SSOMFA Business Cloud
PlatformPricingLive demoBookkeepingBlog
Sign inTry the demoStart free
Home/Legal

Privacy Policy

Effective 16 September 2026 · Somfa Financial Books Services, Calgary, Alberta, Canada

This policy explains how Somfa Financial Books Services handles personal information across the SOMFA Business Cloud platform, our websites, our bookkeeping services and our marketing. It covers two different roles: information we hold about you as our own customer or visitor (we are the controller), and information you put into your workspace about your customers, staff and suppliers (you are the controller and we process it for you under our Data Processing Agreement).

1. Who we are and how to reach us

  • Controller: Somfa Financial Books Services, Calgary, Alberta, Canada.
  • Privacy contact: admin@somfabookkeeping.com · (825) 785-8683.
  • We act as the point of contact for privacy requests in every region where we operate. If your local law requires a representative or a registered data-protection officer, write to the same address and we will route your request.

2. Information we collect

You give us

  • Account and identity: name, business name, work email, phone, password (stored only as a hash), multi-factor settings.
  • Business profile: legal name, trading name, addresses, entity type, business type, industry, currency, tax registration numbers, place of supply and nexus settings.
  • Billing: plan and add-ons, billing address, tax status, and payment records. Card details go directly to our payment processor — we never see or store full card numbers.
  • Workspace content: sales, invoices, quotes, receipts, expenses, bills, suppliers, customers, products, inventory, bank statement imports, documents and uploads, employee records, timesheets, schedules and payroll inputs.
  • Communications: support messages, AI assistant chats, meeting bookings, contact and consultation forms.

We collect automatically

  • Device and log data: IP address, browser and device type, pages viewed, referring page, timestamps, error reports.
  • Security events: sign-in attempts, activation and password resets, session and device records, role changes and audit-log entries.
  • Product usage: features used and aggregated activity counts, used to run and improve the service.
  • Cookies and similar technologies — see the Cookie & Tracking Notice.

We receive from others

  • Sign-in providers (for example Google) confirm your identity and email when you use social sign-in.
  • Our payment processor sends subscription and payment status.
  • Amazon’s Selling Partner API returns your orders, finances, inventory and listing data when you authorise a connection.
  • Email delivery and CRM/booking providers send delivery, bounce, unsubscribe and meeting details.
  • Breached-password screening services confirm only whether a password appears in known breaches; we never send them your password in the clear.

We do not seek special-category or sensitive data. Do not upload government identity documents, health records or full payment card numbers except where a feature explicitly asks for them.

3. Why we use it, and our legal bases

  • Provide the service — perform our contract with you: create workspaces, run POS, invoicing, reconciliation, reports, tax calculations, payroll and workforce features.
  • Billing and collections — contract and legal obligation.
  • Security, fraud prevention, tenant isolation and audit trails — legitimate interests and legal obligation.
  • Support and service messages — contract and legitimate interests.
  • Product improvement and aggregated analytics — legitimate interests, or consent where required for analytics cookies.
  • Marketing emails and remarketing — consent where required (UK/EEA, Canada’s CASL, and similar), otherwise legitimate interests with an opt-out in every message.
  • Legal, accounting and record-keeping obligations — legal obligation.

We do not sell personal information, and we do not share it for cross-context behavioural advertising in the sense used by US state privacy laws. We do not use your workspace content to train third-party AI models, and we do not make decisions with legal effect about you by automated means alone.

4. Who we share it with

  • Service providers acting on our instructions: cloud hosting and managed database infrastructure (North America), transactional email delivery, payment processing and subscription billing, customer relationship and meeting booking, error monitoring, and AI model providers for assistant features.
  • Your own connected accounts and integrations, at your instruction.
  • People inside your workspace — owners, managers, bookkeepers, advisors and employees see what their role permits.
  • Professional advisors, insurers and auditors under confidentiality, where necessary.
  • Authorities, when legally required; we assess and, where lawful, resist overbroad requests and tell you unless prohibited.
  • A buyer or successor in a merger, acquisition or reorganisation, subject to this policy.

All providers are bound by written terms limiting them to our instructions, with confidentiality and security obligations.

5. Where your data lives and international transfers

Our production systems and backups are hosted in North America (Canada and the United States). Some providers operate elsewhere. Where personal information leaves your region we rely on appropriate safeguards: the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions where available, and contractual, technical and organisational measures including encryption in transit and at rest. You can request a summary of the safeguards applying to your workspace.

6. How long we keep it

  • Workspace content: for the life of your subscription, then 30 days read-only, then deletion or de-identification within 90 days of closure unless you ask us to delete sooner.
  • Financial and tax records we must keep as a business: up to 7 years, as Canadian and comparable law requires.
  • Security and audit logs: 12–24 months.
  • Marketing contacts: until you unsubscribe, plus a suppression record so we do not email you again.
  • Backups roll off on their own cycle, normally within 35 days.

7. How we protect it

Encryption in transit and at rest, row-level tenant isolation in the database, role-based permissions, optional multi-factor authentication, activation-link expiry, rate limiting, breached-password screening, session and device revocation, immutable audit logging of sensitive actions, least-privilege administrative access and monitored backups. See the Security & Data Retention policy for detail and our incident process.

8. Your rights, by region

Wherever you are, you can ask us to access, correct, delete or export your personal information, withdraw consent, or object to a use. Email admin@somfabookkeeping.com. We verify requests against your account, reply within 30 days (or sooner where law requires), and never charge or penalise you for asking. An authorised agent may act for you with written proof.

Canada (PIPEDA and provincial laws)

Access and correction rights, withdrawal of consent, and the right to complain to the Office of the Privacy Commissioner of Canada — or to the Alberta, British Columbia or Quebec regulator where their law applies. Quebec residents also have data-portability and automated-decision transparency rights under Law 25.

United Kingdom & European Economic Area (UK GDPR / GDPR)

Access, rectification, erasure, restriction, portability, objection (including to direct marketing), and the right not to be subject to solely automated decisions with legal effect. You may complain to your national supervisory authority or the UK Information Commissioner’s Office. Where we rely on legitimate interests we have carried out a balancing assessment and will share its outcome on request.

United States (CCPA/CPRA and state laws)

Rights to know, access, delete, correct, and to opt out of sale or sharing and of targeted advertising — we do not sell or share your information for those purposes. Rights to limit use of sensitive information, to data portability, and to non-discrimination. Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comparable laws may also appeal a refused request by replying to our decision email.

Africa, Australia and other regions

Nigeria (NDPA), Ghana, Kenya, South Africa (POPIA) and Australia (Privacy Act, APPs): access, correction, objection, deletion where applicable, and the right to complain to your national regulator or Information Officer. Where local law requires local registration, notification of transfers or a data-protection officer, we meet those obligations for the regions we serve.

If your request concerns data inside a business’s workspace (for example you are that business’s customer or employee), we will forward it to that business, which is the controller, and support them in answering you.

9. Cookies, analytics and marketing choices

We use strictly necessary cookies for sign-in and security, and optional analytics and marketing technologies only where permitted — in the UK/EEA and other consent-first regions we ask before setting them; elsewhere you may opt out at any time. Every marketing email includes a one-click unsubscribe, and we honour it immediately. Details are in the Cookie & Tracking Notice.

10. Changes and breach notification

We will post any change here with a new effective date, and email you if it is material. If a breach of personal information creates a real risk of significant harm we will notify affected customers and the relevant regulators within the statutory deadlines applying to them — including 72 hours under the UK/EU GDPR — with what happened, what data was involved and what we are doing about it.

Questions about this document? Email admin@somfabookkeeping.com or call (825) 785-8683. This page is information about our practices, not legal advice; please have your own counsel review it before you rely on it for your own compliance obligations.

All policies

  • Terms of Service
  • Privacy Policy
  • Cookie & Tracking Notice
  • Data Processing Agreement
  • Acceptable Use Policy
  • Subscription, Billing & Refunds
  • Security & Data Retention
  • Bookkeeping Engagement Terms
SOMFA

Accurate books today. Stronger business tomorrow.

Explore

  • Home
  • Platform
  • Pricing
  • Live demo
  • Bookkeeping
  • Blog

Product

  • Dashboard
  • Point of sale
  • Invoices
  • Expenses
  • Banking & reconciliation
  • Reports
  • Payroll
  • People & time

Pro Hub

  • Professional workspace
  • Find an accountant
  • My accountant
  • Team & roles
  • Settings
  • Sign in
  • Start free

Contact

  • (825) 785-8683
  • admin@somfabookkeeping.com
  • www.somfabookkeeping.com
  • Calgary, Alberta, Canada

Intuit QuickBooks Certified ProAdvisor — Elite tier.

Legal CentreTerms of ServicePrivacy PolicyCookiesData ProcessingAcceptable UseBilling & RefundsSecurity
© 2026 Somfa Financial Books Services. All rights reserved.