Security & Data Retention
Effective 16 September 2026 · Somfa Financial Books Services, Calgary, Alberta, Canada
A plain statement of how we protect your books and how long we keep them. It supports our Privacy Policy and Data Processing Agreement, and we update it as the platform evolves.
Safeguards
- Encrypted connections (TLS) for all traffic, and encryption at rest for the database, file storage and backups.
- Strict tenant isolation enforced at the database level, so one workspace cannot read another’s records.
- Role-based access with per-person permissions for owners, managers, bookkeepers, employees and invited advisors.
- Account protections: verified activation with expiring links, sign-in rate limiting, password-strength and breached-password screening, optional TOTP multi-factor authentication, and visibility of active sessions and devices with one-click revocation.
- Audit trails that cannot be edited, covering document cancellation, restoration and amendment, role and permission changes, billing changes and administrative actions.
- Secrets and integration credentials held in encrypted storage, never in application code or browser storage.
- Least-privilege internal access, reviewed regularly; administrative actions are logged.
- Automated typechecks, tests and security linting on every change before it reaches production.
Backups and continuity
- Managed continuous backups with point-in-time recovery, retained on a rolling cycle of approximately 35 days.
- Restoration is tested periodically; we aim to restore service within hours and lose no more than minutes of committed data in a regional failure.
- Offline point-of-sale queues in your browser keep sales safe during connection loss and sync automatically.
Retention periods
- Active workspace records: kept while your subscription is active.
- After closure: 30 days read-only for export, then deletion or de-identification within 90 days.
- Cancelled financial documents are retained rather than erased, so the audit trail stays complete.
- Security and audit events: 12–24 months. Email delivery logs: 12 months. Suppression records: kept indefinitely so we honour unsubscribes.
- Records we must keep as a business, such as invoices and tax records: up to 7 years.
Incident response
- We triage suspected incidents immediately, contain, investigate root cause and remediate.
- Affected customers are notified without undue delay and within 48 hours of confirming a personal-data breach, with what happened, what data was involved and what to do.
- Regulators and, where required, individuals are notified within the statutory deadlines applying to them.
- We publish a post-incident summary for material incidents.
Responsible disclosure
Report a suspected vulnerability to admin@somfabookkeeping.com with enough detail to reproduce it. Please do not access other customers’ data, degrade the service, or disclose publicly before we have fixed it. We acknowledge reports within 3 business days, and we will not take legal action against good-faith research that follows this process.
Your responsibilities
- Use strong, unique passwords and turn on multi-factor authentication.
- Review who has access to your workspace, and remove leaving staff and former advisors promptly.
- Keep your devices and browsers updated, and never share sign-in links or one-time codes.
- Export your own copies of key records periodically.
Questions about this document? Email admin@somfabookkeeping.com or call (825) 785-8683. This page is information about our practices, not legal advice; please have your own counsel review it before you rely on it for your own compliance obligations.