Privacy Policy

Last updated: 19 June 2026

1. Controller details

Self Software Systems SIA, registration number 40203713044, VAT number LV40203713044, Anniņmuižas bulvāris 19–38, Rīga, LV-1067, Latvia ("SelfSIA", "we", "us") is the controller of personal data processed through the SelfSIA website, applications and related services.

Privacy contact: [email protected]

General support contact: [email protected]

2. Scope

This Privacy Policy explains how we collect, use, disclose, transfer, store and otherwise process personal data when you:

  • (a) visit our website;
  • (b) create or use a SelfSIA account;
  • (c) join our waiting list or contact us;
  • (d) connect third-party integrations;
  • (e) use AI-assisted bookkeeping, analytics, reporting or communication features; or
  • (f) otherwise interact with us as a customer, prospect or user.
3. Categories of personal data

Depending on how you use SelfSIA, we may process the following categories of personal data:

3.1 Identity and account data

Name, email address, telephone number, company name, account credentials, profile settings, authentication identifiers, and account status.

3.2 Billing and contract data

Subscription plan, invoices, payment status, transaction references, VAT/company details, billing address and related accounting records.

3.3 Financial and bookkeeping data

Transaction data, bank statement data, invoices, receipts, tax-related records, accounting classifications, files and documents you upload, and metadata associated with those records.

3.4 Integration data

Data received from integrations you authorise, including banks, payment providers, cloud storage services, messaging platforms, identity providers and similar third-party services.

3.5 Usage and device data

IP address, browser type, operating system, device identifiers, log data, pages viewed, actions taken, feature usage, timestamps, session information and similar technical data.

3.6 Communications data

Messages sent to us, support tickets, waitlist submissions, feedback, survey responses, and communications conducted through supported channels.

3.7 AI interaction data

Prompts, uploaded context, generated outputs, classifications, recommendations, explanations and related interaction logs necessary to provide AI-assisted features.

3.8 Compliance and security data

Audit logs, fraud-prevention indicators, access events, error reports, and records necessary to investigate incidents, enforce our terms, or comply with law.

4. Sources of personal data

We collect personal data:

  • (a) directly from you;
  • (b) from your employer or organisation where your use is provisioned by that organisation;
  • (c) from third-party services that you choose to connect or use for sign-in;
  • (d) from service providers acting on our behalf; and
  • (e) from public authorities or other parties where required by law or necessary for legal compliance.
5. Purposes of processing and lawful bases

We process personal data for the following purposes:

5.1 To create and administer your account, authenticate users, provide access to the service, and perform our contract with you.
Lawful basis: performance of a contract; steps prior to entering into a contract.

5.2 To provide bookkeeping, analytics, categorisation, reporting, document handling, integration and communication features you request.
Lawful basis: performance of a contract.

5.3 To operate billing, invoicing, payment collection, accounting and tax compliance processes.
Lawful basis: performance of a contract; compliance with legal obligations.

5.4 To maintain security, prevent fraud or abuse, protect our systems, investigate incidents and enforce our Terms.
Lawful basis: legitimate interests; compliance with legal obligations where applicable.

5.5 To analyse service usage, improve user experience, diagnose issues and develop features.
Lawful basis: consent where cookies or similar technologies require consent; otherwise legitimate interests where permitted by law.

5.6 To communicate with you about the service, support matters, operational notices and updates.
Lawful basis: performance of a contract; legitimate interests.

5.7 To send marketing communications.
Lawful basis: consent where required by law; otherwise our legitimate interests where permitted by law and subject to your right to object.

5.8 To comply with applicable law, respond to lawful requests, assert or defend legal claims, and exercise our legal rights.
Lawful basis: compliance with legal obligations; legitimate interests.

Where we rely on legitimate interests, we assess and balance those interests against your rights and freedoms.

6. Whether provision of data is mandatory

Some data is necessary to provide the service, create an account, process payments, connect integrations, or comply with legal requirements. If you do not provide data marked as required, we may be unable to provide some or all of the service.

7. Cookies and similar technologies

We use cookies and similar technologies on our website and service. Please see our Cookie Policy for detailed information about categories of cookies, legal bases, durations, recipients and how to manage your preferences.

8. Recipients of personal data

We may disclose personal data to:

  • (a) hosting, infrastructure and cloud providers;
  • (b) analytics and consent-management providers;
  • (c) payment processors and billing providers;
  • (d) authentication and identity providers;
  • (e) integration providers you authorise, such as banking, storage, messaging and payment services;
  • (f) customer support and communications tool providers;
  • (g) professional advisers, auditors and insurers;
  • (h) competent authorities, courts, regulators or law enforcement where required by law; and
  • (i) a purchaser or successor in connection with a merger, acquisition, restructuring or sale of assets.
9. International data transfers

Where personal data is transferred outside the EEA/UK/Switzerland, we will ensure that a valid transfer mechanism applies, such as:

  • (a) an adequacy decision;
  • (b) the European Commission's Standard Contractual Clauses; or
  • (c) another legally recognised transfer mechanism.

Where required, we implement supplementary technical and organisational measures.

10. Retention

We retain personal data only for as long as necessary for the relevant purpose, unless a longer retention period is required or permitted by law. As a general rule:

  • (a) account and profile data: for the duration of the account relationship and up to 90 days after closure, unless longer retention is required;
  • (b) billing, invoicing and tax/accounting records: for the retention period required by applicable law;
  • (c) support and contact records: up to 24 months after closure of the request;
  • (d) security logs and audit logs: up to 12 months unless a longer period is needed for investigation, security or legal claims;
  • (e) waitlist and lead data: up to 12 months unless you become a customer or withdraw earlier;
  • (f) cookie consent records: for the period necessary to demonstrate compliance and manage your preferences;
  • (g) backups: retained on a rolling basis for up to 90 days unless restoration or legal hold requires otherwise.
11. Your rights

Subject to applicable law, you may have the right to:

  • (a) obtain access to your personal data;
  • (b) request rectification of inaccurate data;
  • (c) request erasure;
  • (d) request restriction of processing;
  • (e) object to processing;
  • (f) receive personal data in a portable format where applicable;
  • (g) withdraw consent at any time where processing is based on consent; and
  • (h) lodge a complaint with a supervisory authority.

To exercise your rights, contact us at [email protected]. We may request information necessary to verify your identity. We will respond without undue delay and ordinarily within one month of receipt of the request; this period may be extended where legally permitted.

12. Automated decision-making and profiling

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, unless we expressly notify you of that processing, identify the lawful basis, and provide the information and safeguards required by applicable law.

13. Children

SelfSIA is not directed to children. The service is intended for users who are at least 18 years old unless we expressly provide otherwise. If we become aware that we have collected personal data from a child in violation of applicable law, we will take appropriate steps to delete that data. Where consent-based information society services are offered directly to children, we will apply the age and parental-authorisation rules required by applicable law.

14. Security

We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures may include encryption, access controls, role-based permissions, logging, backup procedures, testing and vendor management. No security measure is absolute.

15. Data breaches

Where required by law, we will document personal data breaches, notify competent supervisory authorities, and communicate with affected individuals.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will publish the updated version on this page and change the "Last updated" date. Where required by law, we will also provide additional notice.

17. Contact

For privacy-related questions, requests or complaints, contact:

Self Software Systems SIA

Anniņmuižas bulvāris 19–38, Rīga, LV-1067

Latvia

Email: [email protected]