitimate interests, legal obligation and consent.

7. AI-assisted features and human review

Our services may use AI-assisted or automated tools to help process documents and support bookkeeping workflows. These features are intended to assist users by extracting, classifying, matching, summarising or drafting information. They are not intended, by themselves, to make solely automated decisions about individuals that produce legal or similarly significant effects without appropriate safeguards and human involvement. Users should review outputs before relying on them for accounting, bookkeeping, tax, compliance or financial purposes.

8. Sharing personal data

We may share personal data where reasonably necessary with hosting, infrastructure, storage, backup, authentication, identity, payment, billing, customer support, communications, analytics, accounting, tax, bookkeeping, OCR, document-processing, AI and machine-learning providers; professional advisers; regulators and authorities; prospective corporate-transaction parties; and customers, organisations and authorised users within the platform. Providers or platforms we may use or connect with include AWS, OpenAI, Google / Gemini, Microsoft, Stripe, Xero, Sage, HMRC and other accounting, tax or finance platforms where connected or enabled. We only share personal data to the extent reasonably necessary for the relevant purpose.

9. International data transfers

Some service providers, subprocessors, partners or affiliates may process personal data outside the UK. Where we transfer personal data internationally, we take steps to ensure an appropriate level of protection, such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, standard contractual clauses or another lawful transfer mechanism permitted by applicable law.

10. Data retention

We retain personal data only for as long as reasonably necessary for the purposes in this policy, including service delivery, customer relationship management, legal, tax, accounting and regulatory obligations, dispute resolution, agreement enforcement, security records and product development. Prospect and enquiry data is usually retained for up to 24 months after the last meaningful interaction; account and customer relationship data, support records and operational correspondence are usually retained for up to 6 years where needed; technical, usage, audit and security logs are typically retained for up to 12 months; and customer-uploaded documents and workflow records are retained in accordance with customer agreements, instructions, backup cycles and legal requirements. Where we act as processor, we retain customer data in accordance with the customer agreement and instructions.

11. Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures may include access controls, authentication safeguards, encryption in transit and at rest where appropriate, logging and audit trails, role-based permissions, monitoring and alerting, vendor due diligence, security reviews, testing and change controls, and incident-response procedures. No system can be completely secure, but we work to maintain safeguards proportionate to the nature of the data we process.

12. Your rights

Depending on your circumstances and applicable law, you may have the right to access your personal data; request correction of inaccurate or incomplete data; request deletion; object to certain processing; request restriction; request transfer; withdraw consent where processing is based on consent; and complain to a supervisory authority. We will respond to rights requests without undue delay and within the timeframe required by applicable law. If Koovo acts as processor for the data in question, we may direct your request to the relevant customer or assist them in responding.

13. Cookies and similar technologies

We may use cookies, local storage, pixels, scripts, tags and similar technologies to operate our website and services, remember preferences, understand usage, improve performance, measure communications and support security. Where required by law, we will request consent before placing or using non-essential cookies or similar technologies. You can manage preferences through our cookie banner, browser settings or other tools we make available.

14. Third-party services and integrations

Our services may integrate with third-party products and services. If you enable integrations, personal data may be shared with or received from those third parties according to your settings, instructions, organisation’s permissions, the relevant workflow and the third party’s own terms and privacy notices. You are responsible for reviewing the privacy information of third-party services you choose to connect.

15. Children

Our services are intended for business use and are not directed to children. We do not knowingly collect personal data from children.

16. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above. Where required, we will notify users of material changes through the platform, by email or by other reasonable notice.

17. How to complain

If you have concerns about how we use personal data, please contact us first at Privacy@Koovo.io and we will try to resolve the issue. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) in the UK.

18. Contact us

If you have questions about this Privacy Policy or want to exercise your rights, contact: Koovo Limited, Shelton House, Shelton, Newark, Nottinghamshire, United Kingdom, NG23 5JQ. Email: Privacy@Koovo.io