Privacy Policy

This policy explains how Counter Technologies Ltd(company number 17341153, registered office 14/2e Docklands Business Centre, 10-16 Tiller Road, London E14 8PX) (“Counter”, “we”, “us”) handles personal data in connection with the Counter service (the “Service”). We are registered with the Information Commissioner’s Office under number ZC199853. Questions or requests: hello@trycounter.co.uk.

1. Our two roles

As a controller, we decide how to process the personal data of the people who use Counter: account details, login and usage records, billing information and support correspondence.

As a processor, we process the business documents and communications our customers submit or connect (invoices, quotes, credit notes, supplier emails, accounting records). These can contain personal data of third parties — typically names and contact details of supplier staff. Our customer is the controller of that data and this processing is governed by our Terms and Data Processing Addendum. If your personal data appears in a customer’s documents, that customer is the primary point of contact for privacy requests, though we will assist where we can.

2. What we collect

We use only essential cookies (authentication/session cookies and short-lived preference cookies). We do not use advertising or cross-site tracking cookies.

3. How we use data, and why it’s lawful

4. AI processing

We use third-party AI models to read documents, extract line items, classify products, interpret replies and draft correspondence — currently Google (Gemini), Anthropic (Claude) and OpenAI (voice-note transcription). We use these providers’ business APIs under terms which do not permit them to use our submitted content to train their models. Data sent to AI providers is limited to what the relevant feature needs (typically document images/text and related context).

We do not make solely automated decisions that produce legal or similarly significant effects on individuals. AI output in the Service relates to business documents and pricing, and significant actions (such as sending correspondence or orders) operate within limits our customers configure and can review.

Connecting your own AI assistant (quoting connector). If you enable it, you can connect your own Anthropic Claude account to Counter as a read-only connector so you can look up prices and quote jobs conversationally. When you do, you authorise the connection through a standard sign-in (OAuth) and Counter exposes only a read-only view of your own price book to yourClaude account — the connector cannot change, delete or add data, and cannot reach other customers’ data. The price-book information you request through the connector is sent to Anthropic under the Claude terms and privacy policy of your own Anthropic account, which govern that account and are outside Counter’s control. You can revoke the connection at any time from your Counter integration settings or your Anthropic account.

5. Who we share data with

We do not sell personal data. We share it only with the service providers below (our subprocessors), with the third parties you direct us to contact (your suppliers, when sending correspondence or orders on your behalf), and where required by law. We keep this list current; material changes are notified to customers in advance, as set out in our Data Processing Addendum.

ProviderPurposeLocation
SupabaseDatabase, file storage, authenticationEU (Ireland)
VercelWeb application hostingUK (London)
RailwayAssistant service hostingEU (Netherlands)
GoogleAI document extraction (Gemini)US/EU
AnthropicAI processing (Claude)US
OpenAIVoice-note transcriptionUS
ResendEmail sending and inbound email receiptUS/EU
ComposioOAuth integration layer (Gmail, Outlook, Xero, QuickBooks)US
Meta (WhatsApp) / TelegramMessaging channels, where you use themUS/EU
UpstashRate limiting / cachingUK (London)
SentryError monitoringUS/EU
SlackInternal operational alerts to our teamUS/EU

6. International transfers

Some providers above process data outside the UK. Where they do, we rely on UK adequacy regulations (including the UK–US Data Bridge where the provider is certified) or the UK International Data Transfer Addendum to EU Standard Contractual Clauses, together with the providers’ own security measures.

7. Retention

Customer documents and derived data are retained for as long as the customer’s account is active — pricing history is the core of the Service, so documents are kept for the life of the account unless the customer deletes them or asks us to. After termination, Customer Data is deleted from live systems within 90 days of the export window closing (see Terms, clause 18). Account and billing records are kept as long as needed for legal and accounting obligations (typically 6 years). Logs and error data are kept for shorter operational periods.

8. Security

Data is encrypted in transit and at rest. Access to production data is restricted to authorised personnel, internal service-to-service calls are authenticated with secrets, customer data is segregated per company at the application layer, and we run automated security checks on every code change. No system is perfectly secure; if a breach affects your personal data we will notify you and, where required, the ICO without undue delay.

9. Your rights

Under UK GDPR you can ask us for access to, correction, deletion, restriction or portability of your personal data, and you can object to processing based on legitimate interests. Contact hello@trycounter.co.ukand we will respond within one month. If we process your data as a customer’s processor we may refer your request to that customer. You can also complain to the Information Commissioner’s Office (ico.org.uk).

10. Changes

We may update this policy from time to time; material changes will be notified by email or in the dashboard. The date at the top identifies the current version.