InvoiceIQ Privacy Policy
Effective date: 24 September 2026. Last updated 24 September 2026.
InvoiceIQ is an accounts-payable automation service operated by Analytos ("we", "us"). This policy explains what we collect when you use InvoiceIQ through the web application, the public API, or an AI assistant connected through our MCP server (ChatGPT, Claude or another MCP client).
What we collect
- Account data. Your name, e-mail address, organization, role, and a hashed password. Roles and organizations decide what you can see and do.
- Invoice content. The PDF files you upload and the data we extract from them: supplier, invoice number, dates, amounts, line items, purchase-order references, and the GL coding and match results we produce. Invoices can contain personal data about people other than you, for example the names of contractors or consultants on line items, contact names and addresses of suppliers, or the person who raised a purchase order in your ERP. We process that data as part of the invoice and the ERP record it belongs to and do not use it for any other purpose.
- ERP records. When you connect an ERP (or use the built-in demo ERP), we read the purchase orders, goods receipts and vendor bills needed to match and post invoices, including their lines, amounts, status, the subsidiary, internal record identifiers and the e-mail address of the person who raised the purchase order, and we write the vendor bills you confirm.
- ERP configuration. Vendor mappings, GL accounts, coding rules, match policies and, when you connect an ERP, the credentials you provide for it (stored encrypted in a secrets manager, never in application logs).
- Usage and audit records. Which user performed which action and when, including every tool call made by a connected AI assistant, so your finance team can audit automated activity. For each action by a connected assistant we store the tool called, a shortened copy of its arguments (for example the text of a question you asked, up to 200 characters; never the contents of an uploaded file), a short excerpt of the result, and the outcome. These records are kept with the audit log. Records of who did what are also part of the business records themselves: the posting history, posted bills, match reports and rule versions show the e-mail address or name of the colleague who posted, approved or created them, and other users in your organization, and assistants they connect, can see those names when they open the record.
- Technical data. IP address, request identifiers and error logs needed to run and secure the service.
How we use it
- To extract, code, verify and post invoices as you instruct.
- To enforce access control: every record is scoped to your organization (database row-level security) and to your role.
- To provide support, detect abuse, and meet legal and accounting record-keeping duties.
- We do not sell personal data and we do not use your invoice content to train AI models.
AI processing
Invoice content is sent to an AI model provider to extract and classify fields. The provider is chosen by Analytos for the service by default (currently one or more of: OpenAI, Microsoft Azure OpenAI Service, Anthropic, Google Gemini API, Google Cloud Vertex AI); where your organization supplies its own provider key, that provider relationship is yours. Prompts contain the invoice being processed and the coding context required for it; when you use the spend-search or analytics features the question you type is sent as well, and when you author coding or billing rules the rule text is sent. Providers process the content under their API terms; we do not use your content to train models and we contract with providers on terms that prohibit training on it.
Connected assistants (MCP)
When you connect ChatGPT, Claude or another MCP client, you sign in with your InvoiceIQ credentials and grant that client specific scopes (for example read invoices, upload invoices, post bills). The client acts as you, inside your organization and role. A connected assistant receives the same records you could open in the web application, in the form its tools return: invoice headers and lines, coding explanations, match reports, purchase orders, goods receipts and bills read from your ERP, posting history, rules and reference data. It can also upload invoices and, after your explicit confirmation, post vendor bills. It never receives passwords, tokens or ERP credentials. Bill posting always requires an explicit confirmation step. Access tokens expire automatically and refresh tokens rotate; to revoke a connected client's access, contact your organization administrator or support@analytos.ai.
Sharing
- Sub-processors: Amazon Web Services (hosting); the AI model providers named under "AI processing"; your ERP vendor when you connect it. A current list, including which provider is active for your organization, is available from support@analytos.ai.
- We disclose data when required by law or to protect the service and its users.
Retention
Invoice records and audit logs are kept for as long as your organization keeps its account and for the period your organization configures for accounting retention. Uploaded PDFs can be deleted by an organization administrator. Account data is deleted within 30 days of account closure unless retention is required by law.
Security
Data is encrypted in transit (TLS) and at rest. Secrets are envelope-encrypted with a managed key service. Access is limited by organization and role, enforced in the database. We log and review administrative access.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data, or to object to certain processing. Contact your organization administrator or us at the address below. If you are in the EU/UK you may also complain to your supervisory authority.
International transfers
Data may be processed in the United States and in the regions your organization selects. Transfers rely on standard contractual clauses or equivalent safeguards.
Children
InvoiceIQ is a business service and is not directed to children under 16.
Changes
We will post changes here and, for material changes, notify organization administrators by e-mail.
Contact
Analytos, privacy@analytos.ai