DraftThis document is a working draft pending review by qualified legal counsel. Bracketed fields marked [like this] are to be completed before publication.
rVODE← Back to site

Legal · Privacy

Privacy Policy

Controller · RVODE LIMITEDVersion · 0.1 draftEffective · [date]Last updated · 20 June 2026

rVODE provides bookkeeping software for film and television freelancers and the companies who make their work. This policy explains what personal data we collect, why, how long we keep it, and the rights you have over it. We hold all data inside the European Union, and we never take custody of your money.

Contents

1 · Who we are2 · What we collect3 · Why & lawful basis4 · Open banking5 · Who we share with6 · Where data lives7 · Retention8 · Your rights9 · Cookies10 · Security11 · Changes12 · Contact & DPO

01 Who we are

The data controller for the personal data described in this policy is RVODE LIMITED, a company registered in [England and Wales] under company number [company number], registered office [registered address] (“rVODE”, “we”, “us”).

rVODE is a product of ADROIT². For privacy questions, or to exercise any of the rights in section 8, contact us using the details in section 12.

On the Swedish market. rVODE operates a waitlist in Sweden ahead of launch. Until a Swedish operating entity ([RVODE AB, once incorporated]) is formed, waitlist personal data is controlled by [operating entity]. This must be confirmed before go-live.

02 What we collect

We collect only what we need to run your books and operate the service.

CategoryExamples
Identity & accountName, email, sign-in credentials and passkeys, identity-verification result, business/entity details, tax reference (UTR or equivalent).
Financial & bookkeepingInvoices, deal memos, expenses, receipts, transactions, ledger entries, VAT and status determinations (e.g. IR35) you record, payroll inputs.
Bank data (read-only)Account and transaction information retrieved through a licensed open-banking provider, with your authorisation, for reconciliation only.
Usage & deviceLog data, IP address, device and browser type, and essential interaction data needed to secure and operate the service.
CommunicationsMessages you send us, support requests, and waitlist sign-up details.

We do not sell personal data, and we do not use your financial data to train models for unrelated purposes. [Confirm AI-processing scope with legal.]

03 Why we process it & our lawful basis

  • To provide the service — keeping your books, preparing invoices and filings, reconciling payments. Lawful basis: performance of a contract.
  • To meet legal obligations — bookkeeping, tax, and record-retention duties. Lawful basis: legal obligation.
  • To secure and improve the service — fraud prevention, debugging, service analytics. Lawful basis: legitimate interests, balanced against your rights.
  • Open-banking access — retrieving your bank data read-only. Lawful basis: your explicit authorisation, which you can withdraw at any time.
  • Marketing & waitlist updates — only where you have asked to hear from us. Lawful basis: consent.

04 Open banking & your money

rVODE reads your bank data read-only through Tink, a licensed open-banking provider, and only with your authorisation. We use it to reconcile payments and keep your books current.

rVODE never holds your money. We never take custody of funds, operate a wallet, or hold a float. We prepare payment files and links; the money always moves through your own bank, in full, directly. You can withdraw open-banking authorisation at any time, which stops further bank-data retrieval.

Tink processes your bank data as a provider under its own regulated permissions. See [Tink privacy notice link].

05 Who we share data with

We share personal data only with parties that help us run the service, each under a written data-processing agreement, and with authorities where the law requires it.

  • Open-banking provider — Tink, for read-only bank access.
  • Infrastructure & hosting — EU-based cloud hosting [provider name(s)].
  • Identity verification — [provider]; in the UK, sign-in via GOV.UK One Login; in Sweden, BankID.
  • Licensed accounting oversight — an independent licensed professional who reviews and, where you opt in, signs year-end returns.
  • Tax authorities — where you file, submissions are made to His Majesty's Revenue and Customs (or, at Swedish launch, Skatteverket) through recognised software.
  • Professional advisers & authorities — where required by law or to establish, exercise, or defend legal claims.

06 Where your data lives

All personal data is stored inside the European Union — primary region Stockholm, fallback Frankfurt. It does not leave the EU. Where any processor operates outside the EU, transfers are governed by appropriate safeguards (e.g. Standard Contractual Clauses). [Confirm all sub-processor locations with legal.]

07 How long we keep it

We keep bookkeeping and tax records for the period the law requires, then delete or anonymise them.

  • Bookkeeping & tax records — retained for the statutory period ([UK: 6 years; Sweden: 7 years per Bokföringslagen]), then deleted.
  • Account data — kept while your account is active, and for a limited wind-down period after closure.
  • Waitlist data — kept until launch in your market or until you ask us to remove it, whichever is first.
  • Marketing consent — until you withdraw it.

08 Your rights

Subject to the law, you have the right to access, correct, delete, restrict, or object to our processing of your data, to data portability, and to withdraw consent at any time. You may also lodge a complaint with a supervisory authority — in the UK the Information Commissioner's Office (ICO); in Sweden the Integritetsskyddsmyndigheten (IMY).

To exercise any right, contact us using section 12. We respond within the statutory timeframe (generally one month).

09 Cookies & similar technologies

We use strictly necessary cookies to sign you in and keep the service secure. We use non-essential or analytics cookies only with your consent, managed through our cookie banner. [Insert cookie table and consent-tool details before launch.]

10 Security

We protect your data with encryption in transit and at rest, access controls, verified sign-in (passkeys, GOV.UK One Login, or BankID), and EU-resident infrastructure. No system is perfectly secure, but we hold ourselves to professional-grade controls and review them regularly. [Confirm certifications/standards with legal — e.g. ISO 27001 if/when held.]

11 Changes to this policy

We may update this policy as the service evolves or the law changes. We will post the new version here with an updated effective date and, for material changes, tell you directly.

12 Contact & Data Protection Officer

Privacy questions or rights requests: privacy@rvode.com.

Data Protection Officer: dpo@rvode.com · [DPO name, if appointed].

Postal: [registered address].

For legal review. This draft is a starting framework, not legal advice. Confirm controller details, lawful bases, retention periods, sub-processor list, international-transfer mechanisms, cookie inventory, and the Swedish-entity position before publication.
rVODE
PrivacyTermsCookiesSecuritySub-processorsAccessibility
© 2026 RVODE LIMITED · EU-resident data