Privacy Policy

Last updated: November 2024

Introduction

Harold ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our document processing service.

We are registered in the United Kingdom and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Information We Collect

Account Information

When you register for Harold, we collect your name, email address, company name, and billing information. This information is necessary to provide you with our services and communicate with you about your account.

Document Data

We process the documents you upload or send to Harold. This may include invoices, purchase orders, delivery notes, receipts, and other business documents containing supplier information, financial data, and transaction details.

Usage Information

We automatically collect information about how you interact with Harold, including pages viewed, features used, documents processed, and technical data such as IP address, browser type, and device information.

How We Use Your Information

We use your information to:

  • Provide, maintain, and improve our document processing services
  • Process and extract data from your documents using AI technology
  • Train and improve our AI models (only on your data, kept separate from other customers)
  • Communicate with you about your account, updates, and support requests
  • Process payments and prevent fraud
  • Comply with legal obligations and protect our rights
  • Analyse usage patterns to enhance our service

Data Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, secure cloud infrastructure, regular security audits, and access controls limiting who can view your data.

Your documents and extracted data are stored securely on servers located in the UK and EU. We use industry-standard encryption and security practices to protect your information.

Data Sharing and Disclosure

We do not sell your personal data. We may share your information with:

  • Service Providers: Third-party companies that help us provide our services (cloud hosting, payment processing, email delivery)
  • AI Processing: We use OpenAI and Anthropic APIs to process document content. These providers process data according to their own privacy policies and data processing agreements
  • Legal Requirements: When required by law, regulation, legal process, or governmental request
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

Your Rights Under UK GDPR

You have the right to:

  • Access: Request copies of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data
  • Restriction: Request restriction of processing
  • Portability: Receive your data in a structured, machine-readable format
  • Object: Object to processing of your data
  • Withdraw Consent: Withdraw consent at any time

To exercise these rights, contact us at hello@useharold.com

Data Retention

We retain your documents and extracted data for as long as your account is active or as needed to provide you services. If you close your account, we will delete your data within 90 days unless we are required to retain it for legal or regulatory reasons.

Cookies and Tracking

We use essential cookies to operate our service and analytical cookies to understand how you use Harold. You can control cookies through your browser settings.

International Transfers

Your data is primarily stored within the UK and EU. If we transfer data outside these regions, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice in the service.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: hello@useharold.com
Address: [Your UK Business Address]

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.