01Who is responsible
Clehance Connect is a service of Clehance AI B.V., Nieuwezijds Voorburgwal 162, 1012 SJ Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce under number 98515039 (“Clehance”, “we”).
- For the data of a platform’s customers, the platform decides why the data is processed and is the controller. Clehance processes that data on the platform’s written instructions, as its processor, under a data processing agreement.
- For the data of a platform’s own account with us (its users, its API keys, its invoices) and for our security logs, Clehance is the controller.
02The data Connect handles
| Source | What Connect reads or writes |
|---|---|
| Accounting systems | Reads the administrations, journals, chart of accounts, bank accounts, customers, suppliers, VAT codes and bookings the platform needs. Writes the bookings, invoices, bank transactions and documents the platform sends. Access is granted by the customer through the system’s own consent screen or with a key created in the customer’s account. |
| Mailboxes and file storage | Reads, never writes: new messages and files, to find invoices and receipts. Details for Google accounts in section 3. For a Microsoft 365 or Outlook mailbox, Connect asks Microsoft for Mail.Read (read only) and the account’s e-mail address, and uses them in the same way. For a OneDrive folder, Connect asks Microsoft for Files.Read (read only) and the account’s e-mail address, and uses them in the same way. For a Dropbox folder, Connect asks Dropbox for read-only access to file metadata and content and the account’s e-mail address, and uses them in the same way. |
| The platform’s account | The account name, its users’ e-mail addresses, its API keys (stored as one-way hashes), and the settings the platform chooses. |
| Technical records | For each call to a connected system: when, which operation, the result and the error, with personal data removed from the stored message. |
03Data from Google accounts
What Connect accesses
When a customer connects a Gmail mailbox or a Google Drive folder, Connect asks for read-only access: gmail.readonly for a mailbox, drive.readonly for a Drive folder, and the account’s e-mail address to identify the connection. With that access, Connect searches new messages for likely invoices and receipts, then reads those messages, including their text and PDF attachments, to decide whether they are invoices or receipts. In a Drive folder, it reads the new files of the chosen folder.
How Connect uses it
Each new message or file is checked, by fixed rules, to decide whether it is an invoice or a receipt. Invoices and receipts are delivered to the customer’s workspace on the platform the customer chose. Everything else is discarded at once and not stored. Connect never sends, modifies or deletes messages or files.
Who receives it
Only the platform the customer chose receives the documents. The processors of section 6 host the service; none of them uses Google user data for its own purposes. Connect sends no Google user data to any artificial intelligence provider.
Limited Use
Clehance Connect’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Connect:
- uses Google user data only to provide the invoice collection feature the customer connected;
- transfers Google user data only to the platform the customer chose, to the processors needed to run the service, for security or legal reasons, or with the customer’s explicit consent;
- never uses Google user data for advertising, and never sells it;
- never lets people read Google user data, except with the customer’s explicit consent, for security purposes, to comply with the law, or on aggregated and anonymised data for internal operations;
- does not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models.
04How the data is used
Connect uses the data only to do what the platform asks: read reference data, record bookings and documents, confirm what was recorded, and collect invoices and receipts. It does not:
- combine one customer’s data with another’s, or build statistics or insights across customers;
- reuse a customer’s data for testing, product development or training;
- sell data, share it for advertising, or use it for any purpose the platform did not instruct.
05How long it is kept
| Data | Kept |
|---|---|
| Invoices and receipts found in a mailbox or folder | Until delivered to the platform, then deleted. |
| References to delivered documents | One year, so a document is never delivered twice. |
| Access tokens and keys of a connection | Encrypted while the connection is active; wiped when it is disconnected. |
| Reference data read from an accounting system | Only as a short-lived cache, refreshed from the system. |
| The record of each booking sent | While the connection exists, and one year after it is disconnected, so a reconnection never books the same entry twice. Then deleted. |
| Technical records of calls | 30 days. |
| Events sent to the platform | 90 days. |
| A platform’s account data | For the life of the account, then deleted or returned. |
A platform may instruct shorter periods in its data processing agreement. When a platform ends its agreement, its customers’ data is deleted or returned in the agreed format.
06Hosting and processors
Connect runs on servers in the European Union, and its backups stay in the European Union. Clehance uses a small number of processors, each bound by a data processing agreement: a hosting provider for the servers and the database, and, when enabled, an error-monitoring service hosted in the European Union. The current list, with each processor’s location, is given to every platform and is available on request at hello@clehance.ai. A platform is told before a new processor is added.
07Security
- The tokens and keys of every connection are encrypted at rest, with a separate data key per platform account.
- The platform’s API keys are stored only as one-way hashes; a key is shown once, when it is created.
- All traffic uses encrypted connections (TLS).
- The service runs under database roles with the least rights each part needs.
- Personal data is removed from error messages before they are stored.
08Revoking access
A customer can disconnect a source at any time from the platform. Access can also be revoked at the source: for Google, on the Google account permissions page; for an accounting system, in that system’s connected apps or API keys. Revocation stops all reading and writing at once. Documents and bookings already delivered stay with the platform and in the accounting system.
09Your rights
Requests about personal data (access, correction, deletion, restriction, objection, portability) go first to the platform, which is the controller. Requests sent to Clehance are forwarded to the platform concerned. For the data where Clehance is the controller, write to hello@clehance.ai; Clehance answers within one month. Anyone may also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
10Changes and contact
Clehance updates this policy when the service changes; the date at the top shows the current version, and platforms are told in advance of any change that affects them. Questions go to hello@clehance.ai.