Privacy

Colendo holds documents that accountants and bookkeepers collect from their clients. Most of it is financial and some of it identifies people, so this page says plainly what happens to it.

Where it lives

Documents and personal data are stored in the UK and EU (eu-west-2) and do not leave. We do not move data to other regions for processing.

Who can see it

The firm that collected it, and nobody else. Each firm’s data is isolated at the database level rather than by application code, so a query cannot reach across firms even by mistake.

Our support staff cannot read a firm’s documents unless that firm explicitly grants access, for a stated reason and a limited time. Those sessions are read-only, appear in the firm’s own activity log, and can be withdrawn at any moment.

Client links

A client receives a link rather than an account. The link is a secret with 256 bits of entropy, expires after 90 days, and can be protected with a PIN. We store a scrambled copy, so a link can never be shown twice — resending creates a new one and retires the old.

Uploads

Photo metadata — including the location a photo was taken — is removed before the file ever leaves the phone, and again on arrival, because a receipt photographed at home should not record somebody’s address.

Getting it back, and getting rid of it

A firm can export everything at any time as a ZIP with a readable summary. If a subscription lapses or is cancelled, read access and export remain — losing access to records a firm is obliged to keep would be indefensible.

How long it is kept

The firm decides, because the duty is theirs: an accountant has to keep client records for years after the work ends, and the money laundering regulations set a floor of five. Firms tell us how long they keep records — 6 years unless they say otherwise — and we refuse to erase a client inside that period unless an owner says in writing why those records can go early. A single client can be held for longer, with a reason and a date.

This page describes how the product is built. A reviewed privacy policy is coming; the data processing agreement a firm needs is published in draft.