Legal
Privacy Policy.
This policy explains what personal data we collect when you use vorsye.ai or the VORSYE product, why we collect it, who processes it on our behalf, and the rights you have over it. We are a UK company and we keep things short and honest: we collect the minimum needed to run the service, we do not sell your data, and we do not run advertising trackers on this website.
Last updated: 26 September 2026
- 01 About this policy
- 02 Who we are (controller and processor roles)
- 03 The data we collect
- 04 How we use your data and our legal bases
- 05 AI features and your data
- 06 Cookies
- 07 Sub-processors
- 08 International transfers
- 09 How long we keep data
- 10 How we protect your data
- 11 Your rights
- 12 Marketing communications
- 13 Children
- 14 Third-party sites and services
- 15 Complaints
- 16 Changes to this policy
- 17 Contact
About this policy.
This policy explains how we handle personal data across the vorsye.ai website (including the waitlist, contact forms, and free tools) and the VORSYE product. It is written for the UK GDPR and the Data Protection Act 2018. If you access VORSYE from the EU or EEA, the EU GDPR applies to you on equivalent terms, and references to "UK GDPR" should be read as "EU GDPR" where relevant.
Who we are.
VORSYE is the data controller for the personal data described in this policy. Where one of our business customers adds their own team members or accountant to their VORSYE account, we process those people's data on the customer's behalf as a processor; the customer remains the controller of that data and this policy describes how we handle it as their service provider.
- Entity: [REGISTERED ENTITY NAME]
- Registered in England and Wales, company number [•]
- Registered office: [•]
- Privacy contact: privacy@vorsye.ai
We have not appointed a data protection officer because we are not currently required to. Privacy questions are handled by the team at privacy@vorsye.ai.
The data we collect.
On this website
- Waitlist signups: your name and email address.
- Contact form: your name, email address, the category you select, and your message.
- Free tools (invoice generator and similar): only the data you type into a tool during your session, where the tool needs to process it. We do not link tool inputs to an account.
- Technical data: standard server logs (IP address, browser type, pages requested, timestamps) recorded by our hosting infrastructure for security and reliability.
- We do not use advertising trackers, third-party analytics scripts, or marketing cookies on this website.
In the VORSYE product
- Account data: your name, email address, organisation name and settings, and authentication identifiers.
- Financial data: invoices, bills, expenses, transactions, tax information, reports, and the documents you upload (receipts, invoices, bank statements).
- Bank data: account and transaction data retrieved from your banks through open banking aggregators, only after you explicitly connect an account.
- Connected apps data: where you link third-party accounting or business software through our integrations platform, the data synced from those connections.
- Identity verification data: where required by law (for example anti-money-laundering checks), identity document details, a selfie or liveness image, and phone number.
- Billing data: payment method details are processed by our payment provider. We do not store full card numbers.
- Usage data: product interaction events used to operate, secure, and improve the service. Events are encrypted before they leave our servers.
How we use your data.
| Purpose | Legal basis |
|---|---|
| Provide and operate the service you signed up for | Performance of a contract |
| Process payments and manage your subscription | Performance of a contract |
| Verify identity where the law requires it | Legal obligation |
| Respond to contact and waitlist requests | Legitimate interests (and consent where you opted in) |
| Secure the service, prevent fraud, maintain backups | Legitimate interests |
| Improve the product from usage data | Legitimate interests |
| Send you service messages (receipts, alerts, notifications) | Performance of a contract |
We do not use your data for automated decision-making with legal or similarly significant effects. AI-assisted features (such as transaction categorisation suggestions) produce suggestions that a human reviews; they never act alone on your finances.
AI features and your data.
VORSYE uses AI features to help categorise transactions, draft document chases, and summarise financial information. Your financial data may be processed by our AI providers to produce these features (see section 7). We do not use your personal data or financial data to train general-purpose AI models, and we do not sell it for AI development.
Cookies.
This website uses only essential cookies needed to make forms and sessions work. The product uses session cookies to keep you signed in. We do not set advertising or cross-site tracking cookies. Because we do not use non-essential cookies on this website, no cookie consent banner is required under PECR; if we ever add non-essential cookies, we will ask for consent first and update this policy.
Sub-processors.
We use a small number of trusted companies to operate VORSYE. Each is contractually bound to protect your data and processes it only on our instructions.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Stytch | Authentication and session management | Email address, auth identifiers |
| Stripe | Payment processing and billing | Name, email, payment method data |
| Resend | Transactional email delivery | Email address, message content |
| FormSubmit | Contact form delivery on vorsye.ai | Name, email, message you submit |
| Didit | Identity verification (KYC/AML, where required) | ID document images, selfie/liveness image, phone number |
| Salt Edge | Open banking aggregation | Bank account and transaction data you connect |
| Unified.to | Unified integrations platform (accounting and business software connections) | Connection credentials and the accounting/financial data synced from the services you connect |
| Directus | Content management for this website (self-hosted) | Website content only; no customer personal data |
| Synadia | Managed message infrastructure | Encrypted event payloads only. Every event is encrypted before transmission, so no readable personal data is exposed |
| Tencent Cloud | AI document extraction and insights | Uploaded documents (receipts, invoices) and the financial data sent for AI features [CONFIRM EXACT SCOPE] |
Infrastructure we run ourselves (databases, caches, feature flags, PDF generation) is not a sub-processor relationship; it operates under our direct control on our hosting.
If we add or change sub-processors, we will update this table and give advance notice to product customers where the change affects their data.
International transfers.
Our primary hosting is in [HOSTING REGION]. Some sub-processors operate outside the UK, including in the United States. Where personal data leaves the UK, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and on transfer risk assessments. For transfers out of the EEA, the EU Standard Contractual Clauses apply. You can request a copy of the transfer safeguards we rely on by writing to privacy@vorsye.ai.
How long we keep data.
- Website form submissions (waitlist, contact): kept for as long as needed for the purpose you submitted them, then deleted. [RETENTION PERIOD]
- Product account and financial data: kept while your account is active. On account closure we retain records only as long as UK tax and accounting law requires (typically six years), then delete or irreversibly anonymise them.
- Identity verification data: retained for the period required by anti-money-laundering regulations, then deleted.
- Server logs: kept for a short period for security purposes, then rotated. [LOG RETENTION]
How we protect your data.
Financial records deserve more than the standard promise, so security is built into how VORSYE works: data is encrypted at rest and in transit, access to customer data is restricted by role, events between systems are encrypted end to end, and our secrets and keys are held in a dedicated secrets manager. No system is perfect, but we design so that a single failure does not expose your records. If a breach ever affects your personal data, we will notify you and the ICO as the law requires.
Your rights.
Under the UK GDPR you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: have inaccurate data corrected.
- Erasure: have data deleted where there is no legal reason to keep it.
- Restriction: limit how we use your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests, including profiling.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any right, email privacy@vorsye.ai. We will respond within one month. We may need to verify your identity first. These rights are free to exercise; we only charge for manifestly unfounded or excessive requests.
Marketing communications.
We only email you about your account and service. The waitlist sends one email when your spot opens. If we ever send product news, every email will include an unsubscribe link, and you can opt out at any time without losing access to the service.
Children.
VORSYE is a business accounting service and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact privacy@vorsye.ai and we will delete it.
Third-party sites and services.
Our website and product link to third-party sites and connect to services you choose (banks, accounting software, payment providers). Once you leave our website or connect a third-party service, that provider's own privacy policy applies to how they handle your data. We are not responsible for their practices.
Complaints.
If you are unhappy with how we handle your data, you can complain to the UK supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
ico.org.uk, helpline 0303 123 1113
We would appreciate the chance to address your concern first, so please contact privacy@vorsye.ai before escalating.
Changes to this policy.
We will update this policy when our practices or the law change. The "Last updated" date at the top always reflects the current version. Material changes will be announced to product customers by email or in-product notice before they take effect.