1. Who we are
Vezna is a brand of Ninefold Ltd (Найнфолд ЕООД), a company registered in Bulgaria, VAT number BG204012589, registered address 6-ti Septemvri St. 4 (ул. „6-ти Септември“ 4), 1000 Sofia, Bulgaria (“Ninefold”, “we”, “us”).
This policy covers our public website vezna.ai, the Vezna app at app.vezna.ai (and its earlier address, talea.ninefold.ai), the Vezna connector that lets AI assistants such as ChatGPT and Claude work with the app, and the emails and support we provide.
Questions and requests about privacy: support@vezna.ai — please put “Privacy” in the subject.
2. Our two roles
For your company’s books, we are a processor
When a company (our client) uses Vezna, its books contain personal data — about its employees, owners, customers and suppliers, and about anyone else who appears in its bank transactions or documents. The client company is the controller of that data: it decides why the data is processed, mainly to keep its accounts and meet its tax obligations. We process it only on the client’s documented instructions, under our Data Processing Agreement.
If your personal data appears in a company’s books and you want to exercise your rights, please contact that company. We will help it respond.
For accounts, the website and our own business, we are a controller
We decide how and why we process data about people who sign in to Vezna, visitors to vezna.ai, people who contact us or book a call, and the records we keep to secure and run the service. Sections 4 and 5 describe this processing.
3. Data in your company’s books (we process it for the client)
Depending on what the client connects and uploads, Vezna processes:
- Bank and payment data — transactions from Fibank and Revolut Business (through their APIs), Stripe payments and payouts, or bank statements the client uploads: dates, amounts, currencies, counterparties, payment descriptions, account identifiers such as IBANs, and balances.
- Invoices, receipts and other accounting documents — PDFs and photos collected from the client’s Google Drive, from a Gmail mailbox the client connects with an app password, from uploads, or sent to us by email, with everything printed on them: names, addresses, VAT and company numbers, bank details, line items and amounts.
- The books we keep from them — categorised transactions, documents matched to payments, the general ledger (journal entries that Vezna proposes and the accountant approves), VAT ledgers, and drafts of VAT returns and SAF-T files.
- Conversations — the questions Vezna asks about missing documents and the answers given, chat messages with the in-app assistant “Ask Vezna”, and answers to the company-profile interview (for example ownership, payroll rhythm and recurring commitments).
- People who appear in the books — names, email addresses and other details of suppliers, customers, employees and contractors as they appear in documents and transactions, for example on payroll payments, or on expense reimbursements to employees who paid with a personal card. If a source document contains a personal identification number (ЕГН/ЛНЧ), it is part of that document.
- Mailbox data, only if the client connects a Gmail mailbox — Vezna searches it for invoice emails and downloads their PDF attachments; on request, the in-app assistant and connected assistants can search it, and see only the date, sender, recipients, subject and attachment names of matching emails. Vezna also sends its reminder and digest emails from that mailbox.
We don’t ask for special categories of personal data (such as health data). If a document contains any, it is processed only as part of the client’s records.
4. Data we collect as a controller
- Account data — your name and email address; a hash of your password (we never store the password itself), or the identifier of your Google account if you choose “Continue with Google”, in which case Google shares your name and email address with us; your role for each company (owner, team member or accountant); and invitations and password-reset requests, which we store only as hashes of their links.
- Sign-in and security records — when you sign in, your IP address, browser (user agent) and sign-in method; your active sessions; and an audit trail of account and administration events, such as invitations sent and roles changed.
- Connected-assistant records — when an assistant is connected: which assistant, who connected it, when it was connected and last used, and a log of every tool call it makes (who, which assistant, which tool, a short summary of the request, the outcome and the time). We store only hashes of access tokens.
- Website data — when you visit vezna.ai, our hosting provider processes the technical data needed to deliver the page: IP address, browser, requested page and time. The website has no analytics, advertising or tracking.
- Support and correspondence — emails and attachments you send us, and our replies.
- Discovery calls — if you book a call through our scheduling page (Cal.com), the details you enter, such as your name, email address and notes, and the meeting time.
5. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide Vezna to the client company: sign-in, the workspace, the books, Ask Vezna and connections | Account data; the client’s books | Performance of a contract (Art. 6(1)(b)) where you are the client yourself; otherwise our and the client’s legitimate interest in giving the client’s authorised people access (Art. 6(1)(f)). For the books themselves: the client’s instructions under the DPA. |
| Keep accounts and the service secure: prevent misuse, investigate incidents, keep audit trails | Sign-in and security records; connected-assistant records | Legitimate interest in security (Art. 6(1)(f)); our security obligations (Art. 32) |
| Send service emails: invitations, password resets and important notices | Name, email address | Contract (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)) |
| Answer support requests and manage the client relationship | Correspondence, contact details | Contract (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)) |
| Deliver the website | Website data | Legitimate interest (Art. 6(1)(f)) |
| Arrange discovery calls | Booking details | Steps taken at your request before a contract (Art. 6(1)(b)) |
| Meet our legal obligations: our own accounting and tax records, lawful requests from authorities | Billing records; data an authority lawfully requests | Legal obligation (Art. 6(1)(c)) |
| Establish, exercise or defend legal claims | Records relevant to the claim | Legitimate interest (Art. 6(1)(f)) |
Where we rely on legitimate interests, you can object — see Your rights. We don’t sell personal data, and we don’t use it for advertising.
6. How Vezna uses AI
Vezna uses AI models — Claude, provided by Anthropic — to:
- read invoices, receipts and bank statements and extract their details;
- suggest a category for transactions that the client’s rules don’t cover;
- understand answers to Vezna’s questions, for example what a payment was for;
- power Ask Vezna, the in-app assistant, and the company-profile interview.
For this, the relevant document, transaction details or messages are sent to Anthropic’s API. Under Anthropic’s commercial terms, data sent through its API is not used to train its models. We don’t train AI models on your data.
The figures in Ask Vezna’s answers are calculated by Vezna’s own code from the books; the AI model explains them and can still make mistakes. Automatic steps are bounded: Vezna books a transaction category on its own only when it is confident, records every automatic booking for review, and leaves everything else to the client or the accountant. Journal entries remain proposals until the accountant approves them, and VAT figures are estimates until the accountant files the return.
Vezna does not make decisions about individuals that have legal or similarly significant effects based solely on automated processing.
7. Connected assistants (ChatGPT, Claude)
An owner of a company in Vezna can connect their own AI assistant — for example ChatGPT by OpenAI or Claude by Anthropic — to that company’s books through the Vezna connector. Connecting requires signing in to Vezna, choosing the company and approving the connection on a screen that lists what the assistant will be able to do. How connecting works.
- What is shared. When you ask your assistant something, it calls Vezna’s tools and receives the results — for example P&L and cash figures, transactions matching a search, open items, ledger balances, or email search results (date, sender, recipients, subject and attachment names). Your assistant’s provider processes that data under your own agreement with it, such as OpenAI’s or Anthropic’s terms and privacy policy. For this processing, the provider is not our sub-processor.
- What Vezna receives. Only what your assistant sends to Vezna’s tools — for example a search term, a month, a document or an answer — never your conversation with the assistant.
- What is masked. Tool results never include personal identification numbers (ЕГН/ЛНЧ) or full payment-card numbers.
- What assistants can’t do. They can’t make payments, file returns, approve or change ledger entries, change users or settings, or delete data. They can submit documents, which Vezna files and matches, and answer Vezna’s open questions on the company’s behalf; both are recorded as coming from you through that assistant.
- Logs. Vezna logs every tool call — who, which assistant, which tool and when — and shows the log on the Connections page in Vezna.
- Your control. You can revoke a connection at any time on the Connections page, or disconnect Vezna in your assistant. Access tokens expire after one hour and are renewed automatically; a connection that isn’t used for 30 days stops working.
8. Who receives data
Our sub-processors
These providers process data on our behalf, under contracts that bind them to protect it. The full, current list, with locations and safeguards, is on our sub-processors page.
| Provider | What for |
|---|---|
| DigitalOcean | Servers and storage for the Vezna app and every company’s books (Frankfurt, Germany) |
| Cloudflare | DNS, encryption in transit and network protection — traffic to the app passes through Cloudflare |
| Anthropic | AI models that read documents, classify transactions and power Ask Vezna |
| Only if the client connects them: Google Drive and Gmail. Google sign-in, only if you choose it | |
| Resend | Account emails: invitations and password resets |
| Cloudflare (R2 storage, EU jurisdiction) | Encrypted off-site backups |
Other recipients
- People working on the client’s books — the client’s own users and the accountant responsible for its books see the client’s workspace according to their role.
- Services the client connects — banks and payment providers (Fibank, Revolut Business, Stripe) send us the client’s data at its request. Vezna uses these connections to read activity; it does not initiate payments.
- Assistants you connect — see Connected assistants.
- Website and app delivery — Vercel hosts vezna.ai (no client books are stored there). Pages on vezna.ai and in the app load fonts from Google Fonts, and some app pages load a charting library from the jsDelivr network; your browser fetches these files directly, so those providers see your IP address and browser details. Cal.com handles call bookings.
- Authorities and advisers — public authorities when the law requires it, for example the National Revenue Agency (НАП) on a lawful request; and our professional advisers, who are bound by confidentiality. Returns the accountant files for a client reach the authorities on the client’s behalf.
- A successor business — if Ninefold reorganises or sells its business, data may pass to the successor, which must keep protecting it as this policy and the DPA describe.
9. International transfers
We host the Vezna app and the companies’ books in the EU (DigitalOcean, Frankfurt, Germany). Some providers — Anthropic, Cloudflare and Resend, Google when the client connects it, and DigitalOcean as a US company — may process data outside the European Economic Area, including in the United States. Such transfers are protected by the European Commission’s Standard Contractual Clauses or by the EU–US Data Privacy Framework, as set out in each provider’s data processing terms. You can ask us for a copy of the relevant safeguards.
10. How long we keep data
| Data | How long |
|---|---|
| A client’s books and documents | For as long as the client uses Vezna. When the service ends, the books stay available for export for 90 days; then we delete them, unless the client asks for earlier deletion or the law requires us to keep something. |
| Backups | Encrypted backups rotate (14 daily and 8 weekly copies), so deleted data leaves the backups within about two months. |
| Account data | While your account exists. When your account is closed, we delete or anonymise it within 90 days, except records we must keep for security or legal reasons. |
| Sign-in sessions, with IP address and browser | Until the session ends: at most 30 days, or 7 days without activity. The record is then deleted. |
| Security and audit events | 12 months |
| Connected-assistant log | The latest 500 entries per company; older entries are overwritten. A connection’s record is deleted when it is revoked. |
| Invitations and password-reset links | Invitations expire after 7 days, password-reset links after 1 hour. |
| Support correspondence | 24 months after the last message |
| Discovery-call bookings | 12 months, unless we start working together |
| Website request logs | Kept by Vercel for a short period under its standard log retention. |
| Our own accounting records, such as invoices to clients | As long as Bulgarian accounting and tax law requires. |
Your company’s own obligations stay with your company. The Accountancy Act (Закон за счетоводството, Art. 12) requires companies to keep accounting records for set periods, counted from 1 January of the following year — for example 10 years for accounting registers and financial statements, 50 years for payroll records and 3 years for most other accounting documents — and documents needed for a tax audit may have to be kept longer. Export your books and documents before the service ends. Invoices filed to your own Google Drive stay there.
11. Security
- The app and the books are hosted in the EU. All traffic to the app is encrypted in transit (TLS) and passes through Cloudflare’s network protection; the app server accepts no direct connections from the internet.
- Each company’s books live in a separate, isolated workspace with its own process and storage.
- Access follows roles: owners and team members use the company workspace; accountants use the accounting workspace.
- Passwords are stored only as scrypt hashes. Sign-in attempts are rate-limited, and sessions expire.
- Session, invitation, password-reset and connector tokens are stored only as cryptographic hashes.
- Vezna uses bank and payment connections to read activity; it does not initiate payments.
- Automatic bookings, learned rules, ledger approvals and connected-assistant tool calls are logged.
- Data is backed up daily, encrypted, to separate storage.
If a personal data breach affects data we process, we will notify the client company without undue delay and, where we are the controller, the supervisory authority and affected people, as the GDPR requires.
12. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectification of inaccurate or incomplete data;
- erasure of your data, where there is no reason for us to keep it;
- restriction of processing, for example while we check a complaint;
- portability — receive data you gave us in a machine-readable format, or have it sent to another provider;
- object to processing based on our legitimate interests;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you.
To exercise a right, email support@vezna.ai. We may ask you to confirm your identity. We reply within one month; for complex requests, that can be extended by up to two more months, and we will tell you if so. For data in a company’s books, we pass your request to that company and help it respond.
You can also complain to a supervisory authority — in Bulgaria, the Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg — or to the authority where you live or work. We would appreciate the chance to resolve your concern first.
14. Children
Vezna is a service for businesses, meant for adults acting for a company. It is not directed at children, and we don’t knowingly collect children’s data for our own purposes. A client’s books may incidentally contain information about minors, for example on an invoice; we process it only as the client’s processor.
15. Changes to this policy
We will post changes on this page and update the effective date. If a change materially affects how we process client data or your rights, we will tell account owners by email before it takes effect.
16. Contact
Ninefold Ltd (Найнфолд ЕООД)
6-ti Septemvri St. 4 (ул. „6-ти Септември“ 4), 1000 Sofia, Bulgaria, Bulgaria
Email: support@vezna.ai
Related: Terms of Service · Data Processing Agreement · Sub-processors · Support