Privacy Policy

Last updated: 19 June 2026

Sumeria Solutions Ltd ("we", "us", "our") operates the Expense Claim System (the "Service"). This policy explains how we collect, use, store, and protect personal information when you use the Service.

1. Who we are

The data controller for the Service is Sumeria Solutions Ltd. For privacy enquiries, contact us at [email protected].

2. Information we collect

Depending on how you use the Service, we may process:

  • Account details — name, email address, authentication identifiers, and login activity.
  • Expense and company data — expense claims, line items, categories, descriptions, approval comments, company name, and role assignments within your organisation.
  • Financial details — bank account information you enter for reimbursement, where provided.
  • Receipts and attachments — images or files uploaded with expense claims.
  • Notification preferences — Telegram chat identifiers if you choose to link Telegram for approval alerts.
  • Subscription and billing data — where billing is enabled, payment-related identifiers processed by our payment provider (we do not store full card numbers).
  • Technical and usage data — session and authentication cookies, action logs (pages visited and actions taken), and similar diagnostic information needed to operate and secure the Service.

3. How we use your information

We use personal information to:

  • Provide, maintain, and improve the expense management Service.
  • Authenticate users and manage access within your company.
  • Process expense submissions, approvals, payments, and reconciliation workflows.
  • Send transactional emails such as account verification, password reset, invitations, and subscription notices.
  • Send optional notifications (for example via Telegram) where you have enabled them.
  • Monitor security, prevent misuse, and troubleshoot issues.
  • Meet legal, regulatory, and accounting obligations.

4. Legal bases for processing (UK GDPR)

We rely on one or more of the following, depending on the activity:

  • Contract — to provide the Service you or your organisation has signed up for.
  • Legitimate interests — to secure the Service, prevent fraud, and improve reliability, balanced against your rights.
  • Legal obligation — where we must retain or disclose information to comply with law.
  • Consent — where required, for example optional notification channels. You may withdraw consent at any time without affecting core Service use.

5. Who we share information with

We do not sell personal information. We may share data with:

  • Your organisation — company owners, approvers, payers, and other authorised users within your company, according to their role.
  • Service providers — hosting, email delivery, authentication (including Auth0 and social login providers where enabled), payment processing (Stripe, where enabled), and notification services (Telegram, where enabled). These providers process data on our instructions.
  • Authorities — where required by law or to protect rights, safety, and security.

Some providers may process data outside the UK. Where this occurs, we use appropriate safeguards such as UK adequacy regulations or standard contractual clauses.

6. Cookies and similar technologies

The Service uses essential cookies to:

  • Keep you signed in (Expense3Auth).
  • Maintain your session and selected company (Expense3Session and related session data).

These cookies are necessary for the Service to function. We do not use non-essential advertising or analytics cookies.

7. How long we keep information

We retain personal information for as long as your account and company data are active, and for a reasonable period afterwards to meet legal, tax, and audit requirements. Action and audit logs may be retained to support security investigations and compliance. You may request deletion subject to our legal obligations and your organisation's records needs.

8. Security

We apply appropriate technical and organisational measures to protect personal information, including access controls, encrypted connections in production, and hashed credentials. No online service can guarantee absolute security, but we work to protect data against unauthorised access, loss, or misuse.

9. Your rights

Under UK data protection law, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request erasure in certain circumstances.
  • Restrict or object to certain processing.
  • Request data portability where applicable.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

To exercise your rights, contact [email protected]. If your account is managed by an employer or organisation, some requests may need to be coordinated with your company administrator.

10. Children

The Service is intended for business use and is not directed at children under 16. We do not knowingly collect personal information from children.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected on this page with an updated "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact

Questions about this privacy policy or our use of personal information: [email protected].