Octobooks Privacy Notice for the app
Version of 9 October 2026. This notice covers the Octobooks app. The website and its early access list have their own short Privacy note.
1. Who we are
- Octobooks is run by its founder as a sole trader in the United Kingdom, trading as Octobooks. Email: support@octobooks.ai. The full name and address of the operator are added here before paid plans start.
- For the data in this notice (your account, billing, support, our website) we are the controller.
- For the data inside your books (your customers, suppliers and staff), your business is the controller and we only process it for you. That is covered by the Data Processing Agreement, not by this notice.
2. What we collect
- Account data: name, business name, email, country, login and passkey data, the approval mode you choose, who you invited.
- Billing data: plan, invoices, payment status. Card and bank details go to Paddle, our payment provider, and we never see them in full.
- Usage and security logs: IP address, device and browser type, time of access, actions taken in your account, connector and API calls. We need these to run, secure and debug Octobooks and to keep the audit trail.
- Support and email: what you write to us, and our replies.
- Cookies: only the ones needed to log you in. See the Cookie Notice.
3. Why we use it, and on what legal basis
| Purpose | Legal basis (UK GDPR and EU GDPR) |
|---|---|
| Creating and running your account, delivering Octobooks | Contract (Art. 6(1)(b)) |
| Billing, invoices, tax records | Legal obligation (Art. 6(1)(c)) and contract |
| Security, fraud prevention, audit trail, fixing faults | Legitimate interests (Art. 6(1)(f)): a safe, working service |
| Answering your emails | Contract or legitimate interests |
| Service emails (changes to terms, prices, incidents) | Contract and legal obligation |
| Product news by email | Consent, or legitimate interests for existing customers with an easy opt out in every email |
We do not sell your data, we do not use it for advertising, and we do not use it to train AI models.
4. AI and automated decisions
- Some Octobooks features use AI to suggest bookings, rules and answers. Suggestions are checked and released under the approval mode you choose.
- We make no decisions about you with legal or similarly significant effects by automated means alone.
- Some of our emails and chat replies may be written by an AI assistant, including our assistant "Christina". We say so where that happens.
5. Who we share it with
Only the service providers we need to run Octobooks, under contracts that bind them to protect it. The current list, with locations, is in the Sub-processor List. In short: hosting (Hetzner, Germany), payments (Paddle, once paid plans start) and email (Google Workspace). Octobooks itself sends your books to no AI provider today; your own AI assistant reads what you let it read. We may also disclose data where the law requires it, or to protect our legal rights.
6. Transfers outside the UK and EU
Your data is hosted in Germany. Where a provider processes data outside the UK or EU (for example in the United States), we rely on an adequacy decision, the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement or Addendum.
7. How long we keep it
- Account and usage data: while your account is open, then 90 days for export, then deleted. Backups roll off within a further 35 days.
- Security logs: up to 12 months.
- Billing records: as long as tax law requires (6 years in the UK).
- Support emails: up to 3 years after the last contact.
8. Your rights
You can ask to see, correct, delete, restrict or port your data, and object to processing based on legitimate interests or to marketing at any time. Where we rely on consent you can withdraw it. Email us; we answer within one month.
You can also complain to the UK Information Commissioner's Office (ico.org.uk) or to the data protection authority in your EU country. We would like the chance to fix it first.
9. Security
Data is encrypted in transit, sensitive fields and backups are encrypted, access is limited to people and systems that need it, every change is logged, and backups are tested. No system is perfectly secure; we tell you without undue delay if a breach affects your data.
10. Changes
We will post changes here and email you about material ones.