Legal

Privacy Policy

How Paythos collects, uses, shares, and protects personal data.
Last updated 26 July 2026

This policy explains how Paythos handles personal data under the UK General Data Protection Regulation and the Data Protection Act 2018. It is written for website visitors, prospective customers, workspace users, supplier contacts, and other people whose information may be processed through Paythos.

1. Who we are and when this policy applies

Paythos provides a multi-tenant accounts-payable automation platform for invoice capture, data extraction, supplier management, purchase orders, approvals, risk analysis, payment routing, reporting, and related integrations.

For account administration, billing, support, sales, marketing, and use of our public website, Paythos acts as a data controller. When a customer submits invoices, supplier records, employee details, approval data, or other business content to the platform, the customer normally acts as controller and Paythos acts as its processor. Our Data Processing Agreement governs that processing.

2. Personal data we collect

  • Account and organisation data: name, business email address, company name, job role, workspace, permissions, invitation status, and authentication identifiers.
  • Billing and subscription data: plan, subscription status, billing address, Stripe customer and subscription references, and transaction status. Card details are collected by Stripe and are not stored by Paythos.
  • Accounts-payable data: invoices and attachments; supplier names, contacts, postal addresses, VAT numbers, bank and remittance details; customer VAT numbers; invoice dates, references, purchase-order references, line items, tax amounts and rates, totals, currencies, parser warnings, GL codes, coding suggestions, proposed accounts, and reviewed coding decisions.
  • Workflow and payment data: purchase orders, approval decisions, comments, routing rules and decisions, payment-provider references, settlement status, and audit records.
  • Integration data: the accounting or payment service connected, tenant or account identifiers, synchronisation state, and encrypted OAuth credentials or API connection data.
  • Communications and sales data: contact and demo enquiries, public live-chat messages and timestamps, support messages, CRM contact details, notes, company information, and follow-up history.
  • Technical and usage data: IP address where recorded, browser and device information, user agent, timestamps, page paths, diagnostic events, and security or operational logs.
  • Cookie choices and analytics data: an anonymous consent identifier, consent decision, policy version, optional cookie categories, detected cookie names, and Google Analytics data where analytics consent has been granted.

Please do not upload special-category personal data or criminal-offence data unless it is necessary, lawful, and permitted by your agreement with Paythos.

3. How we collect data

We collect data directly from you and your organisation, automatically when you use our website or platform, from invoices and files you upload, and from services you choose to connect, including accounting and payment providers. We may also receive information from Stripe about subscription payments and from prospective customers who contact us or use the public website live chat. Live-chat records can include the messages you send, the page you were viewing, referral information, optional contact details, and conversation timestamps.

4. How and why we use personal data

  • Provide, secure, administer, and support the platform and your workspace: performance of a contract and our legitimate interests in operating the service.
  • Extract and classify invoice data, suggest or propose GL coding for customer review, identify anomalies, calculate risk indicators, route approvals, and support payment workflows: performance of our contract with the customer and the customer’s documented instructions.
  • Manage subscriptions and payments: performance of a contract and compliance with financial and tax obligations.
  • Send invitations, password-recovery messages, service notices, and support responses: performance of a contract and legitimate interests.
  • Monitor reliability, investigate errors, prevent abuse, and maintain security: legitimate interests and, where applicable, legal obligations.
  • Measure use of public pages and assess campaigns: consent, where required. Optional analytics and marketing storage remain denied until the relevant consent is given.
  • Respond to enquiries and manage prospective customer relationships: legitimate interests; marketing communications are sent on the basis of consent or another lawful basis permitted by law.
  • Operate the public website live chat, notify available team members, prevent chat abuse, and retain a support transcript: legitimate interests in responding to prospective customers and securing the service.
  • Establish, exercise, or defend legal claims and comply with lawful requests: legal obligation or legitimate interests.

5. AI and automated processing

Paythos uses automated systems to extract structured fields from invoices, suggest an existing GL code, propose a new code where no suitable account is found, recommend a spend-request approver from successful organisation approval history, flag possible duplicates or unusual patterns, estimate risk, and explain recommendations. Invoice text, extracted details, line items, vendor context, and the organisation's relevant GL code list may be sent to OpenAI for these AI-assisted functions. The platform also uses a separately hosted machine-learning service to process structured risk and spend-request approval feature data for eligible plans.

GL proposals are checked against active and inactive organisation codes and are not added to the chart until a Super Admin or Admin accepts them. Automated outputs can be incomplete or incorrect and should not be treated as the sole basis for a payment or other decision with legal or similarly significant effects. Customers remain responsible for reviewing invoices, proposed coding, supplier details, tax data, risk indicators, approval configuration, and payment instructions.

6. Who we share data with

We do not sell personal data. Depending on the features used, data may be shared with service providers acting for us or with services selected by the customer:

  • Supabase for managed authentication, PostgreSQL database services, and private file storage.
  • Vercel for application hosting and delivery.
  • Stripe for Paythos subscription checkout, billing, and payment status.
  • Resend for transactional, action-required, invitation, recovery, contact, demo, and live-chat notification emails.
  • OpenAI for invoice extraction and other AI-assisted features initiated through the platform.
  • Northflank for hosting the Paythos machine-learning service.
  • Sentry for application error and performance monitoring when configured.
  • Google Analytics for public-site measurement after analytics consent.
  • Accounting services selected by the customer, including Xero, QuickBooks, Sage, and FreshBooks.
  • Payment services selected and configured by the customer, which may include Wise, Stripe, or Adyen.
  • Professional advisers, regulators, courts, law-enforcement bodies, or a buyer of our business where disclosure is lawful and necessary.

Our current processor commitments are described further in the DPA. A customer-controlled integration is also subject to that provider’s own terms and privacy notice.

7. International transfers

Some providers may process data outside the United Kingdom. Where UK personal data is transferred to a country without an adequacy regulation, we use an appropriate transfer mechanism where required, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard. Customers should assess transfers created by integrations they choose to enable.

8. Retention and deletion

We retain account and platform data while the relevant customer account is active and for a limited period afterwards where needed to provide exports, resolve disputes, meet legal obligations, prevent fraud, and enforce agreements. Retention varies by record type and customer instructions. We delete or anonymise personal data when it is no longer required, subject to backups, technical limitations, and lawful retention obligations.

Customer Data processed on behalf of an organisation is returned or deleted in accordance with the customer agreement and DPA. Closed public live-chat conversations are retained for up to 90 days, unless a shorter period is required or a longer period is necessary to handle abuse, a dispute, or a legal obligation. Cookie-consent records and audit data may be retained to demonstrate choices, accountability, and platform activity. We do not claim a single seven-year period applies to every payment or audit record.

9. Security

We use technical and organisational safeguards appropriate to the platform, including encrypted transport, managed authentication, tenant checks, database row-level security, private invoice storage, role-based permissions, encrypted integration tokens, signed webhook validation, audit records, and operational monitoring. No online service is completely secure. See our Security page for an accurate description of current controls.

10. Cookies and similar technologies

Necessary storage supports authentication, session integrity, security, consent memory, reliable delivery, checkout state, and user-requested settings. Analytics and marketing categories are optional. Our banner provides Accept all, Necessary only, and custom choices and updates Google Consent Mode v2. You can reopen the controls through Cookie settings.

11. Your data protection rights

Subject to applicable law, you may have rights to access, correct, erase, restrict, or port personal data; object to processing based on legitimate interests; withdraw consent; and complain to a supervisory authority. Where Paythos processes Customer Data for your employer or another customer, contact that organisation first. We will assist the customer with a valid request.

To exercise a right relating to data Paythos controls, email hello@paythos.tech. We may verify your identity and will normally respond within one month. You may complain to the UK Information Commissioner’s Office at ico.org.uk.

12. Children

Paythos is a business service and is not directed to children. We do not knowingly collect personal data from children through the platform.

13. Changes and contact

We may update this policy as our services or legal obligations change. We will update the date above and provide additional notice where a change is material. Questions about privacy or this policy can be sent to hello@paythos.tech.