Privacy Notice

Effective 1 September 2026 · Draft pending legal review

Are you a worker using the Saral portal or mobile app? The notice covering worker data (attendance, right-to-work, payroll) is the worker privacy notice. This page is for the businesses that subscribe to Saral.

1. Who we are, and the roles we play

Saral is operated by Deshwal & Co (“we”, “us”), registered in England. For the data your business puts into Saral — including everything synced from your Xero organisations — you are the controller and we are your processor: we process it only to provide the service, on your instructions, under our terms of service. For your account itself (who subscribed, billing records, support correspondence) we are the controller. Contact: accounts@getsaral.co.uk.

2. What we process

  • Accounting data from Xero — invoices, credit notes, payments, bank transactions, manual journals, contacts, chart of accounts, tracking categories, fixed assets, attachments, and financial reports for each organisation you connect. What we read is limited by the OAuth scopes you approve (listed in Support & docs).
  • OAuth tokens — the access and refresh tokens Xero issues are stored encrypted at rest (AES-256-GCM) with keys held outside the database, and are never written to logs.
  • Your users — names, work emails, roles, sign-in records, and optional two-step verification enrolment.
  • Workforce data — where you use the HR modules; the worker notice describes it in full.
  • Documents you send us — supplier invoices and similar documents emailed or uploaded for processing (BillScan).
  • Billing — your subscription, invoices, and Direct Debit mandate references. Your bank details are entered on GoCardless’s pages and never seen or stored by Saral.

3. Why, and on what basis

To provide the service you subscribed to (contract); to bill you and keep required records (contract, legal obligation); to secure the platform — authentication, rate limiting, audit trails (legitimate interest); and to extract data from documents you submit, which uses an AI subprocessor (Anthropic) under an agreement that prohibits training on your data (performance of contract). We never sell data, and we never use your business data to train AI models.

4. Where it lives, and who touches it

Primary hosting and database are in the EU (Supabase/AWS eu-west-1, Ireland), with the application served by Vercel. The full, current list of subprocessors — what each does and where it processes — is public at /subprocessors. Where a subprocessor processes outside the UK/EEA, transfers rest on adequacy decisions or standard contractual clauses. Access to customer data within Saral is limited to the operator role, is reason-gated, and is audit-logged; tenant isolation is enforced so no customer can ever read another’s data.

5. Retention and deletion

  • While you subscribe, your data is retained as the working system of record you maintain.
  • After your subscription ends: 30 days read-only export access, a further 60 days offline retention, then permanent deletion at 90 days, with reminders before it happens.
  • Disconnecting a Xero organisation revokes Saral’s access at Xero and clears our stored tokens; if Xero-side revocation cannot complete we retry and reconcile until it does.
  • Billing records are kept as long as tax law requires.

6. Your rights, and your data subjects’ rights

For account data we control, you can ask us for access, correction, deletion, or portability, and complain to the ICO. For business data you control, we act on your instructions — the application itself is your tool for access and correction, and export is available throughout the retention window. Where a person whose data you process contacts us directly, we will refer them to you and assist you in responding.

7. Security

TLS everywhere; OAuth tokens encrypted at rest with rotatable keys; row-level security plus application-level tenant scoping; two-step verification available to all users and enforceable organisation-wide; signed single-use links for account actions; webhooks authenticated by signature; platform-operator actions step-up authenticated and audit-logged. If a breach affects your data we will notify you without undue delay at your registered contact email.

8. Data processing agreement

Our terms of service incorporate our processor commitments. If your organisation requires a standalone signed DPA, email accounts@getsaral.co.uk and we will provide one.

9. Changes and contact

Material changes to this notice are announced by email at least 30 days before they take effect. Questions, requests, or incident reports: accounts@getsaral.co.uk.