Privacy Policy
Effective date: 20 August 2026 | Last updated: 20 August 2026
This policy covers the One Acc AI web application (app.oneacc.ai), the One Acc Lens mobile app, and this website (oneacc.ai). It is written to describe what the software actually does today; it will be updated as the product changes.
1. Who We Are
Company: One Acc Ltd
Registered in: England and Wales, company number 17186631
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
Website: https://oneacc.ai
Privacy contact: admin@oneacc.co.uk
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our role depends on whose data is involved:
- For your account (your name, email address, sign-in details, and how you use the service) we are the data controller.
- For the business records you keep in One Acc AI — your customers, suppliers, employees, invoices, bank transactions and the documents you upload — you are the data controller and we are your data processor. We process that data only on your instructions, as set out in our Terms. You are responsible for having a lawful basis to hold it and for telling the people concerned.
2. Data We Collect
2.1 Your account
- First name, last name and email address.
- Your password, stored only as a salted PBKDF2-SHA256 hash. We cannot read it. If you sign in with Google or Microsoft we never receive a password.
- Multi-factor authentication data where you enable it: one-time codes sent to your email, an authenticator-app (TOTP) secret, or passkey public keys (WebAuthn). Passkey private keys never leave your device.
- Sign-in security state: failed-attempt counts, temporary lock-outs, email verification and invitation tokens.
2.2 Your organisation
- Legal name, company registration number, registered address, VAT number, country, base currency and financial year.
2.3 Your business records (we act as processor)
- Customers and suppliers: names, contact names, email addresses, phone numbers, postal addresses, tax numbers, bank details and payment terms.
- Invoices, bills, receipts, expenses, payments and credit notes.
- Chart of accounts, journal entries and financial reports.
- Bank accounts and transactions, where you connect a bank feed (see section 6) or import statements.
- Documents you upload or scan, and the data extracted from them (supplier name, dates, amounts, tax values, invoice numbers, line items).
2.4 Connections you authorise
- OAuth access and refresh tokens for services you connect (Google Drive and Sheets, bank providers, HMRC). We never see the password for those services. You can revoke access at the provider at any time.
2.5 Activity and technical data
- Change history (audit trail). Every change to a business record is logged with the user's ID and email address, the time, and the before-and-after values. This is how an accounting system proves who changed what.
- Read access (sampled). A sample of about one in ten read requests is logged with the user ID, the record type and the request parameters, to detect misuse.
- Service telemetry. Our servers record request logs, errors and performance data in Microsoft Azure Application Insights. These may contain your IP address, user agent and the URLs you request, including the identifiers of records you open.
- AI assistant conversations. Messages you type to the in-app assistant and the data it retrieves to answer you (see section 5).
2.6 The One Acc Lens mobile app
- Camera — used only when you choose to scan a document. Never in the background. The app does not record video or audio.
- Scanned documents — converted to PDF on your device and uploaded over an encrypted connection to api.oneacc.ai, together with the capture time and the destination you choose (Inbox, Sales or Purchases).
- Sign-in — the app has no login form of its own. “Sign in with One Acc” opens app.oneacc.ai in your browser; “Continue with Google” uses the Google account on your device and gives us your name, email address and Google account ID. The session token is kept in the device's secure storage (Android Keystore / iOS Keychain).
- Updates — the app checks Expo's update service (u.expo.dev) on launch for new application code. That request carries the app version, platform and a per-install identifier, not your account data.
- The app contains no advertising, analytics or crash-reporting SDKs and does not request location, contacts or microphone access.
2.7 This website
oneacc.ai is a static site. It sets no cookies and runs no analytics or tracking scripts. If you email us, we keep the correspondence.
3. How We Use Your Data and Why We May
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Providing the service: accounts, ledgers, documents, reports, bank feeds, AI extraction and assistant | Contract (6(1)(b)); for your business records, your instructions as processor |
| Creating and securing your account, MFA, email verification | Contract (6(1)(b)) |
| Audit trail, read-access sampling, lock-outs, service logs | Legitimate interests (6(1)(f)): security, integrity of accounting records, fraud prevention |
| Transactional email (verification, password reset, invitations, MFA codes) | Contract (6(1)(b)) |
| Responding to your enquiries and support requests | Contract / legitimate interests |
| Complying with law, court orders and regulators | Legal obligation (6(1)(c)) |
We do not send marketing email, do not profile you for advertising, and do not use your data to train machine-learning models. If we introduce marketing communications we will ask for your consent first.
4. Where Your Data Is Hosted
The platform runs on Microsoft Azure in the European Union:
- Databases (Azure SQL and Cosmos DB: accounts, ledgers, audit trail) — France Central (Paris).
- Application servers, uploaded documents, secrets and logs — West Europe (Netherlands).
- The web front end is delivered through Azure's global content network; it holds no data of its own.
Some of the providers in section 6 are outside the UK and EU, principally in the United States. Where personal data reaches them we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or the UK–US Data Bridge, as applicable to each provider.
5. Artificial Intelligence
One Acc AI uses a large language model, currently OpenAI's GPT-4o via the OpenAI API, for the features below. Please read this section carefully, because it means some of your business data is sent to OpenAI in the United States.
- Document reading. When a receipt, invoice or bill is uploaded or scanned, the full image (or, for PDFs, the extracted text) is sent to the model to read the supplier, dates, amounts, tax and line items. For bills, the names and codes of your expense accounts are sent too, so the model can suggest a category.
- The in-app assistant. Your questions are sent to the model together with the data needed to answer them, which can include contact names and balances, invoices, bank accounts and financial reports from your ledger. The assistant can only read your data; it has no ability to create, change or delete records.
- Every AI result is a suggestion. Nothing is posted to your ledger until a person reviews and confirms it.
- We use OpenAI's API under its business terms, which state that API inputs and outputs are not used to train OpenAI's models.
- There is currently no setting to turn AI processing off. If you need your data excluded from AI processing, contact admin@oneacc.co.uk before uploading documents or using the assistant.
- The platform is also capable of using Azure OpenAI, Google Gemini or DeepSeek as the model provider. We will update this section and notify you before any provider other than OpenAI is used for your data.
6. Who We Share Data With
We do not sell personal data and do not share it with advertisers. Data goes to the following categories of provider, each under a contract that limits them to providing their service to us:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting, databases, document storage, secrets, logging | EU (France, Netherlands) |
| OpenAI | Document reading and the AI assistant (section 5) | USA |
| Twilio SendGrid | Transactional email to you (verification, reset, MFA codes, invitations) | USA |
| Google (Sign-In, Drive, Sheets) | Only if you sign in with Google or connect Drive/Sheets | USA |
| Microsoft (Entra ID) | Only if you sign in with a Microsoft account | EU/USA |
| Plaid; GoCardless Bank Account Data; Revolut Business; Wise | Only if you connect a bank feed. Your bank authorises the connection directly with the provider. | USA / UK / EU |
| Stripe; PayPal; GoCardless | Only if you enable online payment of your invoices. Your customer pays the provider directly; we receive the payment status, never card details. | USA / UK |
| HM Revenue & Customs | Only if you connect HMRC (section 7) | UK |
| Companies House | Looking up UK company details you ask for | UK |
| Open Exchange Rates | Currency rates. No personal data is sent. | USA |
| Expo (EAS) | Delivering updates to the mobile app | USA |
We will also disclose data where the law requires it, for example to a court or regulator, and in the course of a merger or sale of the business, in which case this policy continues to apply.
Google API Services. One Acc AI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Drive and Sheets data is used only to provide the import and export features you invoke.
7. HMRC and Making Tax Digital
One Acc AI includes a Making Tax Digital for VAT connection. It is currently operating against HMRC's test environment and is not yet available for live VAT submissions. When it is, the following will apply:
- You authorise the connection through HMRC's own sign-in. We receive an OAuth token, never your Government Gateway password, and you can revoke it in your Government Gateway account.
- HMRC requires software to send fraud-prevention headers with every request: your public IP address and port, timezone, screen resolution, browser window size and user agent, plus the IP address our server sees. This is a legal requirement of HMRC, not our choice.
- Submissions are encrypted in transit with TLS 1.2 or higher.
8. How Long We Keep Data
| Data | Retention |
|---|---|
| Account and organisation data | Until you ask us to delete your account (section 9) |
| Business records, uploaded documents and extracted data | Until you delete them or close your account. Accounting records may be retained for up to 6 years after closure where UK tax law requires it, locked to legal and compliance access only. |
| Change history (audit trail) | 7 years, to match statutory record-keeping periods |
| Read-access sampling | 90 days |
| Server logs and telemetry | 90 days |
| Encrypted backups | Rotated out within 35 days |
| Email correspondence with us | Up to 24 months after the matter closes |
9. Your Rights
Under UK GDPR you can ask us for access to your personal data, to correct it, to erase it, to restrict or object to our processing, and to receive it in a portable format. You are also entitled not to be subject to decisions based solely on automated processing that significantly affect you — One Acc AI makes no such decisions; every AI output is reviewed by a person.
- Requests are handled by email at admin@oneacc.co.uk. There is not yet a self-service export or account-deletion button in the app. We respond within one month.
- To close your account and have its data erased, including documents scanned with the mobile app, follow the steps on Delete Your Account.
- If your data is held in One Acc AI by a business you deal with (for example, you are their customer or supplier), please contact that business; they control that data and we will assist them.
You may complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve the matter first.
10. Security
- All connections use TLS 1.2 or higher; storage accounts refuse plain HTTP.
- Data at rest is encrypted by Azure's storage-service encryption (AES-256) for databases, document storage and backups.
- Passwords are hashed with PBKDF2-SHA256 (100,000 iterations, per-user salt).
- Multi-factor authentication is available to every user (email code, authenticator app, passkeys) and an organisation can make it mandatory.
- Accounts lock for 15 minutes after 5 failed sign-in attempts.
- Our database accepts only Azure Active Directory identities; application secrets are held in Azure Key Vault and never in source code.
- Each organisation's documents are kept in a separate storage container.
If a breach is likely to put your rights at risk we will notify the ICO within 72 hours of becoming aware of it and tell you without undue delay.
11. Cookies and Local Storage
We do not use cookies, and we do not use any analytics or advertising technology. The web application stores the following in your browser:
- Local storage: your session token and selected organisation (so you stay signed in), and interface preferences such as dismissed checklists.
- Session storage (cleared when the tab closes): sign-in state during Google/Microsoft login, unsaved form drafts, and the hand-off used to sign the mobile app in.
Clearing your browser storage signs you out and discards unsaved drafts; nothing else is affected.
12. Children
One Acc AI is a business service for people aged 18 and over. We do not knowingly collect data from children; if you believe we have, contact admin@oneacc.co.uk and we will delete it.
13. Changes to This Policy
When we change this policy in a way that matters — a new sub-processor, a new use of your data, a change of AI provider — we will email account holders at least 14 days before the change takes effect and update the date at the top of this page.
14. Contact
One Acc Ltd, 128 City Road, London, EC1V 2NX, United Kingdom
Email: admin@oneacc.co.uk