seg-audit

Privacy Policy

Last updated: July 2026

1. The data we process

We connect to your ERP system (Odoo) through a read-only key that you grant. We read aggregated accounting data to produce the report (balances, journal entries, invoices), and we never write to or modify your system in any way. We also keep your email address to manage your account.

2. How we protect your keys

Your ERP key is stored encrypted in an isolated secrets vault and is never displayed again after you enter it. You can rotate or revoke it at any time.

We do not store your raw data rows — they are read from Odoo, aggregated in server memory, and discarded as soon as the report is generated. We keep no copy of them.

3. What we keep from your reports — and for how long

The resulting report is a different thing from the raw data: it contains aggregated figures about your organisation, and we keep it because the feature does not work otherwise — you request a report, come back to download it, and an MFT reviewer may sign it off days later.

Stated plainly: encrypted backups may hold a copy until their cycle expires, which is a requirement of disaster recovery. Nothing but the restore path can reach them.

4. Data sharing

We do not sell your data and do not share it for marketing purposes. We use a language-model provider (Anthropic) solely to write the explanatory narrative — your raw figures never reach it un-aggregated, and it is not used to train any model. A full access log records every read.

5. Your rights

You have the right to access your data, correct it, and delete your account. Deletion is self-service and immediate from the account page — no request and no waiting.

What is erased: your email, password and contact details; every connected Odoo database and its read keys from the vault; and every report we kept for you.

What remains, with no identity attached: payment and subscription records, the audit log, and the free-report counter. Keeping the first is an accounting and regulatory obligation that a request cannot waive, and the last prevents delete-and-re-register from becoming a route to endless free reports. Nothing in any of them points back to you.

We adhere to the principles of Egypt's Personal Data Protection Law (PDPL).

6. Contact

For any privacy enquiry: privacy@seg-audit.com.