Skip to main content

Privacy-by-Design

We do not train AI on your books.

Bookkeepers carry legal liability for what's in your ledger. Sending the entire ledger to an LLM is a non-starter. Here's exactly what crosses the wire and what does not.

AI transparency (EU AI Act, Art. 50)

The chat assistant and document extraction are AI features. Their output is informational only and can be inaccurate — a human always reviews and confirms every figure before it is filed with EMTA or the Business Register. We label AI features clearly, log every AI call, and never make an automated decision about you. SelgeSaldo is a limited-risk system: it does no biometric, hiring, credit-scoring or law-enforcement processing.

Stays in Estonia

  • Full ledger (companies, transactions, declarations)
  • Bank statements & invoices (encrypted at rest)
  • Payroll & employee personal codes (PII encrypted with AES-GCM)
  • Audit log of every change

Goes to AI (only on demand)

  • OCR text from one PDF you uploaded — when you click ✨ Extract
  • Chat question + KMS / EMTA snippets + a short profile of your active company (VAT status, declaration and document statuses, this month's invoices, bank balance as one figure, your plan and AI-points balance) — when you ask the AI assistant. Never per-employee salaries, personal ID codes or raw transaction lists.
  • A receipt photo you attach in chat — the image itself goes to the vision model
  • Period totals (rate buckets) — when you run AI sanity-check on a KMD draft
  • All other data is never sent. Categorisation runs on Free is rule-based, not AI.

Never happens

  • AI training on your data
  • Storage at the AI provider beyond transient API logs (purged within 30 days)
  • Sharing with third parties
  • Sending your full ledger anywhere outside our DB

Where exactly does the AI run?

AI features go through OpenAI's API (gpt-5-nano for chat, gpt-5.4-mini for document parsing and KMD sanity-check). OpenAI's enterprise terms (which we operate under) explicitly state: input and output data is not used to train OpenAI's models. We additionally redact direct identifiers at our boundary — isikukood, IBAN and card numbers are stripped before the request leaves our server. Free text and attached images are sent as you provide them, so avoid including personal data you don't want processed.

Why this matters: the Xero precedent

In March 2026, Xero — the largest accounting platform globally — explicitly banned the use of their API data for training any AI/ML models. They cited 'protection of commercial confidentiality and user trust'. We agree. Our terms include the same prohibition.

Audit trail

Every AI call is logged in our database with: which user, which company, which feature, how many tokens, how much it cost, and which prompt version. You (and your accountant) can review the full history. Each AI suggestion is just that — a suggestion. The number that ends up in the EMTA submission is always under human control.

What about GDPR / Estonian data law?

Our default position: data lives at rest on EU-hosted infrastructure (Postgres in Frankfurt or Tallinn). Only the minimum data for each feature leaves our server, as a single API request to OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.) under a data processing agreement with EU standard safeguards. See our DPA for the full processor list.

Have a question we didn't cover? Reply to any signup email — a human reads it.

See pricing →