1. Overview
AVENOR CAPITAL CLARITY - FZCO is the data processor for you as a business customer. That means you, as a business, are the data controller for the accounting data we process — and we process it following your instructions via a Data Processing Agreement (DPA).
2. Identity and contact
AVENOR CAPITAL CLARITY - FZCO
IFZA Business Park, Dubai Digital Park, Dubai Silicon Oasis, Dubai
United Arab Emirates
Email: contact@talvagt.com
We don't have a statutory DPO, but you can always contact our privacy team at the address above.
3. What we collect
Account information
- Company name, CVR, industry and company address.
- Your name, email, role and phone number.
- Login history and IP address (for security).
Integration data
- Your accounting system (currently e-conomic, Billy or Dinero): chart of accounts, vendors, customers, VAT codes and posted vouchers — read-only unless you approve a posting.
- Your email provider (e.g. Microsoft Outlook): incoming emails that look like invoices, plus their PDF attachments.
- Your bank connection (open banking): account movements and payment details used for automatic bank reconciliation — read-only.
Invoice data
- Invoice fields: vendor, amount, VAT, invoice number, date, due date.
- Line items from the invoice.
- Booking patterns (which account a given vendor → account mapping has been approved on previously).
4. Purpose and legal basis
We process your data to deliver the service itself — to read invoices, suggest entries and post them to your accounting system after your approval.
For the account data where we are the data controller (your name, email and login history), the legal basis is performance of our contract with you and our legitimate interest in operating and securing the service, per Article 6(1)(b) and (f) GDPR. For the accounting data where you are the controller, we process solely on your instruction under the Data Processing Agreement (Article 28); the underlying legal basis is determined by you as controller.
5. AI and personal data
TalVagt uses third-party AI systems to read invoices and suggest entries. To comply with GDPR, all personal data is removed from the payload before anything is sent to the AI system.
What gets removed before we ask the AI
- CPR numbers — replaced with
[CPR_REF_001]. - Personal names — replaced with
[PERSON_REF_001]. - Danish IBAN numbers — replaced with
[IBAN_REF_001]. - Email and phone numbers — replaced with equivalent reference tokens.
The reference tokens can only be translated back to the original values inside our own infrastructure. The AI system never sees them.
What is not removed
- CVR-registered company names (publicly available).
- Invoice numbers, amounts, dates and VAT codes.
- Account numbers from your accounting system's chart of accounts.
Invoice PDFs
Invoice PDFs follow the same principle: the content is used to extract structured data, and personal data is scrubbed before the result is used further. The technical detail of our AI pipeline and zero-data-retention routing is described on our security page.
6. Sub-processors
We use different sub-processors to deliver the service. All have signed data processing agreements and comply with GDPR.
- EU-hosted database and authentication — all data processing happens on servers in the EU.
- EU-hosted web application — runs and serves the app.
- EU-hosted background processing — runs scheduled and automated jobs.
- AI systems — only receive PII-scrubbed data, never personal information.
- Your email provider (EU) — only your own inbox (you authorise the access).
We list sub-processors at the category level here. An up-to-date, named list is provided as an annex to the Data Processing Agreement, and we notify you of changes.
Transfers to third countries
Data processing and AI inference take place with providers in the EU/EEA, and no personal data is sent to AI models (data is PII-scrubbed first). If a processing activity exceptionally involves a transfer to a third country outside the EU/EEA, it is done on a valid transfer basis — the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision.
7. Retention
- Invoice PDFs: retained for as long as your subscription is active + 5 years (Danish bookkeeping law).
- Booking patterns: retained as long as your subscription is active, or until you delete them manually.
- Audit log: 12 months after the action.
- Login history: 90 days.
When you cancel your subscription we delete all your data within 30 days, unless legislation requires longer retention.
8. Your rights
You have the right at any time to:
- Access what data we hold about you.
- Rectify incorrect information.
- Erasure (“the right to be forgotten”).
- Restrict processing.
- Data portability — export via API or email.
- Object to processing.
- File a complaint with the Danish Data Protection Agency.
Email contact@talvagt.com to exercise your rights. We respond without undue delay and at the latest within one month. In complex cases the deadline may be extended by up to two further months, in which case we notify you within the first month (Article 12(3) GDPR).
10. Contact
Questions about this policy? Email contact@talvagt.com.