Privacy Policy
Last updated: September 2026 · Version 1.6
Who we are
The data controller for the personal data described in this policy is Eutaxis Ltd, a company registered in England and Wales under company number 17441843. SectorBoard is a trading name of Eutaxis Ltd. For privacy matters, contact us at [email protected].
1. What We Collect
We collect the following information when you use SectorBoard:
- Account information: name, email address, password (hashed)
- Organisation details: company name, size, industry, address
- Usage data: which connectors and KPIs you configure
- API credentials: stored encrypted, never readable in plain text
- KPI data: numerical metrics fetched from your connected apps
- Workforce data: where you connect an accounting app that includes payroll, an employee reference number and employment dates for each of your employees, plus pay-run totals — see below
Workforce data from payroll-enabled connectors
Where your organisation connects an accounting app that includes payroll and grants the payroll permissions, SectorBoard reads, for each of your employees, an employee reference number generated by that app, the employment start date and, where the employment has ended, the end date — together with pay-run totals for each pay period. We use these to calculate workforce figures for your board: headcount, revenue per employee, payroll cost per employee, and staff turnover.
We do not read names, email addresses, telephone numbers, home addresses, dates of birth, National Insurance numbers, or any individual's pay. Those fields are never requested from the connected app. The individual employee records we do read are used to calculate the figures above while a sync runs and are then discarded — only the resulting figures are stored.
We treat this as personal data about your staff. Although we never see a name, you can match an employee reference number back to a person in your own payroll system. Your organisation is the controller of that data and we process it on your instructions as your processor, under our Data Processing Agreement. The payroll permissions are granted by you when you connect the app, and disconnecting the connector stops this processing.
2. How We Use Your Data
- To provide and improve the SectorBoard service
- To send transactional emails (verification, password reset, invitations)
- To process payments via Stripe
- To display your business KPIs on your dashboard
- To power AI features and the Atlas advisor, if your organisation enables them (see section 4)
- We do NOT sell your data to third parties
- We do NOT use your data for advertising
3. Data Storage & Security
Your data is stored in Supabase (PostgreSQL), hosted in the EU (Ireland) region. API credentials are encrypted using AES-256-GCM before storage, and all data is transmitted over HTTPS (TLS 1.2+). Data is isolated by organisation in the application layer, with database row-level security enabled as an additional safeguard. Access is protected by hashed passwords, rate-limited sign-in with brute-force lockout, optional two-factor authentication, and configurable session controls (automatic inactivity logout and session limits). A fuller description is on our Security & Trust page.
4. Third-Party Services & AI Processing
We use the following third-party services:
- Supabase — database and authentication (EU hosted)
- Stripe — payment processing (they handle all card data)
- Google Workspace — email delivery
- Anthropic — AI processing, engaged if your organisation uses the AI features (including during a free trial) or the Atlas advisor add-on (United States; no model training on inputs)
This is a summary. The complete and authoritative list — including our hosting and rate-limiting providers, and the data each one processes, where, and under which transfer safeguard — is our Sub-processor List, which prevails over this summary. Data read from your connected apps, including the workforce data described in section 1, passes through our hosting provider's servers while a sync runs; the Sub-processor List states where.
AI features & the Atlas advisor. If your organisation uses SectorBoard's AI features (such as Ask AI and AI commentary) — whether on the paid add-on or in the usage-capped form available during a free trial — or the Atlas advisor add-on, we send computed KPI values and organisational context — not raw connector records — to our AI sub-processor Anthropic to generate the analysis; Anthropic does not train its models on this input. The Atlas advisor, when enabled, analyses your KPI data automatically each night (unattended) to produce your morning briefing, alerts and predictions. It is advisory and human-in-the-loop — it does not make solely-automated decisions — and everything it shows is scoped to what each user is permitted to see. Atlas is an opt-in paid add-on: enabling or removing it turns this processing on or off. See the Sub-processor List and Security & Trust pages for detail.
5. Data Retention
Active account data is retained while your account is active. Upon cancellation, data is retained for 90 days to allow reactivation. After 90 days, all personal data and KPI history is permanently deleted. You may request immediate deletion by contacting us.
The individual employee records described in section 1 are not retained at all: they exist only in memory while a sync is running, and what remains afterwards is the calculated workforce figures, which are retained on the same basis as the rest of your KPI history.
6. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Portability — receive your data in a machine-readable format
- Objection — object to processing of your data
To exercise these rights, contact us at [email protected]
7. Cookies
The only cookies we set are strictly necessary and keep you signed in: a session cookie (`session_token`) and a companion cookie that tracks activity for the automatic inactivity logout. Both are HTTP-only, Secure and SameSite. The session length is set by your organisation's administrator (by default 12 hours; optionally up to 24 hours, or 7 days with “Remember me”), and a session is ended automatically after a period of inactivity.
Our site is delivered through Cloudflare, a security and content-delivery network that sits in front of our servers. Cloudflare may set its own strictly-necessary cookie to tell automated traffic apart from real visitors; where it does, that cookie is a security measure and is not used for advertising, analytics or cross-site tracking. We do not use tracking cookies or advertising cookies.
8. Contact
For privacy enquiries, contact us at [email protected]. We aim to respond within 5 business days.