On this page 12 sections
Who we are
Tallently is provided by HeavenlyTrade S.R.L.S., an Italian limited-liability company with VAT number IT04635090618 and registered office at Via Roma 114, 81100 Caserta (CE), Italy(referred to as “Tallently”, “we”, “us” or “our”).
For personal data connected with our website, customer relationship, accounts, billing and support, we act as the data controller. When a business uploads or forwards documents and other records to Tallently, that business normally determines why those records are processed and we act as its data processor. Our Data Processing Agreement governs that processing.
HeavenlyTrade S.R.L.S.Via Roma 114, 81100 Caserta (CE), ItalyVAT: IT04635090618privacy@tallently.comScope and data-protection roles
This policy covers the public website at tallently.com and the application at app.tallently.com.
- Website visitors and prospects. We are controller for technical, enquiry and marketing-preference data.
- Customer account users. We are controller for identity, account, security, subscription and support data needed to provide the service.
- People named in customer content. The customer is normally controller and Tallently is processor for suppliers, employees, customers or other people whose details appear in uploaded records.
Customers are responsible for providing any notices, obtaining any permissions and establishing a lawful basis required for personal data they submit to the service.
Personal data we collect
| Category | Examples |
|---|---|
| Website and device data | IP address, device and browser details, requested pages, timestamps, referral information and performance measurements. |
| Prospect and early-access data | Name, work email, optional phone number, role, company profile, bookkeeping setup, stated challenges, referral and campaign information, and contact or marketing choices. |
| Account and security data | Name, business email, authentication identifiers, team membership, role, invitations, sign-in events and multi-factor authentication status. |
| Business-profile data | Company name, country, industry, base currency and business tax identifier such as a VAT number or EIN. |
| Customer content | Receipts, invoices, credit notes, statements, contracts, email bodies and attachments, supplier and customer details, transaction information and document metadata. |
| Generated and activity data | AI classifications, extracted fields, confidence scores, corrections, supplier rules, tags, exports and audit events. |
| Billing data | Plan, subscription status, usage, billing contact and Stripe customer, checkout and invoice identifiers. Full card details are handled by Stripe and are not stored by Tallently. |
| Communications | Support requests, privacy enquiries, feedback and other messages sent to us. |
How and why we use personal data
| Purpose | Typical lawful basis |
|---|---|
| Provide accounts and the Tallently service | Performance of our contract and steps taken at your request before entering into it. |
| Manage early-access, sign-in and account-recovery requests | Steps taken at your request before entering into a contract, our legitimate interest in launching and supporting the service, and consent where required. |
| Receive, store, classify and extract customer documents | Customer instructions under the DPA; the customer determines its own lawful basis. |
| Manage subscriptions, invoices and payments | Performance of contract and compliance with tax, accounting and fraud-prevention obligations. |
| Secure, troubleshoot and improve the service | Our legitimate interests in operating a reliable and secure business, balanced against individual rights. |
| Respond to support and privacy enquiries | Performance of contract, legal obligations and legitimate interests in customer support. |
| Send service notices and material policy updates | Performance of contract and legal obligations. |
| Optional marketing | Consent where required, or legitimate interests where law permits. You can opt out at any time. |
AI-assisted document processing
Tallently sends uploaded documents and limited business-profile context to Anthropic’s commercial API so that the service can classify records and extract structured fields. Results may include document type, supplier, dates, totals, taxes, currency and a confidence score.
Automated results support bookkeeping workflows but do not make legal decisions about people and do not produce decisions with similarly significant effects. Users can review and correct extracted fields before relying on them.
How we share personal data
We disclose personal data only where needed for the service or where law requires it:
- Subprocessors that host, secure, process, email or bill for the service, listed on our Subprocessors page.
- Customer-authorised services when a customer elects to connect or export to a third-party accounting platform.
- Professional advisers and authorities where reasonably necessary for legal, tax, audit, insurance or regulatory matters.
- Corporate transactions in connection with a financing, reorganisation, acquisition or sale, subject to appropriate confidentiality safeguards.
We do not sell personal data or share it for cross-context behavioural advertising.
International transfers
Tallently primarily hosts application compute and customer storage in London. Some providers process data from the United States or through global infrastructure. When personal data is transferred outside the EEA or United Kingdom, we use an applicable adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, an approved Data Privacy Framework certification, or another lawful transfer mechanism.
Contact us for information about the safeguards relevant to a particular transfer.
How long we keep data
| Data | Retention approach |
|---|---|
| Customer documents and extracted records | For the active service term, including the advertised long-term archive. After termination, content remains available for export for 90 days and is then deleted unless law requires otherwise or the customer instructs earlier deletion. |
| Prospect and early-access data | For up to 24 months after the last relevant interaction, unless you withdraw consent, object or request deletion earlier, or a longer period is needed to document compliance. |
| Account and business-profile data | For the account term and the 90-day post-termination period, then deleted or anonymised unless needed for a legal claim. |
| Billing and tax records | For the period required by applicable accounting and tax law, commonly up to 10 years. |
| Security and operational logs | For the shortest period reasonably needed for security, diagnostics and fraud prevention, subject to provider retention settings. |
| Support and privacy correspondence | For as long as necessary to resolve the request and document our response, then deleted or archived where legally required. |
Security
We use technical and organisational measures designed to protect personal data, including encryption in transit and at rest, private object storage, tenant-level row security, role-based access, time-based one-time-password multi-factor authentication, restricted privileged access, signed file links, audit history, backups and monitoring.
No service can guarantee absolute security. Customers must protect account credentials, use multi-factor authentication where available and notify us promptly of suspected unauthorised access.
Your privacy rights
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy of data, withdraw consent and complain to a supervisory authority. Residents of US states with applicable privacy laws may also request confirmation, access, correction or deletion and may appeal a refusal where the law provides that right.
Send requests to privacy@tallently.com. We may verify your identity and authority before acting. If your request concerns data controlled by a Tallently customer, contact that customer first; we will assist it as required by our DPA.
EEA residents may complain to the Garante per la protezione dei dati personali or their local authority. UK residents may complain to the Information Commissioner’s Office.
Children
Tallently is a business service and is not directed to anyone under 18. Customers must not intentionally use the service to collect children’s data or special-category data unless they have a valid legal basis and the processing is permitted by our agreement.
Changes and contact
We may update this policy to reflect service, legal or regulatory changes. We will update the date shown above and give account owners reasonable notice of material changes by email or in-product notice.
Privacy questions and requests: privacy@tallently.com.
General support: support@tallently.com.