Privacy Policy
Who we are and what this policy covers
Sumly is operated by Sumly Ltd, with registration number [TBA]. This policy covers our websites, the Sumly accounting application, customer accounts, support, sales and the professional or administrative services we arrange or provide. Together, we call these the "Services".
It applies when you visit our website, use the application, contact us, buy or ask about a Service, work with us, or appear in information that a customer or service partner gives us. It does not replace the privacy notice of a bank, government body, independent professional or other third party whose service you use.
When Sumly is a controller and when it is a processor
For the website, account administration, billing, our direct relationship with you, security, marketing and Services that Sumly delivers for its own stated purposes, Sumly decides why and how personal data is used. In those cases, Sumly is the data controller.
A business using the application may also add personal data about its customers, suppliers, workers, directors, shareholders and other people. That business normally decides why the data is used and acts as the controller. Sumly processes the data on its instructions under our agreement with that business. If your data is held in a customer's Sumly account, you should usually send privacy requests to that customer. We will help the customer respond where required.
Personal data we collect
The data depends on which part of Sumly you use. It may include:
- Identity and contact data. Your name, email address, telephone number, postal address, job title and preferred language.
- Account and business data. Login and account details, preferences, permissions, company details, registration numbers, tax numbers, business contacts and information about authorised users.
- Accounting and financial data. Bank transactions and balances, invoices, receipts, expenses, payments, tax records, payroll or employment records, counterparty details and other information added to the application or given to us for a Service.
- Service and verification data. Depending on the Service, this may include identification documents, proof of address, date of birth, nationality, tax residence, signatures, ownership and management information, application forms and correspondence with professional advisers or public authorities.
- Documents and communications. Files you upload or send, emails, messages, support requests, meeting notes, feedback and records of our work for you.
- Payment and subscription data. Your plan, billing contact, invoices, payment status and payment details. When a payment provider collects full card details directly, its own privacy notice also applies.
- Technical and usage data. IP address, device and browser information, login and security events, pages or screens viewed, clicks, feature use, referral information, approximate location derived from an IP address, error reports and online identifiers.
- Marketing data. Communication preferences, campaign and conversion information, and interactions with our website, application or advertising.
Documents may sometimes contain sensitive personal data or information about people other than the person who gives them to us. Please only provide personal data that is needed and that you are authorised to share. Where sensitive data is necessary, we process it only when the law allows and with safeguards suited to the risk.
Where personal data comes from
We may receive personal data:
- directly from you or from an administrator of your Sumly account
- from the business, employer or other customer that asked us to handle it
- from services you connect, such as banks, open-banking providers, payment providers and other software integrations
- from professional advisers, service partners, public authorities, public registers and other organisations involved in a Service
- automatically from your device through logs, cookies, pixels and similar technologies
Why we use personal data and our legal bases
We use personal data only when we have a lawful reason. The main reasons are:
- To take steps before a contract and perform it. This covers creating and managing an account, providing the application and Services, processing connected data, handling payments, communicating with you and providing support.
- To comply with legal obligations. This may include tax, accounting, company, employment, record-keeping and, where applicable, identity verification, anti-money laundering or requests from courts and public authorities.
- For our legitimate interests. These include securing and operating Sumly, preventing fraud and misuse, troubleshooting, improving the Services, understanding business performance, managing customer relationships, protecting legal rights and sending relevant business communications where the law permits. We weigh these interests against your rights before relying on this basis.
- With your consent. We use consent for optional marketing, analytics or advertising technologies where the law requires it, and for other specific purposes we explain when asking. You can withdraw consent at any time.
Some information is required to create an account, provide a requested Service or meet a legal obligation. If you do not provide it, we may be unable to open the account, complete the work or continue providing the relevant Service. We will tell you when this applies.
Cookies, pixels and analytics
Our website and application use cookies, tags, pixels, software development kits and similar technologies. Some are needed for login, security, preferences and core functionality. Others help us see how people find and use Sumly, diagnose problems, measure whether advertising works and improve the experience.
These technologies may collect or generate:
- online identifiers and cookie or device IDs
- IP address, browser, device and approximate location information
- pages, screens, buttons and features used
- referring links, campaign information, signups and other conversion events
We use first-party analytics and may use advertising measurement tools, including Google Ads, to understand campaign performance. Google and other providers may receive online identifiers and information about visits or conversion events. For some of their processing, they may act as separate controllers under their own privacy policies.
Where consent is required for non-essential tracking, consent is our legal basis. You can refuse or withdraw consent without losing access to core Services. You can also block or delete cookies through your browser or device settings, though strictly necessary cookies may be needed for the application to work.
Who we share personal data with
We do not sell personal data. We may share it with:
- Technology providers. Hosting, storage, database, authentication, security, communications, support, document-processing, analytics and other suppliers that help us operate Sumly.
- Payment and financial providers. Payment processors, banks, open-banking providers and integrations used to provide a feature you request.
- Professional and service partners. Bookkeepers, accountants, auditors, lawyers, corporate service providers and other specialists involved in a Service. Some act on our instructions. Others are independent controllers with their own professional and legal duties.
- Your organisation. Account owners, administrators and authorised users may access data according to their permissions.
- Authorities and legal recipients. Tax, company, employment and other public authorities, courts, regulators, law enforcement, insurers and advisers when required by law or needed to establish, exercise or defend legal claims.
- Business transaction recipients. A buyer, investor or adviser if we consider a financing, reorganisation, sale or transfer of all or part of the business, subject to suitable confidentiality and data protection safeguards.
Service providers acting as our processors receive only the data needed for their work and must protect it under contract. When a third party acts as an independent controller, its own privacy notice also applies.
International transfers
Some providers or recipients may process personal data outside the European Economic Area. Where this happens, we use a lawful transfer mechanism, such as a European Commission adequacy decision, standard contractual clauses or another safeguard permitted by data protection law. Contact us if you want information about the safeguards used for a particular transfer.
How long we keep personal data
We keep personal data only as long as needed for the purpose for which it was collected, to provide the Services, meet legal and professional record-keeping duties, resolve disputes, prevent fraud and enforce our agreements. There is no single period that fits every type of data.
- Account and service data is generally kept while the account or Service is active and for a reasonable period afterwards.
- Accounting, tax, company, payment, identity and compliance records may be kept for the period required by applicable law or professional obligations.
- Support, security and technical records are kept for as long as needed to resolve issues, protect the Services and maintain reliable records.
- Marketing data is kept until you opt out, withdraw consent or it is no longer useful for the stated purpose.
When data is no longer needed, we delete or anonymise it. Closing an account does not always mean immediate deletion because legal retention periods, active disputes, fraud prevention and backup cycles may still apply. Data we process for a customer is retained and deleted under our agreement with that customer, subject to applicable law.
How we protect personal data
We use technical and organisational measures designed for the sensitivity of the data and the risks involved. We restrict access to people and providers who need it for their work, require confidentiality and review the safeguards used by service providers. No online system can be guaranteed completely secure. If you believe your account or data may be at risk, contact us promptly.
Your data protection rights
Depending on the circumstances, you may have the right to:
- be informed about how your personal data is used and access a copy of it
- correct incomplete or inaccurate personal data
- ask us to delete personal data
- ask us to restrict how personal data is used
- receive certain data in a portable, machine-readable format
- object to processing based on legitimate interests
- object at any time to personal data being used for direct marketing
- withdraw consent at any time, without affecting earlier lawful processing
- ask for human review where a decision with legal or similarly significant effects is made solely by automated means, where applicable
These rights are not absolute. For example, we may need to keep information to meet a legal obligation or defend a legal claim. We may ask for information to verify your identity before acting on a request. We normally respond within one month, though the GDPR allows more time for complex or multiple requests.
To exercise a right, email support@sumly.cy. If the request concerns data controlled by a Sumly customer, we may refer you to that customer and help them handle the request.
Complaints
Please contact us first if you have a concern so we can try to resolve it. You also have the right to complain to the supervisory authority where you live or work, or where you believe a breach took place. In Cyprus, this is the Office of the Commissioner for Personal Data Protection.
Changes to this policy
We may update this policy when our Services, providers or legal obligations change. We will change the date at the top and, where appropriate, give notice by email or inside the application.
Contact
For questions, requests or concerns about privacy, email support@sumly.cy or write to:
Sumly LtdEleftheriou Venizelou 48
8022 Paphos
Cyprus