Islandbridge Automation Limited
Product: Accruate

Privacy Policy

Last updated: August 7, 2026

This Privacy Notice for Islandbridge Automation Limited ("we," "us," or "our"), a company registered in Ireland under company number 790984, describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you visit our website at https://www.accruate.com or use our application (Accruate).

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at info@islandbridge.io.

Two roles, and which one applies. For your own account information we are the data controller, meaning we decide why and how it is processed, and this notice explains that. For the financial documents and data you upload about your own clients, we are your data processor, meaning we act on your instructions and you remain the controller. Those arrangements are governed by our Data Processing Agreement rather than by this notice.

Summary of Key Points

  • What personal information do we process? We collect information necessary to run your account and to process invoices and accounting data, such as names, addresses, and financial details found on documents you supply.
  • Do we process special category data? No. We process confidential financial information, which we treat as commercially sensitive, but it is not "special category" data as defined in Article 9 of the GDPR (data about health, race, religion, politics, trade union membership, genetics, biometrics, or sex life).
  • Do we collect information from third parties? Yes. We receive data from accounting systems you connect, such as Xero, and from people who email documents to your Accruate intake address. Section 2 explains this.
  • How do we process your information? To run your account, extract data from documents, provide accounting automation, secure the Services, and communicate with you. Section 4 gives the legal basis for each.
  • Do we sell your information? No, and we never will.
  • How do we keep your information safe? Encryption at rest and in transit, EU-hosted infrastructure, and the measures set out in our Security Statement.
  • What are your rights? Access, rectification, erasure, portability, restriction, objection, and the right to complain to the Data Protection Commission. Section 9 explains how to exercise them.

1. What Information Do We Collect From You?

Personal information you provide to us

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us. This may include:

  • Names
  • Email addresses
  • Business name, role, and contact details
  • Billing addresses, if and when we introduce paid plans
  • Contact preferences
  • The content of support messages and feedback you send us

We do not store your password. Authentication is handled by our infrastructure provider, Supabase, which stores passwords in hashed form. We never see or hold your password in a readable form. Where you sign in with Google, we receive only your name, email address, and profile identifier from Google, and no password at all.

We also record when you accepted our Terms and Conditions and which version you accepted, and, if you enable multi-factor authentication, the fact that a factor is enrolled and whether you have chosen to trust a particular device.

Financial and document information

To provide the Services we process the contents of the financial documents supplied to us, including supplier names and addresses, VAT registration numbers, bank details printed on invoices, line item descriptions, amounts, dates, and payment terms. Much of this relates to businesses rather than individuals, but some of it will be personal data, particularly where a supplier is a sole trader.

This information is confidential and commercially sensitive. It is not "special category" data under Article 9 of the GDPR, and we treat it with care regardless.

2. Information We Receive From Other Sources

Not all information reaches us directly from the person it relates to. We also receive:

  • From accounting systems you connect. When you connect Xero, we read your contacts and supplier records, chart of accounts, tax rates, historical transaction coding, and bank transaction lines. We use these to suggest account codes and tax treatment, to detect duplicates, and to identify purchases that appear to be missing paperwork.
  • From people who email your intake address. Each workspace has a dedicated Accruate email address. Anyone you give it to, including your clients and their suppliers, can send documents to it. We process those messages, their attachments, and the sender's email address in order to route the documents into your workspace and to match replies to outstanding requests.

Where we hold personal data about someone who is not our customer, for example a supplier named on an invoice or a person who replies to a document request, we are almost always processing it on behalf of the customer who asked us to. That customer is the controller and is responsible for the notices given to those individuals. If you believe we hold information about you and you are not an Accruate customer, contact us at info@islandbridge.io and we will put you in touch with the relevant controller or deal with the request ourselves where it is ours to deal with.

3. Communications We Send On Your Behalf

The Services can send email to your own clients and their suppliers at your direction, asking for missing documents and following up on requests. These messages are sent from an Accruate address and identify both your firm and Accruate, and replies go to you. We process the recipients' email addresses and the content of their replies for this purpose, on your instructions and as your processor. You decide who is contacted.

4. How Do We Process Your Information, and On What Legal Basis?

Data protection law requires us to have a lawful basis for each purpose we process personal data for. Ours are set out below.

What we do Why Legal basis (GDPR Article 6)
Create and manage your account, authenticate you, and operate multi-factor authentication To give you access to the Services you signed up for Contract (Art 6(1)(b))
Extract, validate, and code data from the documents supplied to us, and post approved records to your accounting system To deliver the core Service Contract (Art 6(1)(b)). Where the data relates to your clients, we act as your processor on your instructions
Send document requests and reminders to your clients and their suppliers at your direction Because you asked us to Contract with you (Art 6(1)(b)); as processor for the recipients' data
Respond to support requests and send administrative or service messages To support you and tell you about changes that affect you Contract (Art 6(1)(b)) and legitimate interests (Art 6(1)(f))
Monitor for errors, abuse, and security incidents, and keep audit and access records To keep the Services and your data secure Legitimate interests (Art 6(1)(f)): running a secure service
Understand how the Services are used so we can improve them To make the product better Consent (Art 6(1)(a)) where this involves analytics stored on your device. See section 7
Comply with legal, accounting, and regulatory obligations Because the law requires it Legal obligation (Art 6(1)(c))

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights and concluded it is not. You can object to that processing at any time. See section 11.

5. Use of Artificial Intelligence (Google Gemini)

Accruate uses AI models provided by Google (the Google Gemini API) to extract data from the documents you upload, and to help manage document requests sent by email. For example, reading a reply sent to your workspace's dedicated Accruate email address so the Services can match attached documents to outstanding requests, note a promised send date, or suggest follow-up messages for your review. We use Google's paid API services which, under Google's terms, are not used to train Google's publicly available AI models. Extracted data and message content are used strictly to provide the Services to you.

We do not use your documents or the data extracted from them to train our own models.

6. Automated Decision-Making

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. The Services suggest account codes, tax treatment, and validation outcomes, but every document is presented to a person for review, and nothing is posted to your accounting system without a human approving it. The final decision is always yours.

7. When and With Whom Do We Share Your Personal Information?

We share data with third-party vendors, service providers, and contractors who perform services for us or on our behalf and who need access to do that work. The specific subprocessors we use, what each is for, and where each is located are listed in our GDPR and Data Protection statement.

We may also disclose information where we are required to by law, by a court, or by a regulator, and to our professional advisers where necessary. If our business is sold or merged, information may transfer to the acquirer, and we will tell you before that happens.

We have never sold or shared personal information for a business or commercial purpose, and we will not do so. We are a paid software business, not an advertising business.

Analytics. At the date of this notice we run no analytics, advertising, or tracking tools of any kind, and we set no cookies that require your consent. If that changes, we will ask for your consent before any analytics or session recording tool is loaded, we will update our Cookie Policy and the subprocessor list first, and you will be able to withdraw consent at any time.

8. Do We Transfer Your Information Outside the EEA?

We host and store your data in the European Economic Area wherever we can, and our database and file storage are located in the EU. Some of our subprocessors nevertheless process data outside the EEA.

Where personal data leaves the EEA, we rely on one of the following safeguards:

  • An adequacy decision by the European Commission, where the receiving country has been recognised as providing an equivalent level of protection.
  • Standard Contractual Clauses approved by the European Commission, incorporated into our agreement with that provider, together with any supplementary technical measures needed.

The transfer position for each subprocessor is set out in the table in our GDPR and Data Protection statement. You can ask us for a copy of the relevant safeguards by emailing info@islandbridge.io.

9. How Long Do We Keep Your Information?

We keep information only as long as we need it for the purposes in this notice, or longer where the law requires.

  • Account information: for as long as you have an account, and for 30 days after you close it.
  • Documents and extracted data: for as long as your workspace exists. After termination you have 30 days to export your data, after which we delete it.
  • Backups: our database backups are taken daily and retained for seven days. Deleted data therefore persists in encrypted backups for up to seven days after deletion from our live systems, after which backup rotation removes it.
  • Support and email correspondence: up to two years after the matter is closed.
  • Records we must keep by law, such as accounting records: for the period the relevant law requires.

Please note that Accruate is not a backup or archival service. You are responsible for retaining original copies of your invoices, receipts, and financial records for as long as your own tax authority requires.

10. How Do We Keep Your Information Safe?

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process, including encryption at rest and in transit, tenant isolation enforced at the database level, multi-factor authentication, and restricted internal access. These are described in our Security Statement.

However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.

11. Your Rights

Under the GDPR you have the following rights in relation to personal data we hold about you as controller:

  • Access: to be told whether we process your data and to receive a copy of it.
  • Rectification: to have inaccurate or incomplete data corrected.
  • Erasure: to have your data deleted where there is no continuing reason for us to hold it.
  • Restriction: to have us pause processing while a dispute about accuracy or lawfulness is resolved.
  • Portability: to receive data you gave us in a structured, commonly used, machine-readable format.
  • Objection: to object at any time to processing based on our legitimate interests. We will stop unless we can show compelling legitimate grounds that override your rights.
  • Withdrawal of consent: where we rely on your consent, to withdraw it at any time. This does not affect processing carried out before you withdrew it.

To exercise any of these, email info@islandbridge.io. We respond to valid requests within one month. Exercising your rights is free, and we will not treat you differently for doing so.

You can also delete your account, and if you own the organisation its entire contents, directly from your account settings.

12. Your Right to Complain

If you are unhappy with how we have handled your personal data, please tell us first and we will try to put it right. You also have the right to lodge a complaint with the supervisory authority at any time. In Ireland that is:

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
www.dataprotection.ie

If you live or work in another EU or EEA country, you may complain to your local supervisory authority instead.

13. Changes to This Notice

We may update this notice. Where a change is material, we will tell you by email or by a notice in the Services before it takes effect. The date at the top of this page shows when it was last revised.

14. Contact Us

We have not appointed a Data Protection Officer, as we are not required to. Questions about this notice, or about how we handle personal data, go to info@islandbridge.io, or by post to:

Islandbridge Automation Limited
Venture Hub
136 Capel Street
Dublin, D01 T2C9
Ireland
Registered in Ireland, company number 790984