Last updated: 18 June 2026 (rev 4)
Ceendesis Ltd(“Ceendesis”, “we”, “us”) is the data controller for the Ceendesis Accounting service available at accounting.ceendesis.com. You can contact us at privacy@ceendesis.com.
We use your data only to:
We do not sell your data, use it for advertising, or share it with third parties except as described in section 5.
maskAllText and maskAllInputs), with URL query strings stripped before send — so no amounts, account names, tokens, or form values are captured. You can opt out at any time by contacting privacy@ceendesis.com.beforeSend scrubber automatically strips all tokens, OAuth credentials, and personal identifiers (email addresses, names) so that no financial line-item data or personal data is included in reports sent to Sentry.All sub-processors are contractually bound via Data Processing Agreements (DPAs) to process data only on our instructions and to maintain appropriate security measures.
We retain your data for as long as your account is active, plus 7 years after account closure to satisfy financial record-keeping obligations under UK law. Settlement line items and posted invoice records are kept for this full period. OAuth credentials are deleted immediately upon connection removal or account closure.
Under UK GDPR you have the right to:
To exercise any of these rights, email privacy@ceendesis.com. We will respond within 30 days.
All data in transit is encrypted with TLS 1.2+. Data at rest is encrypted using AES-256. OAuth credentials are encrypted at the application layer before being stored. We apply the principle of least privilege to all internal systems.
We will notify you by email at least 14 days before any material change to this policy. Continued use of the service after that date constitutes acceptance of the updated policy.