Privacy notice
Credit Control Desk chases business invoices for the companies that use it. What we hold is mostly commercial: the invoices in a receivables ledger. Personal data is the name and work e-mail of the people who use an account, and — where a client's customer is a sole trader or a partnership — that customer's name. This notice describes what the software does today.
Who is responsible
Data controller for this service: Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions about your data: privacy@vitersoft.com. For the ledger a client uploads about its own customers, that client is the controller and we process it on its instructions.
What is stored
- The company's name, website, turnover range and accounting system, as typed on the form.
- The name and work e-mail address of each person on the account.
- The files uploaded, in private storage, and the invoices read from them: number, customer name, dates and amounts.
- Our decision on each invoice, why, and what came of chasing it.
- The name and title of the person who accepted the engagement, and when.
Invoices paid on time are not stored: they are dropped in your browser before anything is saved. We do not store IP addresses, and we never ask for a login to your accounting system.
How long
For as long as the account exists. The owner can delete the account from the settings page: that removes the files, every invoice, the plan, the authorisation and the people at once, and we count each of our tables afterwards to confirm nothing is left. An account that was requested but never signed in to is removed automatically after 30 days. Sign-in links are stored only as a hash and removed within a day of expiring.
Who else sees it
- Cloudflare, Inc. (USA and EU) — runs the application.
- Supabase (EU, Frankfurt) — the database and the private file storage. Only our server can read them; the public keys hold no rights at all.
- Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (trading as Brevo) — sends sign-in links and the message that a plan is ready, to the people on the account only. No message carries a figure or a customer's name. Brevo puts an invisible image in every letter it sends, so it registers when a letter is opened; we cannot switch it off per message. Letters to your customers do not go through Brevo.
- PostHog (EU, Germany) — counts how the tool is used: numbers and categories, no names, no invoice numbers, no amounts.
- Your customers — once you authorise us, the letter about their own invoices, and nothing about anyone else.
No language model is used: every figure and every letter is produced by code from the ledger. Where a recipient processes data outside the UK or the EEA, the transfer is covered by Standard Contractual Clauses.
Cookies
One: the sign-in cookie, which holds the account and the person and nothing else. The analytics are configured without cookies and without local storage, so there is no banner to click.
Your rights
You can ask for a copy of what we hold about you, have it corrected, or have it deleted — the last you can do yourself in settings. You can complain to the Information Commissioner's Office (ico.org.uk). Where the data is about a client's customer, that client answers the request and we help it do so.