Islandbridge Automation Limited
Product: Accruate

GDPR & Data Protection

Last updated: August 7, 2026

Islandbridge Automation Limited (registered in Ireland, company number 790984) is an Irish company, and we are committed to compliance with the General Data Protection Regulation (GDPR). We take an "EU-First" approach to data privacy: our database and file storage are in the EU, and we keep data in the EU wherever we can.

Role of Islandbridge Automation

  • Data Controller: For your account information (your name, email, billing details), Islandbridge Automation Limited acts as the Data Controller. How we handle that is set out in our Privacy Policy.
  • Data Processor: For the financial documents and data you upload to our platform (invoices, receipts), Islandbridge Automation Limited acts as the Data Processor on your behalf. You remain the Controller of this data. The terms on which we do that are set out in our Data Processing Agreement, which meets the requirements of Article 28 of the GDPR and forms part of our Terms and Conditions.

Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can correct inaccurate or incomplete data via your account settings, or ask us to.
  • Right to Erasure ("Right to be Forgotten"): You can request the deletion of your account and all associated data.
  • Right to Data Portability: You can export your data from our platform in a structured, machine-readable format.
  • Right to Restriction of Processing: You can ask us to pause processing while a question about the accuracy or lawfulness of that processing is resolved.
  • Right to Object: You can object at any time to processing we carry out on the basis of our legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your rights.
  • Right to Withdraw Consent: Where we rely on your consent, you can withdraw it at any time, without affecting anything we did before you withdrew it.

Automated decision-making: we do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. Every document is reviewed by a person before anything is posted to an accounting system.

Your Right to Complain

If you are unhappy with how we have handled your personal data, please tell us first. You also have the right to complain to the supervisory authority at any time:

Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie

If you are based in another EU or EEA country, you may complain to your local supervisory authority instead.

Subprocessors

To provide our services, we use the third-party subprocessors listed below. We have Data Processing Agreements in place with each of them. Where a provider processes data outside the European Economic Area, the safeguard we rely on is shown.

Subprocessor Purpose Location Transfer safeguard
Supabase Database, authentication & file storage EU (AWS Ireland/Germany) No transfer outside the EEA for stored data
Vercel Web hosting & serverless functions EU regions, global CDN Standard Contractual Clauses
Google (Gemini API) AI document data extraction & document-request email processing Google Cloud, global Standard Contractual Clauses (Google Cloud Data Processing Addendum)
Resend Transactional email & inbound email intake EU (AWS Ireland) Standard Contractual Clauses where applicable
Xero Accounting integration (optional, only if you connect it) Global Standard Contractual Clauses. New Zealand, where Xero is established, also benefits from a European Commission adequacy decision
Sentry Error monitoring and diagnostics EU (Germany) No transfer outside the EEA. We use Sentry's European region
Cal Demo call booking on our public website (only if you book a call) EU (European data-residency instance) No transfer outside the EEA

What we send to Sentry. Error diagnostics are configured to exclude request bodies, cookies, and any extracted document content. Sentry receives error messages, stack traces, the page address where the error happened, and your IP address. It does not receive your documents or the data extracted from them.

Changes to Our Subprocessors

We will give you at least 30 days' notice before we add or replace a subprocessor that handles data we process on your behalf, by email to the address on your account or by a notice in the Services. If you object on reasonable data protection grounds, tell us within that period and we will work with you to find a solution. If we cannot, you may terminate the affected part of the Services without penalty.

Personal Data Breaches

Where we act as your processor, we will notify you without undue delay after becoming aware of a personal data breach affecting data we process on your behalf, and we will give you the information you reasonably need in order to meet your own notification obligations under Articles 33 and 34 of the GDPR.

Where we are the controller, we will notify the Data Protection Commission within 72 hours where the breach is notifiable, and will tell affected individuals where the law requires it.

Data Deletion Requests

You can delete your account (and, if you are an organization owner, your entire practice and all its documents) directly from your account settings. To exercise your Right to Erasure or request the deletion of specific data, you can also contact us at:

Email: info@islandbridge.io
Subject: GDPR Data Deletion Request

We aim to process all valid requests within 30 days. Deletion from our live systems is not instantaneous in backups: our database backups are taken daily and retained for seven days, so residual copies may persist for up to a further seven days before backup rotation removes them.

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37. Data protection questions go to info@islandbridge.io.