Privacy Policy

Last updated 29 July 2026

Analytix Pro ("we", "us") provides an AI finance review and risk detection service. This policy explains what personal data we collect, why we collect it, how we protect it and the rights you have. We are the data controller for account data and a data processor for the financial records you connect or upload.

1. Who we are

Analytix Pro, United Kingdom. For any privacy question, data request or complaint, contact support@analytixpro.co.uk.

2. Data we collect

  • Account data: name, work email, organisation name, role, password hash (managed by our authentication provider) and multi-factor authentication settings.
  • Financial data: ledger records you upload (CSV, Excel, PDF) or that we retrieve from accounting platforms you connect — including profit and loss, balance sheet, invoices, bills, journals, customers and suppliers, and aged debtor/creditor balances.
  • Billing data: subscription tier, invoice history and payment status. Card details are handled directly by Stripe; we never see or store them.
  • Usage data: pages viewed, features used, AI requests made, and technical logs such as timestamps and error traces.
  • Marketing data: email address and interest, where you submit it to a calculator, health check or enquiry form.

3. Accounting platform connections (Xero, QuickBooks)

When you connect an accounting platform, you authorise us via OAuth 2.0. We never receive or store your accounting platform password. We store encrypted access and refresh tokens so we can retrieve data on your behalf.

We request read access only to the data needed to review your ledger and detect risk: company profile, reports, transactions, contacts and invoice/bill balances. We do not write to, alter or delete anything in your accounting platform.

You can disconnect at any time from Connections inside the app, or from within your accounting platform's connected apps settings. On disconnection we revoke the tokens and stop all further access. Synced data is deleted on request, and automatically within 90 days of account closure.

4. Why we use your data (lawful bases)

  • To provide the service — performance of a contract. Running reviews, detecting anomalies, generating reports, forecasts and recommendations.
  • To secure the service — legitimate interests. Access control, audit logging, fraud and abuse prevention.
  • To bill you — performance of a contract and legal obligation.
  • To support and improve — legitimate interests. Responding to tickets, fixing faults, measuring aggregate feature usage.
  • To send marketing — consent, which you can withdraw at any time using the unsubscribe link in any email.

5. AI processing

We use large language models to analyse your financial data and produce findings, commentary and answers to your questions. Data sent to our AI providers is used solely to return a result to you. Our AI providers are contractually prohibited from using your data to train their models, and prompt content is not retained for training purposes.

AI output is advisory. It supports professional judgement; it does not replace it, and it is not accounting, audit, tax or legal advice. Analytix Pro is a software provider, not a regulated accountancy, audit, tax or financial services firm.

No solely automated decisions. We do not make decisions about you that produce legal or similarly significant effects using automated processing alone. Findings, scores and recommendations are surfaced for a human in your team to review, accept or dismiss, and every finding links back to the underlying records so it can be checked.

6. Sharing and sub-processors

We do not sell your data. We share it only with the providers needed to run the service:

  • Supabase (via Lovable Cloud) — Database, authentication and encrypted file storage (EU/UK region).
  • Lovable Cloud / Cloudflare — Application hosting and edge delivery.
  • Google (Gemini) via the Lovable AI Gateway — AI analysis, commentary and chat responses, under zero-retention, no-training terms.
  • Stripe — Subscription billing and card processing.
  • Resend — Transactional and notification email (notify.analytixpro.co.uk).
  • Resend — outreach sender — Business-development email to prospect contacts, sent from a separate subdomain (mail.analytixpro.co.uk) so it is isolated from customer email.
  • Frankfurter (European Central Bank data) — Daily foreign exchange reference rates.
  • Xero, Intuit QuickBooks and Sage — Read-only accounting data, only where you choose to connect them.

We keep this list current and will give account owners notice by email before adding a sub-processor that materially changes how your data is handled, so you can object.

Where data is transferred outside the UK/EEA, we rely on UK International Data Transfer Agreements or Standard Contractual Clauses. We may also disclose data where required by law.

7. Security

Data is encrypted in transit (TLS 1.2+) and encrypted at rest by our hosting platform's managed infrastructure encryption (disk- and object-storage-level AES-256). We do not operate customer-managed encryption keys or a hardware security module. Accounting platform tokens are encrypted with a separate application key. Every workspace is isolated by row-level security, uploaded files live in a private bucket with no public URLs, and privileged actions are recorded in an audit log. Multi-factor authentication is available and can be enforced across your workspace.

8. Retention

  • Account and workspace data: for the life of your subscription.
  • Ledger and synced financial data: until you delete it, or 90 days after account closure.
  • Audit logs: per your configured retention window, pruned automatically.
  • Billing records: six years, to meet UK statutory requirements.
  • Marketing contacts: until you unsubscribe or ask us to erase them.

9. Your rights

Under UK GDPR you have the right to access, correct, erase, restrict, port or object to our processing of your personal data, and to withdraw consent. Email support@analytixpro.co.uk and we will respond within 30 days. You may also complain to the Information Commissioner's Office at ico.org.uk.

10. Cookies

We use strictly necessary cookies and local storage to keep you signed in and remember preferences, plus minimal first-party analytics on aggregate product usage. We do not run third-party advertising trackers.

11. Children

The service is for business use and is not directed at anyone under 18.

12. Processing on your behalf (Article 28)

For the financial records you upload or connect, you are the controller and we are the processor. We process that data only on your documented instructions (your use of the service), keep our staff under confidentiality obligations, apply the security measures described above, use only the sub-processors listed in section 6, assist you with data subject requests and security incidents, and delete or return the data on termination as set out in section 8. These commitments, together with the End User Agreement, form our data processing terms. If your organisation requires a signed standalone DPA, email us and we will provide one.

13. Personal data breaches

We maintain an incident response process. If a breach affects your data, we will notify affected account owners without undue delay and, where we act as processor, within 72 hours of becoming aware, with the information you need to meet your own reporting duties. Suspected security issues can be reported to support@analytixpro.co.uk; we do not take legal action against good-faith security research.

14. Changes

We will update this page when our practices change and, for material changes, notify account owners by email before they take effect.

Questions? Email support@analytixpro.co.uk. See also our End User Agreement and Trust Centre.