Privacy Policy &
Data Protection Standards
Effective Date: August 17, 2026 • Full client data sovereignty, zero-data-brokerage, in-memory PII tokenization, and strict private LLM inference architecture.
1. Zero-Data-Brokerage Pledge
EliteBooks is built upon a fundamental invariant: Your financial data belongs exclusively to your business. We do not sell, rent, monetize, or broker corporate transaction logs, customer records, or financial metrics to third-party advertisers, data aggregators, or marketing networks under any circumstance.
Our revenue model is strictly software subscription-based. We do not participate in cross-context behavioral tracking or corporate financial surveillance.
2. Information We Ingest & Collect
To power our multi-agent autonomous accounting services, we collect and process the following categories of information:
- Corporate Account Credentials: Administrator name, verified corporate email address, and multi-tenant organization identifiers.
- Financial Ledger Data: Invoices, merchant receipts, bank transaction lines, category tags, and Chart of Accounts mappings.
- Workforce & Payroll Metadata: Employee names, compensation tiers, department assignments, and tax withholding profiles.
- Cloud Infrastructure Logs: Cloud cost metrics and resource billing lines (AWS, Azure, GCP, OpenAI) for FinOps optimization.
3. Ephemeral PII/PHI Masking Vault
All Personally Identifiable Information (PII) and Protected Health Information (PHI)—including bank routing numbers, employee Taxpayer Identification Numbers (TINs/SSNs), health benefit policy IDs, and credit card tokens—is processed through our dedicated Ephemeral PII/PHI Masking Vault. Data is tokenized in-memory with automatic TTL expiration.
In-memory tokenization intercepts sensitive parameters before AI agent processing, ensuring model prompts only operate on redacted, non-identifiable numerical arrays and ephemeral tokens.
4. Zero-Retention Private LLM Inference
When our AI agents synthesize financial summaries or categorize expenses, requests are transmitted via encrypted enterprise TLS 1.3 channels to isolated private model inference endpoints with strict zero-data-retention agreements.
Your raw ledger entries, receipts, and employee records are never stored on external servers or used to train global foundation models. Model outputs are strictly transient and committed solely to your private database partition.
5. Banking & OAuth Token Segregation
Direct bank connections are established through certified Open Banking protocols (Plaid) and payment gateways (Stripe Connect). EliteBooks maintains only tokenized, read-only permissions and never has access to or stores your primary banking passwords or direct login credentials.
6. Global Compliance (GDPR & CCPA)
Regardless of your geographical headquarters, EliteBooks extends global privacy standards to all organizations:
- Right to Portability: Export your complete ledger history, journal entries, and customer rosters in standard JSON/CSV formats at any time.
- Right to Erasure: Request permanent cryptographic deletion of personal workforce records and archived transaction backups upon account termination.
7. Automated Audit Defense & Data Retention Lifecycle
General ledger transactions reconciled with double-entry integrity receive SHA-256 cryptographic locks. Tax compliance documentation (Form 941, 1099-NEC dossiers) is retained pursuant to statutory IRS 7-year audit requirements in immutable, append-only cold storage vaults.
8. Infrastructure & Authorized Subprocessors
EliteBooks utilizes SOC 1/2 Type II certified cloud infrastructure providers including Google Cloud Platform (GCP), Amazon Web Services (AWS), and Stripe. All subprocessors are bound by enterprise Data Protection Agreements (DPAs) enforcing strict confidentiality and encryption invariants.
Experience Enterprise-Grade Security
Protect your financial operations with mathematical double-entry invariants, AES-256-GCM encryption, and full data sovereignty.