1. Overview
NOSCERA is a financial intelligence platform. We build tools that help businesses understand their finances, detect risks, predict outcomes, and act with confidence. To do that, we process certain personal and financial data. This Privacy Policy explains what we collect, why, and the choices you have.
This page is maintained by NOSCERA to explain how we handle data. It applies to all users of the Service, including members of Organisations and their invited colleagues.
NOSCERA is the data controller for the personal data you provide when you create and use your account. For financial data imported from connected sources, we act as a processor on behalf of the Organisation that connected those sources.
2. Data We Collect
Account & profile data
When you register, we collect your name, email address, and authentication credentials. Passwords are stored only as cryptographic hashes by our authentication provider — we never see or store them in plain text. If you sign in with Google, we receive your name and email from Google.
Organisation data
We store the name, plan, and settings of each Organisation you create or join, and the roles and permissions assigned to its members.
Financial data
When you connect an accounting or payment source (such as Xero, QuickBooks, Sage, FreeAgent, or Stripe) or upload a CSV file, we import and store the transactions, account balances, contacts, invoices, and related records that those sources provide. This data is scoped to the Organisation and used to power the Engines.
Uploaded documents
You may upload documents such as invoices, receipts, or statements. We process these to extract structured data and to answer your questions about them.
Usage & interaction data
We record how you interact with the Service — for example, questions asked to the Intelligence Assistant, alerts acknowledged, feedback provided, and features used. This helps us improve the Service and personalise outputs for your Organisation.
Billing data
Payment processing is handled by Stripe. We do not store your full card number or banking details. We retain a minimal record of transactions (amount, date, invoice reference) for accounting and reconciliation purposes.
Technical & device data
We collect standard technical information such as browser type, device identifiers, and IP address for security, abuse prevention, and service operation. Our analytics provider is privacy-friendly and cookieless (see section 11).
3. How We Use Your Data
We use your data to:
- Provide the Service — run the Engines, generate insights, forecasts, briefs, and responses to your questions;
- Operate your Organisation — manage members, roles, billing, and settings;
- Improve the Service — learn from aggregated and anonymised feedback to make insights more relevant and accurate over time;
- Secure the platform — detect fraud, abuse, and unauthorised access;
- Communicate with you — send service notifications, security alerts, and account-related messages;
- Meet legal obligations — comply with applicable law and respond to lawful requests.
We do not sell your personal or financial data to third parties, and we do not use it to train general-purpose AI models. Learning from your feedback is used only to improve insights for your Organisation.
4. Legal Basis for Processing
Where you are in a jurisdiction with data protection laws (such as the UK GDPR or EU GDPR), we rely on the following lawful bases:
- Contract — processing necessary to provide the Service you requested, including running the Engines and storing your imported data.
- Legitimate interests — for security, fraud prevention, service improvement, and analytics, balanced against your rights and expectations.
- Legal obligation — where we are required to retain or disclose data by law (for example, tax records or lawful government requests).
- Consent — for optional activities such as marketing communications, where applicable. You can withdraw consent at any time.
5. Financial Data & Connectors
When you connect a third-party source, you authorise that source to share your data with NOSCERA through its OAuth flow. We import only the data your authorisation permits, and we use it to provide the Service to your Organisation.
Each third-party provider is an independent data controller for the data it holds. We are not responsible for how those providers collect, store, or share your data — their own terms and privacy policies govern that. We encourage you to review them.
You can disconnect a source at any time from your settings. This stops further synchronisation. Data already imported remains until you delete it or your Organisation.
6. AI & Intelligence Processing
How the Assistant works
The Intelligence Assistant interprets your question, classifies it, and routes it to the relevant Engine. The Engine reads from your imported financial data to produce an evidence-backed response. Where a question does not relate to your data, the Assistant may answer from general financial knowledge — but it will not invent specific figures about your business.
Model providers
To generate natural-language responses, the Service sends your question and relevant context to AI model providers through our AI gateway. The context sent may include summarised or derived data from your Organisation — for example, a question about your cash position may include the relevant figures. We do not send raw financial records to general-knowledge model calls.
Self-learning and feedback
When you provide feedback (such as marking an alert as not useful or confirming a prediction was accurate), we store that feedback and use it to adjust how insights are prioritised and surfaced for your Organisation. This feedback is organisation-scoped — it does not modify figures and is not shared across Organisations.
No training on your data for general models
We do not use your personal or financial data to train general-purpose, externally available AI models. Learning is human-in-the-loop, bounded, and used only to improve the relevance of outputs for your Organisation.
8. Data Retention
We keep your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data — retained while your account is active. Deleted when you delete your account or request deletion.
- Financial data — retained while your Organisation is active. Deleted when the Organisation is deleted or the relevant data is removed by an authorised member.
- Usage & feedback data — retained for as long as needed to provide the Service, then aggregated and anonymised or deleted.
- Billing records — retained for the period required by applicable tax and accounting law (typically up to 6 years in the UK).
- After cancellation — we retain data for a limited grace period to allow export, then delete it unless retention is required by law.
You can request deletion of your data at any time. Account and Organisation deletion is irreversible and removes associated data as described in these Terms.
9. Security
We take security seriously. We use industry-standard measures to protect your data, including encryption in transit (TLS), encryption at rest, role-based access controls, and row-level security at the database layer. Access to production data is restricted to authorised personnel on a least-privilege basis.
However, no system is perfectly secure. We cannot guarantee that unauthorised access, loss, or alteration of data will never occur. You play a role too — keep your credentials safe, use strong authentication, and limit membership to those who need it.
If you believe a security issue has occurred, please report it to info@noscera.online. We will investigate and notify affected users where required by law.
10. International Data Transfers
NOSCERA and its subprocessors may process and store data in locations outside your country of residence. Where we transfer personal data from the UK or EEA to a country without an adequacy decision, we rely on appropriate safeguards such as standard contractual clauses or other lawful transfer mechanisms, and we take steps to ensure your data receives comparable protection.
12. Your Rights
If you are in the UK, EEA, or another jurisdiction with data protection laws, you have rights over your personal data, including:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your personal data (also known as the "right to be forgotten"), subject to legal retention requirements.
- Restriction & objection — ask us to limit or stop processing in certain circumstances.
- Data portability — receive certain data in a structured, machine-readable format, and transmit it to another provider.
- Withdrawal of consent — withdraw consent for processing that relies on it, at any time.
You can exercise many of these rights directly within the Service (for example, exporting your data or deleting your account). For other requests, contact our support team at adebukola@noscera.store. We will respond within the timeframes required by applicable law (typically one month).
You also have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data appropriately. We would welcome the chance to address your concern first.
13. Children's Privacy
NOSCERA is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a minor has provided us with personal data, please contact us and we will take steps to delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect, except for urgent legal or security changes, which may take effect immediately. The "last updated" date above reflects when this policy was last revised.
15. Contact
If you have any questions about this Privacy Policy or how we handle your data, contact our data protection lead at:
- Privacy & data enquiries: adebukola@noscera.store
- Security reports: info@noscera.online
- General & sales: team@noscera.org
This page is maintained by NOSCERA to explain our privacy practices. It is not a certification or legal opinion.
