New

QuickBooks Online + Xero publishing is here.

See how it works
taently

Zero-decision bookkeeping

From messy documents to clean books.

See the complete Tallently workflow from capture to export.

Product overview
Document captureUpload, paste and email-inAI extractionClassify, split and extractReviewOnly the exceptions need youSupplier automationRules that remove future workArchive & exportSearch, retain and share clean data
Connected booksPublish with the original attached.
qbQuickBooks OnlineFor US businessesxeroXeroFor UK businesses
View all integrations
PricingSecurityBlog
Log inStart free
Privacy at Tallently

Privacy Policy

A clear account of what we collect, why we use it, where it goes and the choices you have.

Effective July 19, 2026Version 1.1
PrivacyTermsCookiesDPASubprocessors

On this page

  1. 01Who we are
  2. 02Scope and data-protection roles
  3. 03Personal data we collect
  4. 04How and why we use personal data
  5. 05AI-assisted document processing
  6. 06How we share personal data
  7. 07International transfers
  8. 08How long we keep data
  9. 09Security
  10. 10Your privacy rights
  11. 11Children
  12. 12Changes and contact

Questions about this document?Contact our privacy team.

privacy@tallently.com
On this page 12 sections
  1. 01Who we are
  2. 02Scope and data-protection roles
  3. 03Personal data we collect
  4. 04How and why we use personal data
  5. 05AI-assisted document processing
  6. 06How we share personal data
  7. 07International transfers
  8. 08How long we keep data
  9. 09Security
  10. 10Your privacy rights
  11. 11Children
  12. 12Changes and contact
01

Who we are

Tallently is provided by HeavenlyTrade S.R.L.S., an Italian limited-liability company with VAT number IT04635090618 and registered office at Via Roma 114, 81100 Caserta (CE), Italy(referred to as “Tallently”, “we”, “us” or “our”).

For personal data connected with our website, customer relationship, accounts, billing and support, we act as the data controller. When a business uploads or forwards documents and other records to Tallently, that business normally determines why those records are processed and we act as its data processor. Our Data Processing Agreement governs that processing.

HeavenlyTrade S.R.L.S.Via Roma 114, 81100 Caserta (CE), ItalyVAT: IT04635090618privacy@tallently.com
02

Scope and data-protection roles

This policy covers the public website at tallently.com and the application at app.tallently.com.

  • Website visitors and prospects. We are controller for technical, enquiry and marketing-preference data.
  • Customer account users. We are controller for identity, account, security, subscription and support data needed to provide the service.
  • People named in customer content. The customer is normally controller and Tallently is processor for suppliers, employees, customers or other people whose details appear in uploaded records.

Customers are responsible for providing any notices, obtaining any permissions and establishing a lawful basis required for personal data they submit to the service.

03

Personal data we collect

Categories of personal data processed by Tallently
CategoryExamples
Website and device dataIP address, device and browser details, requested pages, timestamps, referral information and performance measurements.
Prospect and early-access dataName, work email, optional phone number, role, company profile, bookkeeping setup, stated challenges, referral and campaign information, and contact or marketing choices.
Account and security dataName, business email, authentication identifiers, team membership, role, invitations, sign-in events and multi-factor authentication status.
Business-profile dataCompany name, country, industry, base currency and business tax identifier such as a VAT number or EIN.
Customer contentReceipts, invoices, credit notes, statements, contracts, email bodies and attachments, supplier and customer details, transaction information and document metadata.
Generated and activity dataAI classifications, extracted fields, confidence scores, corrections, supplier rules, tags, exports and audit events.
Billing dataPlan, subscription status, usage, billing contact and Stripe customer, checkout and invoice identifiers. Full card details are handled by Stripe and are not stored by Tallently.
CommunicationsSupport requests, privacy enquiries, feedback and other messages sent to us.
04

How and why we use personal data

Purposes and lawful bases
PurposeTypical lawful basis
Provide accounts and the Tallently servicePerformance of our contract and steps taken at your request before entering into it.
Manage early-access, sign-in and account-recovery requestsSteps taken at your request before entering into a contract, our legitimate interest in launching and supporting the service, and consent where required.
Receive, store, classify and extract customer documentsCustomer instructions under the DPA; the customer determines its own lawful basis.
Manage subscriptions, invoices and paymentsPerformance of contract and compliance with tax, accounting and fraud-prevention obligations.
Secure, troubleshoot and improve the serviceOur legitimate interests in operating a reliable and secure business, balanced against individual rights.
Respond to support and privacy enquiriesPerformance of contract, legal obligations and legitimate interests in customer support.
Send service notices and material policy updatesPerformance of contract and legal obligations.
Optional marketingConsent where required, or legitimate interests where law permits. You can opt out at any time.
05

AI-assisted document processing

Tallently sends uploaded documents and limited business-profile context to Anthropic’s commercial API so that the service can classify records and extract structured fields. Results may include document type, supplier, dates, totals, taxes, currency and a confidence score.

Customer documents are not used to train Anthropic models

Anthropic’s commercial terms state that it may not train models on customer content submitted through its commercial services. Tallently does not permit customer content to be used for advertising or general-purpose model training.

Automated results support bookkeeping workflows but do not make legal decisions about people and do not produce decisions with similarly significant effects. Users can review and correct extracted fields before relying on them.

06

How we share personal data

We disclose personal data only where needed for the service or where law requires it:

  • Subprocessors that host, secure, process, email or bill for the service, listed on our Subprocessors page.
  • Customer-authorised services when a customer elects to connect or export to a third-party accounting platform.
  • Professional advisers and authorities where reasonably necessary for legal, tax, audit, insurance or regulatory matters.
  • Corporate transactions in connection with a financing, reorganisation, acquisition or sale, subject to appropriate confidentiality safeguards.

We do not sell personal data or share it for cross-context behavioural advertising.

07

International transfers

Tallently primarily hosts application compute and customer storage in London. Some providers process data from the United States or through global infrastructure. When personal data is transferred outside the EEA or United Kingdom, we use an applicable adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, an approved Data Privacy Framework certification, or another lawful transfer mechanism.

Contact us for information about the safeguards relevant to a particular transfer.

08

How long we keep data

Tallently retention periods
DataRetention approach
Customer documents and extracted recordsFor the active service term, including the advertised long-term archive. After termination, content remains available for export for 90 days and is then deleted unless law requires otherwise or the customer instructs earlier deletion.
Prospect and early-access dataFor up to 24 months after the last relevant interaction, unless you withdraw consent, object or request deletion earlier, or a longer period is needed to document compliance.
Account and business-profile dataFor the account term and the 90-day post-termination period, then deleted or anonymised unless needed for a legal claim.
Billing and tax recordsFor the period required by applicable accounting and tax law, commonly up to 10 years.
Security and operational logsFor the shortest period reasonably needed for security, diagnostics and fraud prevention, subject to provider retention settings.
Support and privacy correspondenceFor as long as necessary to resolve the request and document our response, then deleted or archived where legally required.
09

Security

We use technical and organisational measures designed to protect personal data, including encryption in transit and at rest, private object storage, tenant-level row security, role-based access, time-based one-time-password multi-factor authentication, restricted privileged access, signed file links, audit history, backups and monitoring.

No service can guarantee absolute security. Customers must protect account credentials, use multi-factor authentication where available and notify us promptly of suspected unauthorised access.

10

Your privacy rights

Depending on your location and applicable law, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy of data, withdraw consent and complain to a supervisory authority. Residents of US states with applicable privacy laws may also request confirmation, access, correction or deletion and may appeal a refusal where the law provides that right.

Send requests to privacy@tallently.com. We may verify your identity and authority before acting. If your request concerns data controlled by a Tallently customer, contact that customer first; we will assist it as required by our DPA.

EEA residents may complain to the Garante per la protezione dei dati personali or their local authority. UK residents may complain to the Information Commissioner’s Office.

11

Children

Tallently is a business service and is not directed to anyone under 18. Customers must not intentionally use the service to collect children’s data or special-category data unless they have a valid legal basis and the processing is permitted by our agreement.

12

Changes and contact

We may update this policy to reflect service, legal or regulatory changes. We will update the date shown above and give account owners reasonable notice of material changes by email or in-product notice.

Privacy questions and requests: privacy@tallently.com.
General support: support@tallently.com.

Tallently legal

Related documents

Terms of ServiceCookie PolicyData Processing AgreementSubprocessors
Current document: Privacy Policy
taently

AI-powered bookkeeping and expense automation for small businesses.

Product

OverviewDocument captureAI extractionReviewSupplier automationArchive & export

Integrations

OverviewQuickBooks OnlineXero

Company

AboutBlogContact

Legal

Privacy PolicyTerms of ServiceCookie PolicyData Processing AgreementSubprocessors
© 2026 Tallently by HeavenlyTrade S.R.L.S. · P. IVA IT04635090618. Built for small businesses in the US and UK.Home