Privacy Policy
What the platform processes, why it processes it, how long invoices and filings have to be kept, and how to exercise your rights over any of it.
Scope and roles
This policy explains how IIH Money handles information when you visit this website and when you or your organisation uses the platform to create, send, receive, file and archive invoices.
Two different roles apply, and which one applies changes how a request is handled and who decides the outcome:
- We act as a processor for the business records our customers put into the platform — invoices and their line items, tax identification numbers, payment records, customer and supplier details, records synced from connected systems, and submissions made to tax authorities. The customer decides what goes in and why; we process it to run the service on their instruction.
- We act as a controller for the information we need in order to operate: account and user records, authentication and security events, billing records for paid plans, and the enquiries you send us through the contact form.
The platform is built for business and professional use. It is not directed at children, and we do not knowingly collect information from them.
Information we process
Business records processed on a customer’s instruction
- Invoices and invoice line items — descriptions, quantities, amounts, currencies and tax treatment.
- Tax identification numbers, both for the customer’s own organisation and for the businesses it trades with.
- Payment records and the payment status held against each document.
- Customer and supplier business details — trading names, registered details, the addresses used for invoicing, and contact details for the people who handle billing.
- Credentials and access tokens used to connect ERP, accounting, CRM and banking systems, and the records synced through those connections.
- Submissions made to tax authorities, and the responses returned by them — including rejections, clearance results and reference numbers.
- Audit-trail events recording which action was taken on a document, by whom and when.
Invoice content is supplied by our customers. The platform does not ask for special categories of personal data and is not designed to hold them.
Information we hold in order to run the service
- Account and user records — names, work contact details, roles and permissions.
- Authentication and security events, including sign-in attempts and the network address recorded against them.
- Billing and plan records for paid plans.
- The content of enquiries sent to us through the contact form.
- Technical information your browser sends when it loads a page, and the browser storage described in our Cookie Policy.
Why we process it
Each purpose below is tied to the information it actually needs. Where a purpose no longer applies, the processing that served it stops.
| Purpose | Information used |
|---|---|
Creating, formatting and delivering invoices | Invoices and line items, customer and supplier details, tax identification numbers |
Reporting or clearing documents with a tax authority | Invoices, tax identification numbers, submission records and authority responses |
Reconciling payments and reporting on what is outstanding | Payment records and status, invoices |
Keeping connected systems in step | Connection credentials and tokens, synced records |
Accountability, internal review and dispute resolution | Audit-trail events, the documents they describe |
Operating accounts and protecting them from abuse | Account and user records, authentication and security events |
Billing for paid plans | Billing and plan records, account records |
Answering enquiries and providing support | Contact-form content, account records |
Keeping the service reliable and improving it | Aggregate usage and technical information, error and performance data |
We do not use the contents of invoices, tax identification numbers or connected-system records for advertising, for profiling unrelated to the service, or to train models for other customers’ benefit.
Legal bases for processing
Data-protection law differs between the jurisdictions the service reaches, and the framework that applies to a given record depends on where you and your counterparties are established. Where a legal basis is required, we rely on the following, in general terms:
- Performance of a contract — processing needed to provide the platform to the customer that asked for it, to operate an account, and to bill for it.
- Compliance with a legal obligation — processing needed to meet invoicing, reporting and record-retention requirements that attach to the documents themselves.
- Legitimate interests — securing the service, preventing abuse and fraud, maintaining audit trails, and understanding in aggregate how the platform is used. Where we rely on this we weigh it against your interests, and you can object — see your rights.
- Consent — for optional browser storage such as analytics, where the law that applies to you requires consent before it is set. Consent can be withdrawn; the Cookie Policy explains how.
Where we act as a processor, the legal basis for the underlying business records is determined by our customer as controller, not by us.
Service providers and connected systems
Service providers
Running the platform depends on third-party providers — hosting and infrastructure most obviously, and the tooling that supports the service around it. Where they handle information covered by this policy they do so only on our instruction, under written terms that restrict what they may do with it, and they are not permitted to use it for their own purposes. We remain answerable for them.
We do not sell information, and we do not disclose it to third parties for their own marketing.
If you need the current list of sub-processors for a due-diligence review, request it through the contact form and we will provide it. We do not publish the list on this page, because a list maintained on a marketing page goes out of date faster than the list itself changes.
Systems a customer connects
When a customer connects an ERP, accounting, CRM or banking system, records move between that system and the platform at the customer’s direction. Those systems are operated by their own providers, under their own terms and privacy notices, and we do not control what happens to data once it is inside them. Disconnecting a system stops further syncing; it does not recall records that have already been sent.
Tax authorities
Reporting and clearance are the point of the service. Where a document must be reported to or cleared by a tax authority, its contents are transmitted to that authority, which then processes it under its own legal powers rather than under this policy.
Legally compelled disclosure
We may disclose information where we are legally required to. We will require the request to be valid and properly scoped, will resist requests that exceed what the law requires, and will notify the affected customer wherever we are lawfully able to do so.
International transfers
The service is built to work across borders — the platform covers more than 100 countries and more than 200 tax authorities. Cross-border processing is therefore ordinary here rather than exceptional, and it happens in three ways:
- To the tax authority of the jurisdiction in which a document must be reported or cleared, which is frequently not the jurisdiction where you are established.
- To the systems a customer chooses to connect, which are hosted wherever their providers host them.
- To our own infrastructure and service providers, which may be located in a different country from you.
Where a transfer requires a specific legal mechanism in order to be lawful, that mechanism is identified in the data-processing terms that form part of the customer’s agreement, together with the hosting arrangements that apply to that customer. We do not restate them on this page, because they differ by customer and by jurisdiction and a generalised summary would be misleading.
How long we keep information
Invoices are not ordinary records that can be deleted on request. Tax law in most jurisdictions requires the issuer, and often the recipient, to retain invoices and the evidence of their transmission for a period after the tax period they belong to. That period is set by the law applying to the document, not by us, and it is why parts of this policy cannot promise deletion on demand.
- Invoices, line items and tax identification numbers — retained for as long as the applicable statutory retention period requires, and for as long as the customer instructs, whichever is longer.
- Submissions to tax authorities and their responses — retained alongside the documents they relate to, because they are the evidence that reporting happened.
- Audit-trail events — retained for the life of the document they describe. An audit trail that can be pruned is not an audit trail.
- Payment records — retained with the invoices they settle.
- Connection credentials and tokens — held only while a connection is active, and revoked when it is disconnected or the account is closed.
- Account and user records — retained while the account is open, then for the period needed to close out billing and meet our own record-keeping obligations.
- Enquiries sent through the contact form — retained for as long as needed to deal with the enquiry and any follow-up to it.
When a retention period ends, records are deleted or irreversibly anonymised. Where a customer asks us to delete data that is still under a statutory retention obligation, we will say so and explain what has to be kept rather than delete it and leave them unable to evidence a filing.
Your rights over your information
Depending on where you are and which law applies, you may have the right to ask for:
- Access — a copy of the information we hold about you, and an explanation of what we do with it.
- Rectification — correction of information that is inaccurate or incomplete.
- Erasure — deletion of information we no longer have a lawful reason to keep.
- Portability — information you provided, in a structured, machine-readable form, or sent on to another provider.
- Objection — that we stop processing carried out on the basis of legitimate interests.
- Restriction — that processing pauses while a dispute about accuracy or lawfulness is resolved.
Two things change how a request is handled.
- Who controls the record. If the information sits inside a customer’s account — an invoice issued to you by a business that uses the platform, for instance — that business is the controller. Send the request to them. If you send it to us, we will pass it on and help them answer it, but we will not alter or delete a customer’s records on our own initiative.
- Statutory retention can override erasure. Where the law requires a document to be kept, we will keep it and tell you why, rather than delete it.
We may need to verify who you are before we act, and we will keep verification proportionate rather than use it to stall. To make a request, use the contact form and say which right you are exercising and which records it concerns.
If you are not satisfied with how a request was handled, you can complain to the data-protection supervisory authority for your jurisdiction. Doing so does not affect any other remedy available to you.
How we protect information
The controls below are the ones the service relies on. This section describes controls; it is not a claim to hold any particular certification, and we do not make one here.
- Encryption in transit and at rest — data is encrypted while it moves between you, the platform, connected systems and tax authorities, and while it is stored.
- Role-based access — permissions are granted by role, so people reach the documents their role requires and not the rest. Customers configure their own roles and approval workflows.
- Audit trails — actions taken on a document are recorded, which makes access reviewable rather than assumed.
- Credential handling — integration credentials and tokens are stored so that they can be used by the service and revoked, and are revoked when a connection is removed or an account closes.
No system is completely secure, and any policy that implies otherwise is wrong. If we become aware of a breach affecting your information, we will act on it and notify the people and authorities we are required to notify, within the timescales that apply to us.
Some of it is yours to do: use strong, unique credentials, remove access for people who leave your organisation, and keep the permissions inside your account as narrow as the work allows.
Version, changes and review status
Last reviewed: not yet reviewed by legal counsel — see the notice at the top of this page.
This policy is versioned with the service rather than dated. The version you are reading is the current version; when the service changes in a way that affects it, the text on this page changes with it. There is no effective date printed here, and that is deliberate: a date on an unreviewed draft would imply an approval that has not happened.
When a final, counsel-reviewed version is published, material changes will be communicated through the service or to account contacts before they take effect, and the draft notice at the top of this page will be removed.
Contacting us about this policy
Questions about this policy, requests to exercise a right, and due-diligence requests such as the current sub-processor list all take the same route: the contact form.
We do not publish an inbox address on this page. Routing through the form means a request reaches the people who can act on it and is recorded, rather than resting in a mailbox nobody owns.
Read alongside our Terms of Service and Cookie Policy.
Related documents
These three documents are read together, and all three carry the same draft status described above.