← Settl

Privacy Policy

Product: Settl (accounts-receivable chasing software, self-hosted) Vendor: Settl ("we", "us", "the vendor") Effective date: 2026-09-19 · Version: 1.0 Contact for privacy matters: partners@piedmontaccounting.com

Plain-language summary: Settl is software the client installs on the client's own server. We never receive the invoices, customer names, email addresses, phone numbers or reminder contents stored in a client's installation. The only data that reaches us is licence and licence-check-in information, plus whatever the client chooses to send us for support, and whatever an individual sends us through this website.


1. Scope — two very different roles

This policy covers both sides of our business, and they must not be confused:

Role Whose data What we are
A. This website and our public demo installation Visitors to the website, the demo, and people who contact us Controller of the data listed in §3
B. A licensed Settl installation running on a client's own server The client's invoices and the client's customers (debtors) Not a controller and not a processor of that data. We have no access to it. The client is the controller of everything in their installation

An agreement to process personal data on a client's behalf (a data-processing agreement) is not part of the licence, because we do not process the client's data. If a client asks for one, the correct answer is that the processing does not occur; the section that governs the narrow exception (a support bundle the client chooses to send us) is §4.4.

How we characterise it in writing: the client is the sole controller of every record in the installation. We do not host, process, store or have access to that data, so we are not a processor under GDPR Article 28 or an equivalent law. The check-in described in §3.4 is administrative metadata about the licence, not about the client's business: we process it to perform the licence contract and on the basis of our legitimate interest in operating, securing and supporting the licence service, and we keep it to the minimum needed for that.


2. What we do NOT collect

For the avoidance of doubt, in the ordinary operation of a licensed installation we do not receive, store, copy, back up, or have any means of accessing:

  • invoice contents, amounts, due dates, payment status;
  • the client's customers' names, email addresses, postal addresses or phone numbers;
  • the contents of reminder emails or the transcripts of calls;
  • the client's accounting-system credentials, email credentials or carrier credentials;
  • the client's database file.

The client's installation is not reachable from the internet at our instigation. We have no remote-access tool, no agent, and no back door in the delivered software.


3. Data we do collect (website, demo, and licence operations)

# Data Source Purpose Lawful basis
3.1 Licence identity: client name, licence ID, tenant identifier Provided by the client when a licence is issued Issuing and administering the licence Contract
3.2 Contact details of the person we deal with: name, business email, business phone Provided by the client or the prospect Delivery, support, invoicing, renewal notices Contract / legitimate interests
3.3 Invoicing and payment records The client's payment Accounting, tax and legal record-keeping Legal obligation
3.4 Licence check-in data: licence ID, application version, the domain the installation is served from, a host identifier, and counts only (e.g. number of invoices, number of reminders sent), plus the time of the check-in Sent by the installation every 6 hours while it can reach our licence service Verifying the licence, knowing which installations are alive, answering "is this version affected?" in a security notice Contract / legitimate interests
3.5 Support correspondence and any diagnostics bundle the client chooses to send The client Diagnosing the problem the client asked us to fix Consent (the client decides to send it)
3.6 Website server logs: IP address, timestamp, request line, user agent Automatic, from serving the website Security, abuse prevention, fault diagnosis Legitimate interests (short retention, see §7)
3.7 Enquiry data when a prospect contacts us: name, email, and whatever they write The individual Answering the enquiry, sales follow-up Legitimate interests / consent
3.8 Acceptance record: which user account accepted which version of the Terms, the Privacy Policy and the Licence Agreement, and when Written by the installation when a user ticks the acceptance box at sign-in Proving that the terms a user is held to were the terms that user was shown. Not profiling, and not a sign-in log Contract / legitimate interests

3.8 is deliberately minimal and deliberately local. The record holds an account, a document version and a timestamp. It holds no IP address, no user agent, no device identifier and no location, because it exists to prove assent and must not become a tracking log. In a client's own installation this record is the client's data and we never see it (§1 role B); in the demonstration instance we operate it is ours, and it is deleted with the demo. Records are kept for as long as the terms may be relied on, and are deleted with the rest of the account's data on request.

A check-in never carries invoice contents, customer names, customer contact details, credentials, message bodies, or file contents. The installation sends counts and identifiers only. A client can leave the check-in address blank, in which case the installation sends nothing at all (and the licence is then honoured offline for its stated term).

3.1 Cookies and similar technologies

See the separate Cookie Policy. In short: one strictly necessary session cookie for signing in to this website and the demo, no analytics, no advertising, no tracking pixels, and no third-party content that would see a visitor's IP address.

3.2 No automated decision-making, no profiling, no sale of data

We do not use personal data for automated decision-making with legal effect, we do not profile individuals for marketing, and we do not sell or share personal data with advertisers or data brokers. We do not use customer data to train machine-learning models.


4. Who receives data, and where it goes

4.1 Sub-processors and services we use

Provider What it sees Why
Our hosting provider (Oracle Cloud, or the provider named on our website) The website and licence service, including check-in records Hosting
Our email provider Correspondence with clients and prospects Email
Our payment processor Payment and invoice details Taking payment
Our source-code host (GitHub) Source code only — never client data Software development and release

We do not sell, rent or trade personal data. We disclose it to a third party only where the law compels us (for example a valid court order), after telling the affected party unless we are prohibited from doing so.

4.2 International transfers

We are based in Pakistan and our service providers may store data in other countries. Where a client or website visitor is in the EEA, the UK, Switzerland, Canada or the United States, this means their data may be transferred outside their own jurisdiction. We rely on the contract itself (§3.1–3.6 data is necessary to perform it) and on our providers' standard contractual clauses where they are required.

4.3 Third parties the client's own installation talks to

A licensed installation communicates directly with services the client connects, using the client's credentials: Xero, QuickBooks Online, NetSuite, HubSpot, Microsoft Dynamics, Google (Gmail) or Microsoft (Outlook), and a telephony carrier (Telnyx or Twilio). Those transfers are between the client and their chosen provider. We are not a party to them, do not see them, and are not the sender. The client's own privacy notice must describe them.

4.4 The one exception: a diagnostics bundle

Settl's installer includes a script that builds a diagnostics bundle on the client's machine. It is redacted by design (no credentials, no invoice or customer details). It leaves the client's server only if the client sends it to us, and we use it only for the support request it arrived with. We delete it at the end of that support case, or within 90 days, whichever is sooner, unless the law requires us to keep it.


5. Data belonging to the client's customers (debtors)

The people who receive reminders and calls from a licensed installation have a relationship with the client, not with us. Requests from such a person (access, correction, deletion, "stop contacting me") are the client's to answer, in the client's installation, and the client is the party obliged to answer them. If one of those requests reaches us, we will pass it to the client and tell the person we have done so.

If you are one of those people and you want the contact to stop: tell the firm that is contacting you. Settl has controls the firm can use immediately — pause chasing for your account, mark an invoice as disputed, remove your contact details, and dismiss your call task.


6. Security

We protect the data in §3 with: TLS in transit; access limited to the vendor; strong credentials; a secret key held only on the systems that need it; encrypted storage of any provider credentials we hold; and no client credentials held at all (they live in the client's installation, encrypted with the client's own key). Our security overview, including the threat model and the honest list of controls we have not built, is the SECURITY_AND_ACCESS document, available on request.

No system is perfectly secure. If we become aware of a breach affecting personal data we control, we will notify the affected parties and the relevant authority without undue delay and will tell them what we know, what we have done, and what they should do.


7. Retention

Data Retention
Licence and check-in records Life of the licence, then 24 months (dispute and tax cover)
Support correspondence and bundles End of the support case, or 90 days
Invoices, tax records The period the law requires (typically 6 years)
Website server logs 30 days or fewer
Enquiry data 24 months from last contact

We delete or irreversibly anonymise data when the retention period ends.


8. Your rights

Where our processing is subject to the GDPR, UK GDPR, PIPEDA, or a US state privacy law, you may have the right to: know what we hold about you and obtain a copy; have inaccurate data corrected; have data erased; restrict or object to processing; receive data in a portable format; withdraw consent where consent is the basis; and not be discriminated against for exercising a right. Write to partners@piedmontaccounting.com. We answer within 30 days and will explain if we cannot act.

If you are not satisfied, you may complain to your local data-protection authority. For the EEA/UK that is your national authority; for Canada, the Office of the Privacy Commissioner.


9. Children

Settl is business software. It is not directed at children, and we do not knowingly collect data from anyone under 16.


10. Changes to this policy

We may update this policy. The version and effective date at the top always change together, and material changes are notified to the contact on each active licence and posted here at least 30 days before they take effect.


11. Contact

Settl

Email: partners@piedmontaccounting.com · Support: partners@piedmontaccounting.com

Settl · version 1.1 · effective 2026-09-19 · partners@piedmontaccounting.com

The same documents are published with every Settl installation.

Terms of Service Privacy Policy Cookie Policy Refund Policy Settl — Software Licence, Sale and Support Agreement (EULA)
Settl Terms of ServicePrivacy PolicyCookie PolicyRefund PolicySettl — Software Licence, Sale and Support Agreement (EULA)

Comments