Legal
This policy explains what personal data we collect when you use fyled.io or the FYLED product, why we collect it, who processes it on our behalf, and the rights you have over it. We are a UK company and we keep things short and honest: we collect the minimum needed to run the service, we do not sell your data, and we do not run advertising trackers on this website.
Last updated: 26 September 2026
This policy explains how we handle personal data across the fyled.io website (including the waitlist, contact forms, and free tools) and the FYLED product. It is written for the UK GDPR and the Data Protection Act 2018. If you access FYLED from the EU or EEA, the EU GDPR applies to you on equivalent terms, and references to "UK GDPR" should be read as "EU GDPR" where relevant.
FYLED is the data controller for the personal data described in this policy. Where one of our business customers adds their own team members or accountant to their FYLED account, we process those people's data on the customer's behalf as a processor; the customer remains the controller of that data and this policy describes how we handle it as their service provider.
We have not appointed a data protection officer because we are not currently required to. Privacy questions are handled by the team at privacy@fyled.io.
| Purpose | Legal basis |
|---|---|
| Provide and operate the service you signed up for | Performance of a contract |
| Process payments and manage your subscription | Performance of a contract |
| Verify identity where the law requires it | Legal obligation |
| Respond to contact and waitlist requests | Legitimate interests (and consent where you opted in) |
| Secure the service, prevent fraud, maintain backups | Legitimate interests |
| Improve the product from usage data | Legitimate interests |
| Send you service messages (receipts, alerts, notifications) | Performance of a contract |
We do not use your data for automated decision-making with legal or similarly significant effects. AI-assisted features (such as transaction categorisation suggestions) produce suggestions that a human reviews; they never act alone on your finances.
FYLED uses AI features to help categorise transactions, draft document chases, and summarise financial information. Your financial data may be processed by our AI providers to produce these features (see section 7). We do not use your personal data or financial data to train general-purpose AI models, and we do not sell it for AI development.
This website uses only essential cookies needed to make forms and sessions work. The product uses session cookies to keep you signed in. We do not set advertising or cross-site tracking cookies. Because we do not use non-essential cookies on this website, no cookie consent banner is required under PECR; if we ever add non-essential cookies, we will ask for consent first and update this policy.
We use a small number of trusted companies to operate FYLED. Each is contractually bound to protect your data and processes it only on our instructions.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Stytch | Authentication and session management | Email address, auth identifiers |
| Stripe | Payment processing and billing | Name, email, payment method data |
| Resend | Transactional email delivery | Email address, message content |
| FormSubmit | Contact form delivery on fyled.io | Name, email, message you submit |
| Didit | Identity verification (KYC/AML, where required) | ID document images, selfie/liveness image, phone number |
| Salt Edge | Open banking aggregation | Bank account and transaction data you connect |
| Unified.to | Unified integrations platform (accounting and business software connections) | Connection credentials and the accounting/financial data synced from the services you connect |
| Sanity | Content management for this website | Website content only; no customer personal data |
| Synadia | Managed message infrastructure | Encrypted event payloads only. Every event is encrypted before transmission, so no readable personal data is exposed |
| Tencent Cloud | AI document extraction and insights | Uploaded documents (receipts, invoices) and the financial data sent for AI features [CONFIRM EXACT SCOPE] |
Infrastructure we run ourselves (databases, caches, feature flags, PDF generation) is not a sub-processor relationship; it operates under our direct control on our hosting.
If we add or change sub-processors, we will update this table and give advance notice to product customers where the change affects their data.
Our primary hosting is in [HOSTING REGION]. Some sub-processors operate outside the UK, including in the United States. Where personal data leaves the UK, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and on transfer risk assessments. For transfers out of the EEA, the EU Standard Contractual Clauses apply. You can request a copy of the transfer safeguards we rely on by writing to privacy@fyled.io.
Financial records deserve more than the standard promise, so security is built into how FYLED works: data is encrypted at rest and in transit, access to customer data is restricted by role, events between systems are encrypted end to end, and our secrets and keys are held in a dedicated secrets manager. No system is perfect, but we design so that a single failure does not expose your records. If a breach ever affects your personal data, we will notify you and the ICO as the law requires.
Under the UK GDPR you have the right to:
To exercise any right, email privacy@fyled.io. We will respond within one month. We may need to verify your identity first. These rights are free to exercise; we only charge for manifestly unfounded or excessive requests.
We only email you about your account and service. The waitlist sends one email when your spot opens. If we ever send product news, every email will include an unsubscribe link, and you can opt out at any time without losing access to the service.
FYLED is a business accounting service and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact privacy@fyled.io and we will delete it.
Our website and product link to third-party sites and connect to services you choose (banks, accounting software, payment providers). Once you leave our website or connect a third-party service, that provider's own privacy policy applies to how they handle your data. We are not responsible for their practices.
If you are unhappy with how we handle your data, you can complain to the UK supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
ico.org.uk, helpline 0303 123 1113
We would appreciate the chance to address your concern first, so please contact privacy@fyled.io before escalating.
We will update this policy when our practices or the law change. The "Last updated" date at the top always reflects the current version. Material changes will be announced to product customers by email or in-product notice before they take effect.