01 Who we are
The data controller for the personal data described in this policy is RVODE LIMITED, a company registered in [England and Wales] under company number [company number], registered office [registered address] (“rVODE”, “we”, “us”).
rVODE is a product of ADROIT². For privacy questions, or to exercise any of the rights in section 8, contact us using the details in section 12.
02 What we collect
We collect only what we need to run your books and operate the service.
| Category | Examples |
|---|---|
| Identity & account | Name, email, sign-in credentials and passkeys, identity-verification result, business/entity details, tax reference (UTR or equivalent). |
| Financial & bookkeeping | Invoices, deal memos, expenses, receipts, transactions, ledger entries, VAT and status determinations (e.g. IR35) you record, payroll inputs. |
| Bank data (read-only) | Account and transaction information retrieved through a licensed open-banking provider, with your authorisation, for reconciliation only. |
| Usage & device | Log data, IP address, device and browser type, and essential interaction data needed to secure and operate the service. |
| Communications | Messages you send us, support requests, and waitlist sign-up details. |
We do not sell personal data, and we do not use your financial data to train models for unrelated purposes. [Confirm AI-processing scope with legal.]
03 Why we process it & our lawful basis
- To provide the service — keeping your books, preparing invoices and filings, reconciling payments. Lawful basis: performance of a contract.
- To meet legal obligations — bookkeeping, tax, and record-retention duties. Lawful basis: legal obligation.
- To secure and improve the service — fraud prevention, debugging, service analytics. Lawful basis: legitimate interests, balanced against your rights.
- Open-banking access — retrieving your bank data read-only. Lawful basis: your explicit authorisation, which you can withdraw at any time.
- Marketing & waitlist updates — only where you have asked to hear from us. Lawful basis: consent.
04 Open banking & your money
rVODE reads your bank data read-only through Tink, a licensed open-banking provider, and only with your authorisation. We use it to reconcile payments and keep your books current.
rVODE never holds your money. We never take custody of funds, operate a wallet, or hold a float. We prepare payment files and links; the money always moves through your own bank, in full, directly. You can withdraw open-banking authorisation at any time, which stops further bank-data retrieval.
06 Where your data lives
All personal data is stored inside the European Union — primary region Stockholm, fallback Frankfurt. It does not leave the EU. Where any processor operates outside the EU, transfers are governed by appropriate safeguards (e.g. Standard Contractual Clauses). [Confirm all sub-processor locations with legal.]
07 How long we keep it
We keep bookkeeping and tax records for the period the law requires, then delete or anonymise them.
- Bookkeeping & tax records — retained for the statutory period ([UK: 6 years; Sweden: 7 years per Bokföringslagen]), then deleted.
- Account data — kept while your account is active, and for a limited wind-down period after closure.
- Waitlist data — kept until launch in your market or until you ask us to remove it, whichever is first.
- Marketing consent — until you withdraw it.
08 Your rights
Subject to the law, you have the right to access, correct, delete, restrict, or object to our processing of your data, to data portability, and to withdraw consent at any time. You may also lodge a complaint with a supervisory authority — in the UK the Information Commissioner's Office (ICO); in Sweden the Integritetsskyddsmyndigheten (IMY).
To exercise any right, contact us using section 12. We respond within the statutory timeframe (generally one month).
10 Security
We protect your data with encryption in transit and at rest, access controls, verified sign-in (passkeys, GOV.UK One Login, or BankID), and EU-resident infrastructure. No system is perfectly secure, but we hold ourselves to professional-grade controls and review them regularly. [Confirm certifications/standards with legal — e.g. ISO 27001 if/when held.]
11 Changes to this policy
We may update this policy as the service evolves or the law changes. We will post the new version here with an updated effective date and, for material changes, tell you directly.
12 Contact & Data Protection Officer
Privacy questions or rights requests: privacy@rvode.com.
Data Protection Officer: dpo@rvode.com · [DPO name, if appointed].
Postal: [registered address].