Privacy Policy
Last Updated: August 2026
1. Scope and Swiss revFADP Compliance
This Privacy Policy outlines how Digintu Tech Ltd ("we", "our") collects and processes personal data. Our processing is strictly governed by the revised Swiss Federal Act on Data Protection (nFADP). We act as a data processor for the accounting data passing through our middleware, and as a data controller only for the account management data required to provide the service.
2. Zero-Retention Middleware Principle
Our core application logic is designed as a pass-through engine. Financial documents (invoices, statements, PAIN.001 exports) retrieved from Xero or external integrations are processed in volatile memory. We do not permanently store your accounting files, contact lists, or transaction histories. Only cryptographic hashes are retained for duplicate protection.
3. Data We Collect
We collect only what is strictly necessary to maintain your account: Identity Data (Name, email address), Authentication Data (OAuth2 tokens connecting your Xero account, encrypted at rest), and Billing Data (processed entirely by our sub-processor, Stripe Inc.).
4. System Audit Logs
To ensure non-repudiation and security, we maintain pseudonymized system audit logs (tracking IP addresses, execution timestamps, and success/failure states of API calls). These logs are exclusively accessible to Workspace Owners for diagnostic and due diligence purposes.
5. User Rights & Data Deletion
Under the nFADP, you hold the right to access, rectify, or erase your data. Users can invoke an immediate hard-deletion of their Digintu workspace directly from the profile settings. This action instantly drops all corresponding tokens, audit logs, and account configurations from our Swiss-hosted servers.
For detailed inquiries regarding our role as a processor, please refer to our Due Diligence Pack or contact our Data Protection Officer at xero@digintu.tech.