GDPR

Last updated: 9 September 2026

Summarly holds your bookkeeping — bank transactions, receipts, invoices, and if you run payroll, your employees’ payslips. That is about as sensitive as business records get, and most of it is personal data belonging to people who are not you. This page says plainly who else can touch it, what protects it, and how you get it back or destroy it.

The full detail is in our Privacy Policy. This is the short version for the questions people actually ask.

Your rights are buttons, not a support ticket

Most services answer a GDPR request by asking you to email them and promising a response within thirty days. Two of the rights that matter most are self-service here, and you do not have to ask us:

  • Access and portability (Articles 15 and 20) — download a full copy of your workspace from Settings → Privacy & data, whenever you like, as many times as you like.
  • Erasure (Article 17)— delete your workspace and account from the same page. It removes the transactions, the receipts, the assistant history and the other members’ access to it. It is not a flag on a row; the records go.

Rectification, restriction and objection (Articles 16, 18 and 21) are not buttons, because they need a conversation. Email founders@summarly.com and a person will answer. You can also complain to the Cyprus Office of the Commissioner for Personal Data Protection, and you do not need to go through us first.

Who is responsible for what

This matters more than it sounds, particularly if you are an accountant putting client records into a workspace.

DataControllerOur role
Your workspace contents — transactions, receipts, invoices, employees, payslipsYouProcessor. We hold and process it to run the service for you, on your instructions.
Your account — sign-in, name, email, billing recordSummarlyController. We decide what we need in order to give you an account.

So the people named inside your books — your customers, your suppliers, your employees — are your data subjects, not ours. If one of them exercises a right against you, the export and deletion tools above are how you act on it.

Who else touches it

A short list, on purpose. Each provider processes data only on our instructions, and this is the same list the Privacy Policy carries — it is rendered from one source, so the two pages cannot come to disagree.

ProviderPurpose
SupabaseDatabase, file storage, authentication.
Anthropic (Claude)AI categorization, receipt extraction, and the assistant. Inputs are not used to train models — see our AI Terms.
VercelApplication hosting.
MXrouteSign-in and notification emails we send you.
ResendReceipts and invoices you forward to your workspace email address, and the waiting list.
CloudflareBot protection on sign-up and the waiting list, which sees the IP address of the device making the request.

Some of these providers are established outside the EEA. Where personal data is transferred to them, the transfer is protected by appropriate safeguards such as the EU Standard Contractual Clauses.

Anthropic is the one worth knowing about in detail, because the AI features are the only place your books are read by anything other than Summarly itself. What reaches a model and what does not is set out feature by feature in our AI Terms, and your financial data and assistant conversations are never used to train one.

Payments are separate. Polar acts as merchant of record — they are the seller for your subscription and a data controller in their own right, not a provider acting for us. We never see or store your card details.

We do not sell data, and we run no third-party advertising or analytics trackers.

How it is kept safe

  • Workspaces are isolated in the database itself, not by a filter in application code. One customer cannot read another’s rows even if the application asks for them.
  • Encrypted in transit and at rest. Receipts and payslips live in private storage and are only ever reachable through short-lived signed links, so a copied URL stops working.
  • Payslip share links expire.A payslip is somebody else’s personal data and a permanent URL to one is a liability, so those links are time-limited by design.
  • Staff access is limited to what is needed to operate and support the service.
  • Roles inside a workspace are enforced server-side. An invited accountant is a viewer: they can read the books and raise questions, and they cannot alter your ledger.

If something goes wrong

If personal data in your workspace is breached, we will tell you without undue delay, with what we know: what happened, what data was involved, and what we are doing about it. Because you are the controller of your workspace contents, you may then have your own duty to notify your supervisory authority within 72 hours, and we will give you what you need to do that.

Data processing agreement

Our Data Processing Agreement covers the Article 28 terms and applies automatically as part of the Terms of Service — there is nothing to sign. If your own compliance needs a signed counterpart, email founders@summarly.com and we will execute one.

Questions we get asked

Does the AI read my books? Some features send specific data to a model — categorising a transaction, reading a receipt, answering a question you asked the assistant. Our AI Terms set out feature by feature what is sent and what comes back. Nothing you send is used to train a model.

Where exactly is my data stored? With the providers listed above, under our contracts with them. If you need the specific regions for your own compliance file, email us and we will confirm them in writing.

Can I get everything out? Yes, from Settings → Privacy & data, without asking us and without notice.

What happens if I stop paying? Losing a subscription does not delete your data. Deletion is something you do deliberately.

What happens when I delete my workspace? Its records and uploaded files are permanently removed. We keep only the limited information we are legally required to keep, such as billing records.

I am an accountant. Can I use this for client data? Yes, and you would be the controller for it while we act as your processor. Email us about a data processing agreement before you bring client records across.

Anything not answered here? Email founders@summarly.com — a founder reads it.