Skip to main content

Privacy policy

Last updated 3 September 2026

This policy explains what IFRS 18 Navigator collects, why it is collected, who else handles it, how long it is kept and how to have it removed. Financial statements you upload are treated as confidential throughout, and are described separately below because they are the most sensitive thing the product holds.

Who we are

IFRS 18 Navigator is operated from Dubai, United Arab Emirates, and the operator is the data controller for the personal data described here. Questions about this policy, and any request to exercise the rights set out below, go to support@ifrs18navigator.com.

What this policy covers

It covers the public website at ifrs18navigator.com, the free tools and the readiness questionnaire, the product behind sign-in, the embeddable answer widget, and the emails we send. It does not cover sites we link to, which have policies of their own.

What you give us directly

Depending on which parts of the product you use, we hold:

  • Account details. Your name and email address, and the identifier of the account you signed in with.
  • Questions and answers. The questions you ask, the answers returned, the sources cited, and the conversation they belong to.
  • Files you upload. Statements of profit or loss as PDF, spreadsheet, CSV or image, and the figures and line-item labels read out of them.
  • Billing details. The customer and subscription identifiers Stripe gives us, and which plan you are on. We never see or store your card number.
  • Enquiries and the waitlist. Your email address, and where you offer them a name, organisation, role and a note. A telephone number is stored only if you tick the box agreeing to be called, and we store the wording you agreed to and the moment you agreed to it.
  • Tool results you ask us to send. An email address, given so that a readiness score or a mapping can be sent to you.

What Google gives us when you sign in with Google

If you choose Google to sign in, Google passes us your name, your email address and the identifier of your Google account. That is the whole of it: we request no other scope, so we cannot read your Gmail, your Drive, your calendar or your contacts. We use those three items only to create your account, to recognise you when you return, and to send you service email about your own account. Furthermore, data received from Google is never used for advertising, is never sold, is never transferred to anyone except the processors listed below acting on our instructions, and is not used to train any model. You can withdraw our access at any time from your Google account's third-party access settings, and you can delete the account outright from your settings here.

What we collect automatically

Our hosting keeps short-lived server logs containing the request, the time and an IP address, which is how a fault is diagnosed and abuse is stopped. Cookies strictly needed to keep you signed in, to remember your language and to remember your appearance choice are always set. Product analytics and session replay are not, and load only after you accept measurement.

Why we use it, and the lawful basis

Each purpose rests on one basis, not on a general permission:

  • To answer your questions, hold your history and read your statements, because that is the contract you have with us.
  • To bill you and keep records of what was charged, because that is the contract, and afterwards because the law requires records to be kept.
  • To enforce the free monthly cap and to keep the service available to everyone, on our legitimate interest in a product that works.
  • To send service email about your own account, such as a sign-in link or a receipt, because that is the contract.
  • To measure how the product is used, and to record the cost of each answer, on your consent for measurement and our legitimate interest in knowing what to fix.
  • To follow up an enquiry by email, on our legitimate interest in responding to somebody who asked us to. To telephone you, only on your consent.

Financial statements you upload

Uploaded statements are encrypted in transit and at rest, and are readable only by your own account. That restriction is enforced in the database and in the file store rather than in the interface, so a fault in a screen cannot expose another organisation's figures. Your questions and your uploaded figures are masked in our analytics and session-replay tools, so they are never captured there. They are not used to train any model, they are not shared with other customers, and they are not used for any purpose except producing the analysis you asked for.

What is sent to a model provider

Answering a question means sending the question, the passages retrieved from our own source library, and, where you have uploaded a statement, the figures and labels read out of it, to the model provider that produces the answer. Those providers are Anthropic, Google and OpenAI. Under the terms on which we use their interfaces, content sent this way is processed only to return the answer and is not used to train their models. We do not send them your name, your email address or your billing details. If we change provider, this list changes with it.

Who else processes your data

We use a small number of processors, each on written terms, each acting only on our instructions:

  • Supabase, for authentication, the database and file storage.
  • Vercel, for hosting and content delivery.
  • Anthropic, Google and OpenAI, as model providers, as described above.
  • Stripe, for payments and subscription management.
  • Resend, for sending email.
  • PostHog, for product analytics and session replay, loaded only after you accept measurement.
  • Google Analytics, for traffic measurement, loaded only after you accept measurement.

Where your data goes

The operator is in the United Arab Emirates, and the processors above run in the United States and the European Union, so personal data is transferred outside the United Kingdom and the European Economic Area. Those transfers rest on the standard contractual clauses in each processor's data-processing terms. A copy of the safeguards relied on for any particular processor is available on request to support@ifrs18navigator.com.

How long we keep it

Nothing is kept indefinitely simply because it was once collected:

  • Uploaded files are deleted 30 days after upload, automatically and on a schedule, from the file store as well as the database.
  • Conversations, questions and answers are kept until you delete them, and deleting one removes any file attached to it.
  • Your account is kept until you delete it. Deleting it removes your profile, your conversations and your files.
  • Billing records are kept for as long as tax and company law requires them, which is longer than the account itself.
  • Enquiry and waitlist details are kept until you ask us to remove them, or until you withdraw consent where consent is what we relied on.
  • Server logs are short-lived and are kept only as long as they are useful for diagnosing a fault.

How it is protected

Data is encrypted in transit and at rest. Access to your rows and your files is restricted to your own account by row-level security, which is applied by the database rather than trusted to the application. Administrative access is limited to the people who need it, keys with elevated permissions are held only on the server and never in a browser, and sensitive fields are masked before they reach any measurement tool. No system is perfect, and if a breach affects your personal data we will tell you and the relevant authority as the law requires.

Your rights

You may ask us for a copy of your personal data, to correct it, to delete it, to restrict how we use it, to object to processing that rests on our legitimate interests, and to receive it in a portable form. Where we rely on your consent, you may withdraw it at any time without giving a reason, and withdrawing it does not affect what was done before. Most of this is self-service in your settings, including export and account deletion. For anything else, write to support@ifrs18navigator.com and we will respond within thirty days.

Cookies and measurement

Cookies needed to keep you signed in, to remember your language and to remember whether you chose a light or dark appearance are set without asking, because the product cannot work without them. Product analytics and session replay are set only after you accept measurement in the banner, and you can withdraw that at any time in your settings, after which they stop loading.

Automated processing

The product produces answers and reclassifications by machine, and they are a reference aid rather than a decision. Nothing here makes an automated decision that has a legal effect on you or your organisation, and no accounting position is filed, submitted or reported on your behalf. Every screen that shows an answer says so: the position still needs sign-off from a technical accounting lead or an auditor.

Children

This is a professional tool for people preparing financial statements. It is not directed at children, and we do not knowingly collect personal data from anyone under eighteen. If you believe a child has given us data, write to support@ifrs18navigator.com and we will remove it.

Changes to this policy

When this policy changes, the date at the top changes with it. Where a change materially affects how we use data you have already given us, we will tell account holders by email rather than relying on you to notice.

Complaints

If you are unhappy with how we have handled your personal data, write to support@ifrs18navigator.com first, because most of it is quicker to fix directly. You also have the right to complain to the data protection authority in the country where you live or work. In the United Kingdom that is the Information Commissioner's Office.