Privacy Policy

Last updated

Abacist is production accounting software. This policy explains what personal data the service handles, who processes it on our behalf, and what you can ask us to do with it.

1.Who is responsible for your data

Abacist is operated by Fontainhas Brothers, Lda. You can reach us at hello@abacist.io for any question about this policy.

Two different relationships apply, and the distinction matters for your rights. For data about your own account — the address you sign in with, your name and profile details — we are the controller. For the production records you enter into the service, such as crew and vendor details, we act as a processor on behalf of the production company that holds the account; that company is the controller and decides what is stored and for how long.

If you are a crew member or supplier and want your details corrected or removed, contact the production you worked with first. We will help them action it, and we will respond directly if they cannot.

2.What the service holds

Abacist stores what a production accounting system needs to function. We do not buy personal data, and we do not collect anything for advertising.

  • Account details — name, email address, and profile photo if you set one.
  • Profile details you choose to add — telephone number, postal address, and a tax identification number.
  • Crew and personnel records entered by a production — name, email, telephone, photo, postal address, tax identification number and country, and where a production records it, an identification document type and number.
  • Supplier records — company or contact name, email, telephone, postal address, and tax identification number.
  • Financial records — budgets, purchase orders, transactions, petty cash, and the bank details of the production's own accounts, including account and routing numbers.
  • Documents — invoices, receipts and statements you upload, or send to a project's intake address. These frequently contain personal data placed there by whoever issued them.
  • Email sent to and from a project's intake address, including attachments and sender details.
  • Security and operational records — audit entries, sign-in events, and error reports.
  • Product usage data from the signed-in application, including session recordings that capture how pages were used.

3.What we use it for

To provide the service: authenticating you, showing you the productions you have access to, and running the accounting features you use.

To process documents you submit. Invoices, receipts and statements are read by an automated extraction step so their figures can be proposed to you. A person reviews and confirms the result before it becomes an accounting record — the extraction proposes, it does not post.

To validate tax identification numbers you ask us to check, against the relevant public registry.

To send transactional email: sign-in links, approval requests, reminders and notifications.

To keep the service secure and accountable — detecting abuse, rate-limiting sign-in attempts, and maintaining an audit trail of who changed what.

To understand how the application is used, so it can be improved. This is the only purpose session recording serves, and it applies to the signed-in application, not to this website.

4.Our legal basis

Where we act as controller, we rely on performance of a contract for anything necessary to deliver the service you signed up for, and on our legitimate interests for security, abuse prevention, audit logging and product improvement. Where a purpose requires consent, we ask for it and you can withdraw it at any time.

Where we act as processor for production records, the legal basis is the controlling production company's to establish, and our processing follows their documented instructions.

5.Who processes data on our behalf

We use a small number of sub-processors. Each is named here with what it actually does, rather than described in general terms.

  • Google Cloud and Firebase — application hosting, authentication, the database, and file storage. This is where the service and your data live.
  • Google Gemini and Google Document AI — automated extraction of figures from documents you upload or email in. Documents are sent for processing when this step runs.
  • Resend — sending transactional email and receiving mail addressed to project intake addresses.
  • PostHog (EU region) — product analytics, session recording and error reporting for the signed-in application.
  • The European Commission's VIES service — checking VAT numbers when a tax identification number is submitted for validation.

6.Where data is held

The application, its database and its file storage run in Google Cloud's Netherlands region, and our analytics provider is configured to its European region. Data is stored in the European Union.

Some sub-processors are organisations that may access data from outside the European Economic Area for support purposes. Where that happens it is covered by the transfer safeguards in our agreements with them, including Standard Contractual Clauses.

7.How long it is kept

Production records are kept for as long as the production's account is active, and then according to the instructions of the production company that controls them. Accounting records carry statutory retention periods that outlast the account.

Closing an account archives it rather than erasing it. Access ends and memberships are deactivated, but the underlying records are retained, because most of them are the accounting records above. Pending invitations are deleted at that point.

Sign-in and security events are kept for 90 days. The audit trail over accounting records is kept for as long as the records themselves, because its purpose is to show who changed what.

8.Your rights

Under the General Data Protection Regulation you can ask for access to your personal data, correction of anything inaccurate, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests.

Erasure has limits, and we would rather be plain about them than quiet. Where a record is one we are required by law to keep — accounting records above all — we cannot erase it while that obligation lasts. We will tell you what is held, what we can remove, and what we must keep and why.

Write to hello@abacist.io and we will respond within one month. Requests are handled by a person; there is no self-service delete. If your data was entered by a production company, we will route the request to them and support them in answering it.

You also have the right to complain to the data protection supervisory authority in the country where you live or work.

9.How it is protected

Access is enforced in the database itself rather than only in the interface, so a request that is not entitled to a record cannot read it regardless of where it came from. Sensitive operations are checked a second time on the server.

Data is encrypted in transit and at rest by our hosting provider. Sign-in attempts are rate-limited, and changes to accounting records are recorded in an audit trail.

No system is beyond compromise. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant supervisory authority as the law requires.

10.Cookies on this website

This website sets no analytics or advertising cookies and runs no tracking scripts. Nothing here follows you.

The signed-in application at app.abacist.io is different: it sets a session cookie so you stay signed in, and it runs the product analytics described above. That is a working application rather than a brochure, and it tells you so when you sign in.

11.Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we handle your personal data, we will tell account holders by email rather than relying on you to notice.

12.Contact

Email hello@abacist.io. Questions about this policy reach a person, not a queue.