Privacy Policy
Version 2.0 | Effective Date: 10 July 2026 | Last Updated: 10 July 2026

On this page:1. Introduction and Scope
1. Introduction and Scope
This Privacy Policy explains how AccDoo (“AccDoo”, “we”, “us”, “our”), a cloud application developed and operated by Era Biz Solutions (Pvt) Ltd (bearing business registration number P.V. 81735), registered office at Level 35, West Tower, World Trade Center, Colombo 01, Sri Lanka (Tel: +94 11 749 4291), collects, uses, discloses and protects personal data in connection with AccDoo.ai — our cloud accounting, invoicing, payroll, HRMS, inventory and compliance platform – our websites, free online tools (including the VAT invoice generator), mobile applications and related services (the “Services”), wherever in the world you use them.
We are headquartered in Sri Lanka and comply with the Personal Data Protection Act No. 9 of 2022 of Sri Lanka (“PDPA”). Because our users are global, this Policy is also designed to satisfy the EU and UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and comparable laws elsewhere. Sections 1–14 apply to everyone; Section 15 contains regional supplements that apply in addition, based on where you live, and prevail over the general sections in case of conflict.
Read this Policy together with our Terms of Service and Cookie Policy. Capitalised terms not defined here have the meanings in the Terms of Service.
2. Our Role: Controller vs Processor
We act as a Controller(called a “business” under the CCPA) — deciding the purposes and means of processing — for personal data about you when you visit our websites, use free tools, create or administer an account, contact support, receive our marketing, or are billed by us.
We act as a Processor(a “service provider” under the CCPA) for personal data contained in Customer Data that our business customers upload or generate in the platform — most importantly Personnel Data (employee payroll, statutory contribution, attendance and leave records) and the contact details of our customers’ own clients and suppliers appearing in invoices and ledgers. For that data, our customer is the Controller; we process it only on the customer’s instructions under our Terms of Service and Data Processing Addendum (“DPA”); and individuals should direct privacy requests to the relevant employer or business. Where such a request reaches us, we will forward it to the responsible customer and assist them as required by applicable law.
3. Personal Data We Collect
Data you provide
- Account and identity data: name, business name and registration details, designation, email address, mobile number, country, password (stored hashed), profile photograph (optional);
- Billing data:billing address, tax registration numbers (e.g., VAT/GST/TIN), payment card or bank details (collected and stored by our payment processors — we retain only tokens, card brand and last four digits), invoices and payment history;
- Communications: support tickets, chat and email correspondence, call recordings where notified, survey responses and feedback;
- Verification data: documents or numbers you provide to verify your business where required for regulated features (e.g., payroll filings).
Data collected automatically
- Usage data: features used, pages viewed, actions taken, timestamps, referral URLs and interaction with in-product messages;
- Device and connection data: IP address, approximate location derived from IP, browser type and version, operating system, device identifiers and language settings;
- Cookies and similar technologies: as described in our Cookie Policy;
- Log and security data: authentication events, admin actions and audit trails maintained for security and accountability.
Data from third parties
Payment processors (payment status and fraud signals); single sign-on providers you choose (e.g., Google — name, email); integration partners you connect; publicly available business registers; and analytics or advertising partners as described in the Cookie Policy.
Free tools
Free tools such as the VAT invoice generator can generally be used without an account. Details you enter are processed in your browser and/or transiently on our servers to produce your document; unless you save them to an account, we do not retain the contents beyond short-lived technical logs. We collect usage analytics on free-tool pages as described in the Cookie Policy.
Special categories / sensitive data
As a Controller we do not intentionally collect special categories of personal data (such as health or biometric data) or, in CCPA terms, “sensitive personal information” beyond log-in credentials. Sensitive data appearing in Customer Data (for example, employee medical leave records) is processed by us only as a Processor on the Controller’s instructions.
4. Purposes and Legal Bases
We process personal data only where a lawful condition applies under the PDPA and, where relevant, Article 6 GDPR:
- Providing and operating the Services(account creation, authentication, hosting your workspace, support) — performance of a contract;
- Billing and account administration(invoicing, payment collection, tax documentation) — contract and legal obligation;
- Compliance with law(tax, accounting, anti-money-laundering, sanctions screening, lawful requests from authorities) — legal obligation;
- Security and fraud prevention(monitoring, logging, abuse detection, incident response) — legitimate interests in protecting the Services, our customers and their data;
- Product improvement and analytics(understanding feature usage, diagnosing errors) — legitimate interests, and consent where required for non-essential cookies;
- Service communications(transactional emails, security notices, important changes) — contract / legitimate interests;
- Marketing(newsletters, product updates) — consent, withdrawable at any time via the unsubscribe link or account settings; or, where permitted, legitimate interests for similar-products marketing to existing business customers with an opt-out;
- AI feature operation(processing your inputs to return outputs) — performance of a contract (see Section 7);
- Legal claims(establishing, exercising or defending) — legitimate interests.
Where we rely on legitimate interests we balance them against your rights and freedoms and do not proceed where your interests override ours. You may request information about a balancing assessment via Section 14.
6. International Data Transfers
- We are a Sri Lankan company with a global user base. Our primary hosting region is US East (Virginia, USA), and some infrastructure providers process backup records or metadata in other countries, including the United States, the European Union, and Singapore.
- Depending on the legal origin of your personal records, we implement the following transfer protection safeguards:
- Data governed by the Sri Lankan PDPA: Cross-border transfers are conducted strictly under the conditions of Section 26 of the PDPA, ensuring that any recipient country provides a comparable level of data protection or that adequate contractual safeguards are in place.
- Data governed by the EU/UK GDPR:Where data is transferred from the EEA or the UK to countries without an adequacy decision (such as Sri Lanka or the United States), we implement the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, alongside supplementary technical measures like encryption.
- Data governed by US State Laws: Data transferred across state or national borders is secured via data processing agreements with our service providers to prevent unauthorized disclosure or processing outside our strict instructions.
You may request a copy of the relevant safeguards via Section 14.
7. AI Features and Automated Decision-Making
When you use AI Features, your prompts and relevant workspace context are processed to generate outputs. Where third-party model providers are used, they are contractually prohibited from using your data to train their models, and we do not use your Customer Data to train generalised models available to other customers without your explicit opt-in consent.
We do not make decisions producing legal or similarly significant effects on you based solely on automated processing (within the meaning of section 24 PDPA or Article 22 GDPR). AI outputs in the product are recommendations requiring human review and confirmation by you. If we ever introduce such automated decision-making, we will provide the notices, safeguards and objection/review rights required by applicable law.
8. Data Retention
We retain personal data only as long as necessary for the purposes described, then delete or irreversibly anonymise it. Indicative periods:
- Account data: life of the account plus up to [90] days after closure (reactivation and export window);
- Billing and tax records:[6–7] years as required by tax and company law applicable to us;
- Support communications: [24] months from resolution;
- Security logs: [12] months, longer for ongoing investigations;
- Marketing data: until consent withdrawal or [24] months of inactivity;
- Backups: encrypted, overwritten on rotation within [35] days.
9. Security
We apply administrative, technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest, role-based access control and least-privilege administration, network segregation, vulnerability management and penetration testing, logging and monitoring, staff confidentiality and training, and vendor security assessment. No system is perfectly secure; safeguard your credentials and enable multi-factor authentication.
If a personal data breach occurs, we will act in accordance with applicable law — including notification to the Data Protection Authority of Sri Lanka under the PDPA, to EU/UK supervisory authorities within 72 hours where the GDPR requires, and to affected individuals where required — and, for Customer Data we process as a Processor, we will notify the affected Controller without undue delay.
10. Your Rights
Subject to the conditions and exemptions of the law that applies to you, you have rights that typically include:
- Access— confirmation of processing and a copy of your personal data;
- Rectification / correction— of inaccurate or incomplete data;
- Erasure / deletion— in the circumstances the applicable law provides;
- Withdraw consent— at any time, without affecting prior processing;
- Object— to processing based on legitimate interests, and always to direct marketing (which we will stop on request);
- Restriction of processing and data portability— where the GDPR or similar laws apply;
- Review of automated decisions— human review of any decision based solely on automated processing that significantly affects you;
- Complain— to us first if you wish, and to your supervisory authority (see Section 15 for the authority relevant to your region).
To exercise any right, contact us via Section 14. We may verify your identity, and an authorised agent may act for you where the law allows. We respond within the period required by the applicable law — under the PDPA within the prescribed period (we aim for [21–30] days); under the GDPR within one month (extendable by two for complex requests); under the CCPA within 45 days (extendable by 45). We do not charge a fee unless the law permits, and we will not discriminate against you for exercising your rights. If your request concerns data we hold as a Processor (for example, your employer’s payroll records), we will refer it to the responsible Controller and assist them.
11. Children
The Services are intended for business users aged 18 and over, and we do not knowingly collect personal data from children as a Controller (including anyone under 13, or under 16 where the GDPR’s information-society-services consent age applies without parental consent). Data about minors within Customer Data (for example, statutory apprentice records) is processed solely on the Controller’s instructions, and the Controller is responsible for satisfying the children’s-data requirements of the laws applicable to it. If you believe a child has provided us personal data directly, contact us and we will delete it.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified by email or prominent in-product notice at least [30] days before taking effect; the “Last Updated” date reflects the latest revision. Where a change requires fresh consent under applicable law, we will seek it.
14. Contact Us
- Controller: Era Biz Solutions (Pvt) Ltd (Business Registration No. P.V. 81735) for the AccDoo.ai platform.
- Registered Office: Level 35, West Tower, World Trade Center, Colombo 01, Sri Lanka.
- Data Protection Officer / Privacy Contact: Privacy Operations Team, privacy [at] accdoo.com, +94 11 749 4291.
- EU Representative under Article 27 GDPR: Inquiries from data subjects or supervisory authorities within the European Union may be directed to our central helpdesk at privacy [at] accdoo.com, which will route your request directly to our designated regional legal representative.
- UK Representative: Inquiries regarding UK data protection compliance may be sent directly to privacy [at] accdoo.com for prompt resolution with our UK administrative point of contact.
- India Grievance Officer: Inquiries or grievances arising under the DPDP Act may be addressed to our designated Data Grievance Officer via privacy [at] accdoo.com
15. Regional Supplements
Sri Lanka (PDPA)
You have the rights of access, rectification, erasure, withdrawal of consent, objection and review of automated decisions set out in Part II of the PDPA, exercisable as described in Section 10. If you are dissatisfied with our response to a request or appeal, you may complain to the Data Protection Authority of Sri Lanka (dpa.gov.lk). Cross-border transfers follow section 26 of the PDPA as described in Section 6.
European Economic Area and United Kingdom (GDPR / UK GDPR)
Our legal bases are set out in Section 4. You additionally have the rights to restriction of processing and data portability, and the right to lodge a complaint with the supervisory authority of your habitual residence, place of work or place of alleged infringement — in the UK, the Information Commissioner’s Office (ico.org.uk). Where processing is based on legitimate interests you may object on grounds relating to your particular situation. International transfers use the safeguards in Section 6. We are not established in the EU/UK; our representative details appear in Section 14.
California (CCPA/CPRA)
In the preceding 12 months we have collected the categories of personal information described in Section 3 (identifiers; commercial information; internet activity; approximate geolocation; professional information; and inferences drawn for product analytics), from the sources in Section 3, for the purposes in Section 4, disclosed for business purposes to the categories of recipients in Section 5. We do not sell personal information and have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes requiring a right to limit. Optional advertising cookies may constitute “sharing”; you can opt out via “Cookie Settings” or the “Your Privacy Choices” link, and we honour Global Privacy Control (GPC) signals as an opt-out of sharing for that browser. California residents have the rights to know/access, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination, exercisable via privacy [at] accdoo.com or accdoo.ai/privacy-request, directly or through an authorised agent. We retain each category no longer than described in Section 8.
Other United States states
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah and Texas) have comparable rights of access, correction, deletion, portability and opt-out of targeted advertising, exercisable as above; where your state provides an appeal process for refused requests, you may appeal by replying to our decision, and if unresolved, contact your State Attorney General.
India (DPDP Act, 2023)
Where the Digital Personal Data Protection Act, 2023 applies, we process digital personal data for the purposes in Section 4 on the basis of your consent or applicable legitimate uses. You have rights to access, correction, erasure, grievance redressal and nomination, exercisable via our grievance contact in Section 14, and thereafter to the Data Protection Board of India.
Australia
We handle personal information consistently with the Australian Privacy Principles where the Privacy Act 1988 (Cth) applies. Complaints may be made to us first and thereafter to the Office of the Australian Information Commissioner (oaic.gov.au). Overseas disclosure locations are described in Section 6.
Canada
Where PIPEDA or substantially similar provincial laws apply, we process personal information with consent or as otherwise permitted, and you may access and correct your information and complain to the Office of the Privacy Commissioner of Canada. Our privacy contact in Section 14 is accountable for compliance.
Singapore
Where the Singapore PDPA 2012 applies, our Data Protection Officer contact is in Section 14, and you may access and correct personal data and withdraw consent as provided by that Act, with complaints to the Personal Data Protection Commission (pdpc.gov.sg).

