Privacy Policy

Last updated: [Month Day, Year]

1. Introduction

This Privacy Policy explains how [Legal Entity Name] ( “Counted,” “we,” “us,” or “our") collects, uses, stores, shares, and protects personal data when you:

  • visit getcounted.ai and related marketing pages (the “Site”);
  • use the Counted web application, APIs, and connected workflows (the “Platform”); or
  • receive accounting, bookkeeping, or related services delivered through Counted (the “Services”).

Counted is an AI-native subscription accounting operating engine for service-led businesses in the GCC, with the United Arab Emirates as our primary market. We process personal data in accordance with applicable law, including the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, as amended) (“PDPL”).

If you do not agree with this Privacy Policy, please do not use the Site, Platform, or Services.

2. Who is responsible for your data?

Data controller:

[Legal Entity Name]
[Registered address, emirate, UAE]
Trade license / registration: [Number]
Privacy contact: privacy@getcounted.ai

If you use Counted on behalf of a business, that business may also be a controller of certain data processed in connection with its accounting records. Where we process data solely on the business’s instructions, we act as a processor or service provider, as applicable.

3. What this policy covers

This policy applies to:

  • Visitors to our Site (including people who submit contact or waitlist forms).
  • Authorized users of the Platform (accountants, operators, founders, and other users invited by Counted or by a client organization).
  • Client organizations whose financial and operational data we ingest, prepare, and support as part of the Services.

It does not apply to third-party websites, accounting systems, email providers, banks, or messaging platforms that you connect to Counted. Those providers have their own privacy policies.

4. Personal data we collect

We collect only what we need for the purposes described below.

4.1 Information you provide directly

  • Contact and account details: name, email address, phone number, job title, organization name, and communications with us.
  • Onboarding information: business legal name, country, base currency, tax registration number (TRN), and other details needed to set up your organization in Counted.
  • Support and correspondence: messages, feedback, and files you send to our team.
  • Founder or client responses: answers to structured questions we send (for example via the Platform, email, or WhatsApp) when information is missing from source records.

4.2 Information collected through authentication

When you sign in with Google or Microsoft, we receive basic profile information permitted by the OAuth scopes we request (currently limited to identity information such as your email address and name). We use this to authenticate you and manage your account. Access to the Platform is restricted to users who have been onboarded by Counted or authorized by a client organization.

We also create and store session data, including a hashed session token, sign-in provider, sign-in time, IP address, browser user agent, and session expiry/revocation status.

4.3 Financial and business data (Services and Platform)

With your organization’s authorization, we may collect and process:

  • Accounting system data from providers such as Zoho Books or QuickBooks, including chart of accounts, contacts, tax codes, bills, invoices, payments, journal entries, and bank feeds available through those systems.
  • Bank and transaction data, including account metadata, balances where available, and transaction history from native accounting feeds, open-banking providers, or imported statements.
  • Documents and communications, including bills, receipts, invoices, and attachments from connected email or messaging channels (for example Gmail or WhatsApp), plus metadata such as sender, recipient, timestamps, and message identifiers.
  • Extracted document fields, including vendor names, amounts, dates, VAT details, TRNs, and confidence scores produced by automated extraction.
  • Accounting workflow data, including categorization suggestions, match candidates, review items, audit logs, and accountant approval records.

Some of this information may relate to identifiable individuals (for example employees named on expenses, vendor contacts, or email participants). We treat it in accordance with this policy and our contractual obligations.

4.4 Information collected automatically

When you use the Site or Platform, we may automatically collect:

  • Device and usage data: pages viewed, features used, timestamps, referring URLs, and diagnostic logs.
  • Technical data: browser type, operating system, device identifiers, and approximate location derived from IP address.
  • Cookies and similar technologies as described in Section 12.

We do not intentionally collect special categories of personal data unless you or your organization provide it as part of legitimate accounting records (for example payroll-related information in documents).

5. How we use personal data

We use personal data for the following purposes:

PurposeExamples
Provide the ServicesOnboard organizations, connect integrations, ingest and normalize financial data, prepare books, route work for review, and support monthly accounting workflows
Authenticate and secure accessSign-in, session management, access control, fraud prevention, and tenant isolation
Operate and improve the PlatformMonitoring, debugging, product analytics, and service reliability
AI-assisted processingDocument extraction, categorization, matching, duplicate detection, and drafting structured questions, always subject to configured confidence thresholds and human review rules
Communicate with youService notices, support responses, onboarding, and operational messages
Legal and regulatory complianceUAE VAT and corporate tax record-keeping, audit trails, responding to lawful requests, and enforcing our terms
Marketing (where permitted)Sending information about Counted where you have opted in or where applicable law allows

We apply purpose limitation and data minimization: we do not use personal data for unrelated purposes without notice and, where required, consent.

6. Legal bases for processing (PDPL)

Depending on context, we rely on one or more of the following:

  • Performance of a contract with you or your organization.
  • Legitimate interests, such as securing the Platform, improving services, and preventing misuse, balanced against your rights.
  • Consent, especially for connecting third-party financial, email, or messaging sources and for optional marketing communications. Consent may be withdrawn at any time without affecting processing already performed.
  • Legal obligation, including tax and accounting record retention requirements.

Where we act as a processor for a client organization, that organization is responsible for establishing an appropriate legal basis for the data it instructs us to process.

7. Consent for connected sources

Counted is designed to access financial sources only with explicit, granular, and revocable authorization. Before we access bank data, accounting systems, email, storage, or messaging channels on your behalf, we will ask you (or your authorized representative) to connect those sources and accept the relevant scopes.

You may disconnect integrations where the provider and our Platform support it. Disconnecting may limit or prevent us from delivering the Services.

We maintain records of connection authorizations and material consent actions as part of our audit and compliance controls.

8. AI and automated decision-making

Counted uses automated systems, including AI models, to propose accounting treatments such as extraction, categorization, matching, and duplicate detection. Automated outputs are not final financial statements or tax filings. Uncertain or low-confidence items are routed for review by qualified accounting personnel before material actions are taken.

We do not use fully automated decision-making that produces legal or similarly significant effects without appropriate human oversight in our accounting workflow.

9. How we share personal data

We do not sell personal data. We may share personal data with:

  • Service providers and subprocessors that help us host, secure, monitor, and operate the Platform (for example cloud infrastructure, observability, email delivery, and support tools), subject to contractual confidentiality and data protection obligations.
  • Integration partners you or your organization authorize (for example Google, Microsoft, Zoho, QuickBooks, open-banking aggregators, and messaging providers), strictly as needed to perform the connection.
  • Professional advisers such as lawyers, auditors, and insurers, under confidentiality obligations.
  • Affiliates within our corporate group, for internal operations consistent with this policy.
  • Authorities or other parties when required by law, regulation, court order, or to protect rights, safety, and security.

A current list of material subprocessors is available on request at privacy@getcounted.ai.

10. International transfers

Your data may be processed in the UAE and in other countries where our service providers operate. Where personal data is transferred outside the UAE, we implement appropriate safeguards required by PDPL, such as standard contractual protections, adequacy mechanisms, or other lawful transfer tools.

11. Data security

We implement administrative, technical, and organizational measures designed to protect personal data, including:

  • encryption in transit and at rest for sensitive systems and credentials;
  • strict tenant isolation so client data, credentials, mappings, and learned patterns are not commingled across organizations unless intentionally configured as shared product settings;
  • encrypted storage of integration credentials in a token vault with refresh and re-authentication handling;
  • role-based access controls and least-privilege integration scopes where provider APIs allow;
  • logging and audit trails for material automated and human actions on financial data.

No method of transmission or storage is completely secure. You are responsible for safeguarding your account credentials and ensuring only authorized users access your organization.

12. Cookies and similar technologies

We use cookies and similar technologies on the Site and Platform to:

  • keep you signed in;
  • remember preferences;
  • measure Site performance; and
  • maintain security.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using parts of the Platform.

Where required by law, we will present a cookie notice and obtain consent for non-essential cookies.

13. Data retention

We retain personal data only as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by law.

In particular:

  • Accounting, tax, and financial records may be retained for at least five (5) years or longer where required for UAE VAT, corporate tax, or audit obligations.
  • Security and audit logs are retained for a period appropriate to investigation and compliance needs.
  • Marketing contact data is retained until you unsubscribe or we no longer need it.
  • Session data is retained for the life of the session and a limited period thereafter for security purposes.

When data is no longer needed, we delete or anonymize it in accordance with our retention schedule, subject to legal holds and backup cycles.

14. Your rights

Subject to PDPL and applicable exceptions, you may have the right to:

  • access personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request deletion or restriction of processing;
  • object to certain processing based on legitimate interests;
  • withdraw consent where processing is consent-based;
  • request data portability, where applicable; and
  • lodge a complaint with the UAE Data Office or other competent authority.

To exercise these rights, contact privacy@getcounted.ai. We may need to verify your identity and, where requests relate to an organization’s accounting records, confirm that you are authorized to act on that organization’s behalf.

We will respond within the timeframe required by applicable law.

15. Children

Counted is a business service and is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe we have collected a child’s data, contact us and we will take appropriate steps to delete it.

16. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on the Site with an updated “Last updated” date. Where changes are material, we will provide additional notice as required by law or contract.

17. Contact us

[Legal Entity Name]
[Registered address]
Email: privacy@getcounted.ai
Website: https://getcounted.ai