InvoiceIQ
Invoice Intelligence

InvoiceIQ Privacy Policy

Effective date: 24 September 2026. Last updated 24 September 2026.

InvoiceIQ is an accounts-payable automation service operated by Analytos ("we", "us"). This policy explains what we collect when you use InvoiceIQ through the web application, the public API, or an AI assistant connected through our MCP server (ChatGPT, Claude or another MCP client).

What we collect

How we use it

AI processing

Invoice content is sent to an AI model provider to extract and classify fields. The provider is chosen by Analytos for the service by default (currently one or more of: OpenAI, Microsoft Azure OpenAI Service, Anthropic, Google Gemini API, Google Cloud Vertex AI); where your organization supplies its own provider key, that provider relationship is yours. Prompts contain the invoice being processed and the coding context required for it; when you use the spend-search or analytics features the question you type is sent as well, and when you author coding or billing rules the rule text is sent. Providers process the content under their API terms; we do not use your content to train models and we contract with providers on terms that prohibit training on it.

Connected assistants (MCP)

When you connect ChatGPT, Claude or another MCP client, you sign in with your InvoiceIQ credentials and grant that client specific scopes (for example read invoices, upload invoices, post bills). The client acts as you, inside your organization and role. A connected assistant receives the same records you could open in the web application, in the form its tools return: invoice headers and lines, coding explanations, match reports, purchase orders, goods receipts and bills read from your ERP, posting history, rules and reference data. It can also upload invoices and, after your explicit confirmation, post vendor bills. It never receives passwords, tokens or ERP credentials. Bill posting always requires an explicit confirmation step. Access tokens expire automatically and refresh tokens rotate; to revoke a connected client's access, contact your organization administrator or support@analytos.ai.

Sharing

Retention

Invoice records and audit logs are kept for as long as your organization keeps its account and for the period your organization configures for accounting retention. Uploaded PDFs can be deleted by an organization administrator. Account data is deleted within 30 days of account closure unless retention is required by law.

Security

Data is encrypted in transit (TLS) and at rest. Secrets are envelope-encrypted with a managed key service. Access is limited by organization and role, enforced in the database. We log and review administrative access.

Your rights

Depending on where you live you may have rights to access, correct, export or delete your personal data, or to object to certain processing. Contact your organization administrator or us at the address below. If you are in the EU/UK you may also complain to your supervisory authority.

International transfers

Data may be processed in the United States and in the regions your organization selects. Transfers rely on standard contractual clauses or equivalent safeguards.

Children

InvoiceIQ is a business service and is not directed to children under 16.

Changes

We will post changes here and, for material changes, notify organization administrators by e-mail.

Contact

Analytos, privacy@analytos.ai