Privacy Policy
Last updated: 2026-10-10
This policy explains how Cromalt Ltd ("we", "us", "our") handles personal data in xpense.events (the "Service"), a Cromalt product. We are based in the United Kingdom and comply with the UK GDPR and the Data Protection Act 2018.
- Legal entity: Cromalt Ltd, a company registered in Scotland (company no. SC891350)
- Registered office: 48 West George Street, Glasgow G2 1BP
- Contact for data protection: privacy@xpense.events
- ICO registration number: ZC265567
1. Our two roles
xpense.events is business-to-business software. Our role under data-protection law depends on whose data is involved:
- We are the controller for data about the people who run the account: the individuals who sign up, our billing contacts, and people we communicate with about the Service. This policy governs that data.
- We are a processor for the expense and receipt data that our customer organisations upload. In that case the customer organisation is the controller and decides why and how that data is processed. We only process it on their documented instructions, under our Data Processing Agreement. If your employer or client uses xpense.events, direct data-rights requests about your expenses to them.
2. Personal data we collect (as controller)
| Category | Examples | Source |
|---|---|---|
| Identity & account | Name, email, organisation name, role | You, via WorkOS sign-up |
| Authentication | Login identifiers, session tokens | WorkOS AuthKit |
| Billing | Billing contact, subscription tier, payment status | You / Stripe |
| Usage & technical | IP address, device/browser, log and audit events, error reports (technical details of a fault, with your user and workspace ID) | Automatically, when you use the Service |
| Communications | Emails and support messages you send us | You |
We do not intentionally collect special-category data. Uploaded receipts may incidentally reveal such information (e.g. a pharmacy purchase); that data is handled on behalf of our customers — see our role as processor above.
If you email a receipt to submit@xpense.events, we hold it for up to 30 days until you file it into a workspace, then it is treated as any other receipt; receipts we cannot match to an account are deleted within 7 days.
3. Why we use it and our lawful basis
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Provide and operate the Service, where you are the customer yourself (for example a sole trader) | Contract (Art. 6(1)(b)) |
| Provide and operate the Service, where you act for a customer organisation (as its admin, billing contact or other representative) | Legitimate interests (Art. 6(1)(f)): delivering the Service to, and managing our relationship with, the organisation you act for |
| Authenticate users, keep the Service secure | Legitimate interests (Art. 6(1)(f)) — security |
| Detect, diagnose and fix faults (error monitoring) | Legitimate interests (Art. 6(1)(f)): keeping the Service reliable and secure |
| Bill and take payment | Contract / Legal obligation |
| Keep financial and tax records | Legal obligation (Art. 6(1)(c)) — HMRC |
| Respond to support and communicate service notices | Legitimate interests / Contract |
| Product analytics and improvement (not currently in use) | Legitimate interests, or consent where the technology used (such as cookies) requires it |
| Marketing email (not currently sent) | Legitimate interests, or consent where we ask for it |
Where we rely on legitimate interests, we have weighed them against your rights and will provide the balancing assessment on request.
We do not currently run product analytics or send marketing email. If we start, we will rely on the bases shown above and update this policy first.
Marketing email is also covered by the electronic-marketing rules (PECR), which are separate from the lawful basis above. We will only send it to people who have opted in, or to existing customers about similar services where they were given a clear chance to opt out. Every marketing email will carry an unsubscribe link, and you can object to marketing at any time by emailing privacy@xpense.events.
4. Who we share it with (sub-processors)
We use carefully selected service providers to run xpense.events. Those that process data for us are bound by a data-processing agreement and act only on our instructions. Stripe, our payment provider, also acts as a controller in its own right for purposes such as preventing fraud and meeting its own legal obligations; its privacy policy explains that processing. The current list — including what each provider does and where it is located — is maintained at /legal/subprocessors. We will give notice of changes so controllers can object.
If a workspace admin connects the organisation's own accounting package, expense data from that workspace is sent to the organisation's account there, on its instruction. That provider acts for the organisation, not for us.
We do not sell personal data.
5. International transfers
Our primary database is hosted in the UK/EU (London, eu-west-2). Some
sub-processors (for authentication, AI OCR, payments and email) are based in the
United States or process data outside the UK. Where personal data is transferred
outside the UK, we rely on the UK International Data Transfer Agreement (IDTA) or
the UK Addendum to the EU Standard Contractual Clauses, together with additional
safeguards as appropriate. Details per provider are in our
sub-processor list.
6. Automated processing / AI
We use an AI vision model (via the Vercel AI Gateway) to read uploaded receipt images and extract fields such as merchant, amount and date ("OCR"). This is a labour-saving aid: extracted values are presented for human review and can be edited before an expense is submitted. We do not make solely automated decisions that produce legal or similarly significant effects about you. Every OCR request is sent with a zero-data-retention requirement: it is only passed to model providers that have agreed not to keep the data after processing or use it to train models, and it is refused if no such provider is available. See our security page for detail.
7. How long we keep it
We keep personal data only as long as necessary.
Data we hold as controller
- Account data: for as long as you belong to a workspace. When a workspace is deleted (see below), anyone left with no other workspace is anonymised and their login is removed.
- Our own billing and tax records for a customer's subscription: 6 years, to meet HMRC and company-law requirements.
- Logs and security events: 12 months.
- Support messages: closed support tickets, and the original email, are deleted 24 months after the ticket closes.
Expense data we hold for customers (as processor)
- Expenses, receipts and reports are kept for as long as the customer's workspace is open. The customer decides what is recorded in it.
- A customer's admin can close the workspace at any time. It is then locked, and for 30 days its admins can download the data (a spreadsheet of every expense and an archive of the receipt files) or reopen the workspace.
- After those 30 days the workspace is permanently deleted: every expense, receipt file, report and membership.
- Keeping records to meet the customer's own obligations (for example to HMRC) is the customer's responsibility. Download the data before the 30 days end.
What remains for a short time after deletion
- Database history: deleted data can still be restored from database history for up to 7 days. This covers the database only.
- Error reports: held by our error-monitoring provider for up to 90 days. They contain technical details of a fault with user and workspace IDs.
- Emails we have already sent stay with the people who received them.
8. Your rights
Under UK GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and to withdraw consent where we rely on it. To exercise any of these, contact privacy@xpense.events. We respond within one month. (If your data is expense data held on behalf of your employer/client, please contact them as the controller.)
You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO) — ico.org.uk, 0303 123 1113 — though we'd appreciate the chance to resolve concerns first.
9. Security
We apply appropriate technical and organisational measures, including tenant isolation, role-based access control, private (non-public) storage of receipt files, encryption in transit and at rest, and least-privilege access. See /legal/security.
10. Cookies
We use strictly necessary cookies for authentication and session security, which do not require consent. We do not currently use any non-essential or analytics cookies. If we introduce them in future, we will ask for your consent first.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified via the Service or by email. The "last updated" date above reflects the latest version.
12. Contact
Questions or requests: privacy@xpense.events, or write to Cromalt Ltd, 48 West George Street, Glasgow G2 1BP.