AccDoo Logo
Simplify Tax & Compliance

Simplify Tax & Compliance

Automatically calculate VAT and taxes, generate downloadable PDF invoices and reports, and stay up to date with changing Sri Lankan tax requirements.

Explore Features
AccDoo Logo
👋

Welcome to Accdoo

Manage your accounting
from anywhere.

Language

Region

© accdoo.ai 2026

1. Introduction and Scope

This Privacy Policy explains how AccDoo (“AccDoo”, “we”, “us”, “our”), a cloud application developed and operated by Era Biz Solutions (Pvt) Ltd (bearing business registration number P.V. 81735), registered office at Level 35, West Tower, World Trade Center, Colombo 01, Sri Lanka (Tel: +94 11 749 4291), collects, uses, discloses and protects personal data in connection with AccDoo.ai — our cloud accounting, invoicing, payroll, HRMS, inventory and compliance platform – our websites, free online tools (including the VAT invoice generator), mobile applications and related services (the “Services”), wherever in the world you use them.

We are headquartered in Sri Lanka and comply with the Personal Data Protection Act No. 9 of 2022 of Sri Lanka (“PDPA”). Because our users are global, this Policy is also designed to satisfy the EU and UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and comparable laws elsewhere. Sections 1–14 apply to everyone; Section 15 contains regional supplements that apply in addition, based on where you live, and prevail over the general sections in case of conflict.

Read this Policy together with our Terms of Service and Cookie Policy. Capitalised terms not defined here have the meanings in the Terms of Service.

2. Our Role: Controller vs Processor

We act as a Controller(called a “business” under the CCPA) — deciding the purposes and means of processing — for personal data about you when you visit our websites, use free tools, create or administer an account, contact support, receive our marketing, or are billed by us.

We act as a Processor(a “service provider” under the CCPA) for personal data contained in Customer Data that our business customers upload or generate in the platform — most importantly Personnel Data (employee payroll, statutory contribution, attendance and leave records) and the contact details of our customers’ own clients and suppliers appearing in invoices and ledgers. For that data, our customer is the Controller; we process it only on the customer’s instructions under our Terms of Service and Data Processing Addendum (“DPA”); and individuals should direct privacy requests to the relevant employer or business. Where such a request reaches us, we will forward it to the responsible customer and assist them as required by applicable law.

3. Personal Data We Collect

3.1

Data you provide

  • Account and identity data: name, business name and registration details, designation, email address, mobile number, country, password (stored hashed), profile photograph (optional);
  • Billing data:billing address, tax registration numbers (e.g., VAT/GST/TIN), payment card or bank details (collected and stored by our payment processors — we retain only tokens, card brand and last four digits), invoices and payment history;
  • Communications: support tickets, chat and email correspondence, call recordings where notified, survey responses and feedback;
  • Verification data: documents or numbers you provide to verify your business where required for regulated features (e.g., payroll filings).
3.2

Data collected automatically

  • Usage data: features used, pages viewed, actions taken, timestamps, referral URLs and interaction with in-product messages;
  • Device and connection data: IP address, approximate location derived from IP, browser type and version, operating system, device identifiers and language settings;
  • Cookies and similar technologies: as described in our Cookie Policy;
  • Log and security data: authentication events, admin actions and audit trails maintained for security and accountability.
3.3

Data from third parties

Payment processors (payment status and fraud signals); single sign-on providers you choose (e.g., Google — name, email); integration partners you connect; publicly available business registers; and analytics or advertising partners as described in the Cookie Policy.

3.4

Free tools

Free tools such as the VAT invoice generator can generally be used without an account. Details you enter are processed in your browser and/or transiently on our servers to produce your document; unless you save them to an account, we do not retain the contents beyond short-lived technical logs. We collect usage analytics on free-tool pages as described in the Cookie Policy.

3.5

Special categories / sensitive data

As a Controller we do not intentionally collect special categories of personal data (such as health or biometric data) or, in CCPA terms, “sensitive personal information” beyond log-in credentials. Sensitive data appearing in Customer Data (for example, employee medical leave records) is processed by us only as a Processor on the Controller’s instructions.

5. How We Share Personal Data

We do not sell personal data, and we do not “share” it for cross-context behavioural advertising as defined by the CCPA, except to the extent optional advertising cookies described in our Cookie Policy constitute sharing — which you can decline or switch off at any time. We disclose personal data only as follows:

  • Service providers / sub-processors:hosting and cloud infrastructure, payment processing, email delivery, support tooling, analytics and AI model providers — bound by contracts requiring confidentiality, security and processing only on our instructions. Current list: [accdoo.ai/legal/subprocessors];
  • Integrations you enable: data needed for a third-party service you connect, shared at your direction;
  • Professional advisers: auditors, insurers, lawyers and accountants under confidentiality;
  • Authorities and legal process: courts, regulators (including the Data Protection Authority of Sri Lanka, EU/UK supervisory authorities and tax authorities) and law enforcement where required by law or necessary to protect rights, safety or the integrity of the Services;
  • Corporate transactions: a buyer or successor in a merger, acquisition, financing or asset sale, with this Policy continuing to apply and notice of any material change.

6. International Data Transfers

  • We are a Sri Lankan company with a global user base. Our primary hosting region is US East (Virginia, USA), and some infrastructure providers process backup records or metadata in other countries, including the United States, the European Union, and Singapore.
  • Depending on the legal origin of your personal records, we implement the following transfer protection safeguards:
  • Data governed by the Sri Lankan PDPA: Cross-border transfers are conducted strictly under the conditions of Section 26 of the PDPA, ensuring that any recipient country provides a comparable level of data protection or that adequate contractual safeguards are in place.
  • Data governed by the EU/UK GDPR:Where data is transferred from the EEA or the UK to countries without an adequacy decision (such as Sri Lanka or the United States), we implement the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, alongside supplementary technical measures like encryption.
  • Data governed by US State Laws: Data transferred across state or national borders is secured via data processing agreements with our service providers to prevent unauthorized disclosure or processing outside our strict instructions.

You may request a copy of the relevant safeguards via Section 14.

7. AI Features and Automated Decision-Making

7.1

When you use AI Features, your prompts and relevant workspace context are processed to generate outputs. Where third-party model providers are used, they are contractually prohibited from using your data to train their models, and we do not use your Customer Data to train generalised models available to other customers without your explicit opt-in consent.

7.2

We do not make decisions producing legal or similarly significant effects on you based solely on automated processing (within the meaning of section 24 PDPA or Article 22 GDPR). AI outputs in the product are recommendations requiring human review and confirmation by you. If we ever introduce such automated decision-making, we will provide the notices, safeguards and objection/review rights required by applicable law.

8. Data Retention

We retain personal data only as long as necessary for the purposes described, then delete or irreversibly anonymise it. Indicative periods:

  • Account data: life of the account plus up to [90] days after closure (reactivation and export window);
  • Billing and tax records:[6–7] years as required by tax and company law applicable to us;
  • Support communications: [24] months from resolution;
  • Security logs: [12] months, longer for ongoing investigations;
  • Marketing data: until consent withdrawal or [24] months of inactivity;
  • Backups: encrypted, overwritten on rotation within [35] days.

9. Security

We apply administrative, technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest, role-based access control and least-privilege administration, network segregation, vulnerability management and penetration testing, logging and monitoring, staff confidentiality and training, and vendor security assessment. No system is perfectly secure; safeguard your credentials and enable multi-factor authentication.

If a personal data breach occurs, we will act in accordance with applicable law — including notification to the Data Protection Authority of Sri Lanka under the PDPA, to EU/UK supervisory authorities within 72 hours where the GDPR requires, and to affected individuals where required — and, for Customer Data we process as a Processor, we will notify the affected Controller without undue delay.

10. Your Rights

Subject to the conditions and exemptions of the law that applies to you, you have rights that typically include:

  • Access— confirmation of processing and a copy of your personal data;
  • Rectification / correction— of inaccurate or incomplete data;
  • Erasure / deletion— in the circumstances the applicable law provides;
  • Withdraw consent— at any time, without affecting prior processing;
  • Object— to processing based on legitimate interests, and always to direct marketing (which we will stop on request);
  • Restriction of processing and data portability— where the GDPR or similar laws apply;
  • Review of automated decisions— human review of any decision based solely on automated processing that significantly affects you;
  • Complain— to us first if you wish, and to your supervisory authority (see Section 15 for the authority relevant to your region).

To exercise any right, contact us via Section 14. We may verify your identity, and an authorised agent may act for you where the law allows. We respond within the period required by the applicable law — under the PDPA within the prescribed period (we aim for [21–30] days); under the GDPR within one month (extendable by two for complex requests); under the CCPA within 45 days (extendable by 45). We do not charge a fee unless the law permits, and we will not discriminate against you for exercising your rights. If your request concerns data we hold as a Processor (for example, your employer’s payroll records), we will refer it to the responsible Controller and assist them.

11. Children

The Services are intended for business users aged 18 and over, and we do not knowingly collect personal data from children as a Controller (including anyone under 13, or under 16 where the GDPR’s information-society-services consent age applies without parental consent). Data about minors within Customer Data (for example, statutory apprentice records) is processed solely on the Controller’s instructions, and the Controller is responsible for satisfying the children’s-data requirements of the laws applicable to it. If you believe a child has provided us personal data directly, contact us and we will delete it.

12. Cookies and Similar Technologies

We use cookies and similar technologies as described in our Cookie Policy [accdoo.ai/legal/cookies], which explains categories, specific cookies, regional consent behaviour (including opt-in consent in the EEA/UK and Global Privacy Control recognition for California residents), and how to manage preferences.

13. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified by email or prominent in-product notice at least [30] days before taking effect; the “Last Updated” date reflects the latest revision. Where a change requires fresh consent under applicable law, we will seek it.

14. Contact Us

  • Controller: Era Biz Solutions (Pvt) Ltd (Business Registration No. P.V. 81735) for the AccDoo.ai platform.
  • Registered Office: Level 35, West Tower, World Trade Center, Colombo 01, Sri Lanka.
  • Data Protection Officer / Privacy Contact: Privacy Operations Team, privacy [at] accdoo.com, +94 11 749 4291.
  • EU Representative under Article 27 GDPR: Inquiries from data subjects or supervisory authorities within the European Union may be directed to our central helpdesk at privacy [at] accdoo.com, which will route your request directly to our designated regional legal representative.
  • UK Representative: Inquiries regarding UK data protection compliance may be sent directly to privacy [at] accdoo.com for prompt resolution with our UK administrative point of contact.
  • India Grievance Officer: Inquiries or grievances arising under the DPDP Act may be addressed to our designated Data Grievance Officer via privacy [at] accdoo.com

15. Regional Supplements

15.1

Sri Lanka (PDPA)

You have the rights of access, rectification, erasure, withdrawal of consent, objection and review of automated decisions set out in Part II of the PDPA, exercisable as described in Section 10. If you are dissatisfied with our response to a request or appeal, you may complain to the Data Protection Authority of Sri Lanka (dpa.gov.lk). Cross-border transfers follow section 26 of the PDPA as described in Section 6.

15.2

European Economic Area and United Kingdom (GDPR / UK GDPR)

Our legal bases are set out in Section 4. You additionally have the rights to restriction of processing and data portability, and the right to lodge a complaint with the supervisory authority of your habitual residence, place of work or place of alleged infringement — in the UK, the Information Commissioner’s Office (ico.org.uk). Where processing is based on legitimate interests you may object on grounds relating to your particular situation. International transfers use the safeguards in Section 6. We are not established in the EU/UK; our representative details appear in Section 14.

15.3

California (CCPA/CPRA)

In the preceding 12 months we have collected the categories of personal information described in Section 3 (identifiers; commercial information; internet activity; approximate geolocation; professional information; and inferences drawn for product analytics), from the sources in Section 3, for the purposes in Section 4, disclosed for business purposes to the categories of recipients in Section 5. We do not sell personal information and have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes requiring a right to limit. Optional advertising cookies may constitute “sharing”; you can opt out via “Cookie Settings” or the “Your Privacy Choices” link, and we honour Global Privacy Control (GPC) signals as an opt-out of sharing for that browser. California residents have the rights to know/access, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination, exercisable via privacy [at] accdoo.com or accdoo.ai/privacy-request, directly or through an authorised agent. We retain each category no longer than described in Section 8.

15.4

Other United States states

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah and Texas) have comparable rights of access, correction, deletion, portability and opt-out of targeted advertising, exercisable as above; where your state provides an appeal process for refused requests, you may appeal by replying to our decision, and if unresolved, contact your State Attorney General.

15.5

India (DPDP Act, 2023)

Where the Digital Personal Data Protection Act, 2023 applies, we process digital personal data for the purposes in Section 4 on the basis of your consent or applicable legitimate uses. You have rights to access, correction, erasure, grievance redressal and nomination, exercisable via our grievance contact in Section 14, and thereafter to the Data Protection Board of India.

15.6

Australia

We handle personal information consistently with the Australian Privacy Principles where the Privacy Act 1988 (Cth) applies. Complaints may be made to us first and thereafter to the Office of the Australian Information Commissioner (oaic.gov.au). Overseas disclosure locations are described in Section 6.

15.7

Canada

Where PIPEDA or substantially similar provincial laws apply, we process personal information with consent or as otherwise permitted, and you may access and correct your information and complain to the Office of the Privacy Commissioner of Canada. Our privacy contact in Section 14 is accountable for compliance.

15.8

Singapore

Where the Singapore PDPA 2012 applies, our Data Protection Officer contact is in Section 14, and you may access and correct personal data and withdraw consent as provided by that Act, with complaints to the Personal Data Protection Commission (pdpc.gov.sg).