GDPR & Data Protection

GDPR & Data Protection

Last updated: [DD Month 2026]

At Lusobo, protecting personal data is central to how we build and operate our platform. This page explains how we comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and — where it applies to individuals in the European Economic Area — the EU General Data Protection Regulation (EU GDPR). It sets out what personal data we process, why, on what legal basis, and the rights you have.

This page complements our Privacy Policy and Cookie Policy. Where there is any inconsistency in relation to data-protection matters, please read this page alongside those documents and contact us if anything is unclear.

1. Who we are

Lusobo is a service provided by LUSOBO LTD, a company registered in England and Wales (company number 17209602), with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom.

For questions about data protection, or to exercise your rights, contact us at:

[If you have appointed a Data Protection Officer or a UK/EU representative, name them here. If not, delete this sentence.]

2. Our role: controller and processor

Lusobo acts in two different capacities depending on the data involved. Understanding which applies to you determines who is responsible and how you exercise your rights.

When we are the data controller

We are the controller for the personal data we decide how to use, including:

  • account and user details (name, email address, job role, password credentials);
  • billing and subscription information;
  • information you submit through our website, contact forms, or support channels;
  • website usage and analytics data collected via cookies (see our Cookie Policy).

When we are a data processor

When you connect an accounting system (such as Xero), a bank account, or upload documents, our platform processes the financial data held in those systems on your behalf. That financial data may contain personal data relating to third parties — for example, the names of your customers, suppliers, or employees appearing in invoices, bank transactions, or payroll entries.

For this data, you (our customer) are the data controller and Lusobo is a data processor acting on your documented instructions. We process it only to provide the services you have asked us to perform — such as syncing, normalising, validating, reconciling, and analysing your finances. Our processing of this data is governed by our Data Processing Agreement (available on request or as part of your service terms).

If you are an individual whose personal data appears within a Lusobo customer’s financial records and you wish to exercise your rights, please contact that customer (the controller). We will support them in responding to your request.

3. The personal data we process

Depending on your relationship with us, we may process the following categories of personal data:

  • Identity and contact data — name, email address, telephone number, job title, business name.
  • Account and credential data — login details, authentication tokens, and access permissions.
  • Financial and transactional data — invoices, bills, payments, bank transactions, chart of accounts, and related records synced from connected systems or uploaded by you. This may include personal data relating to your customers, suppliers, and employees.
  • Usage and technical data — IP address, device and browser information, log data, and interactions with the platform.
  • Communications data — records of correspondence with our support and sales teams.
  • Marketing preferences — your choices about receiving communications from us.

We do not seek to process special category data (such as health, biometric, or racial/ethnic data). Please do not upload documents containing special category data unless it is strictly necessary and you have a lawful basis to share it with us.

4. Our legal bases for processing

Where we act as a controller, we rely on the following legal bases under Article 6 of the UK/EU GDPR:

  • Performance of a contract — to create and manage your account, provide the platform, and deliver the features you subscribe to.
  • Legitimate interests — to secure and improve our services, prevent fraud and misuse, and communicate with existing customers about relevant products. Where we rely on legitimate interests, we balance them against your rights, and you may object (see Section 6).
  • Consent — for non-essential cookies and for marketing communications to prospective customers. You can withdraw consent at any time.
  • Legal obligation — where we must retain records or disclose information to comply with law, including tax, accounting, and anti-money-laundering requirements.

Where we act as a processor, we process personal data on the documented instructions of our customer under our Data Processing Agreement.

5. How we use personal data

We use personal data to:

  • provide, maintain, and secure the Lusobo platform;
  • connect to and sync data from accounting systems and banks you authorise;
  • build a unified view of your finances and run validation, reconciliation, and reporting;
  • generate insights and AI-assisted commentary that you review and approve;
  • manage billing, provide support, and respond to your requests;
  • comply with our legal and regulatory obligations;
  • improve our services and, where permitted, send you relevant communications.

6. Your rights

Under the UK/EU GDPR you have the following rights. We will respond to a valid request within one month, unless an exemption applies or the request is complex, in which case we may extend the period and will tell you.

  • Right to be informed — to know how your personal data is used, as set out on this page.
  • Right of access — to obtain a copy of the personal data we hold about you.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure — to have your personal data deleted where there is no overriding reason to keep it (note that we may be legally required to retain certain financial records).
  • Right to restrict processing — to limit how we use your data in certain circumstances.
  • Right to data portability — to receive the personal data you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another provider where technically feasible.
  • Right to object — to object to processing based on legitimate interests, and to object to direct marketing at any time.
  • Rights relating to automated decision-making and profiling — see Section 7 below.

To exercise any of these rights, contact privacy@lusobo.com. There is normally no charge, and we may need to verify your identity before responding.

7. Automated processing and AI

Lusobo uses automated processing, including machine learning and AI, to read documents, classify transactions, detect inconsistencies, suggest reconciliations, and produce financial insights.

Our platform is built around human oversight: our AI features detect, propose, and explain, but a human reviews and approves outcomes, and every action is recorded in an audit trail. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without meaningful human involvement.

If you have questions about how a particular automated feature works, or you wish to request human review of an outcome, contact privacy@lusobo.com.

8. Data retention

We keep personal data only for as long as necessary for the purposes described on this page, or for as long as required by law. Financial and accounting records are typically retained for at least six years to meet UK tax and accounting obligations. When data is no longer required, we securely delete or anonymise it. Where we act as a processor, we retain and delete customer data in accordance with our Data Processing Agreement and your instructions.

9. How we protect your data

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, strict tenant separation so each organisation’s data is isolated, audit logging, and regular review of our security practices. No system can be guaranteed completely secure, but we work continuously to reduce risk and to respond quickly if an issue arises.

10. International data transfers

Some of the service providers we rely on may process personal data outside the UK or the EEA. Where we transfer personal data internationally, we ensure an appropriate safeguard is in place, such as an adequacy decision, the UK International Data Transfer Agreement (IDTA) or Addendum, or the European Commission’s Standard Contractual Clauses, together with any additional measures required. You can contact us for more detail on the safeguards used for a specific transfer.

11. Third parties and sub-processors

We share personal data with trusted service providers who help us deliver the platform, and only under contracts that require them to protect it. These include, for example:

  • accounting and finance integrations you connect (such as Xero);
  • open banking and payment data providers (such as Plaid);
  • cloud hosting and infrastructure providers;
  • analytics, communication, and support tools.

[Maintain and link a current list of sub-processors here, e.g. “A current list of our sub-processors is available at /sub-processors/ or on request.”] We do not sell your personal data.

12. Data breaches

We have procedures to detect, report, and investigate personal data breaches. Where a breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the Information Commissioner’s Office (ICO) without undue delay and, where required, within 72 hours of becoming aware of it. Where the risk is high, we will also notify affected individuals. Where we act as a processor, we will notify the relevant controller without undue delay.

13. Cookies

We use cookies and similar technologies on our website. Non-essential cookies are only used with your consent. For full details and to manage your preferences, see our Cookie Policy.

14. Children’s data

Lusobo is a business service and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe we have inadvertently done so, please contact us so we can delete it.

15. Changes to this page

We may update this page from time to time to reflect changes in our practices or the law. The “last updated” date at the top shows when it was last revised. We encourage you to review it periodically.

16. Complaints

If you have a concern about how we handle your personal data, please contact us first at privacy@lusobo.com so we can try to resolve it.

You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO) — ico.org.uk. If you are in the EEA, you may complain to the data protection authority in your country of residence.