← Back to HEDGR
Important Notice
This Privacy Policy explains how Hedgr collects, uses, stores, shares and protects personal information under the Protection of Personal Information Act, 2013 (POPIA) of South Africa, the UK General Data Protection Regulation (UK GDPR) and, where it applies, the EU GDPR.
1. Who We Are
Hedgr Ltd is a company registered in England and Wales (Company No. 17138901), ICO Registration No. ZC116542. For your account data we are the responsible party (POPIA) and data controller (UK GDPR). For the accounting data of a business that uses Hedgr, that business is the responsible party and Hedgr acts as its operator, under our Data Processing Agreement.
Information Officer: Timmy Elenjical
Email: [email protected]
Business Address: 16 Mandalay Road, London, SW4 9EE
Phone: +447356642143
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, company name, and a password that we store only as a salted bcrypt hash.
- Settings: Financial year dates, base currency and policy preferences.
- CSV Uploads: Invoice data you upload manually. It is stored in your browser. If you choose Save workspace to cloud, we also store a copy on our servers.
- Communication Data: If you contact us for support, we collect your name, email and the content of your messages.
2.2 Information from Accounting Platforms
When you connect an accounting platform, we access the following information on a read-only basis:
- Invoices and Bills: Amounts, currencies, dates, statuses and contact names
- Bank Accounts: Account names, currencies and balances
- Organization Details: Business name, base currency and financial year settings
- Profit & Loss Data: Financial performance data, where the platform provides it
Important: We have read-only access. We cannot modify, create, or delete any data in your accounting system.
Xero, QuickBooks Online, Sage Business Cloud, Sage One (South Africa) and Google Sheets connect through OAuth 2.0, so we never see your password for those services. Holded connects through an API key, which we encrypt at rest.
2.3 AI-Powered Features (Scout)
Hedgr includes an optional AI assistant called Scout. When you use Scout:
- Your question and the relevant dashboard data are sent to our AI provider, Anthropic (USA), to generate the answer.
- This data can include the names of your customers and suppliers, with amounts, currencies and dates. It does not include bank account numbers or your login details.
- Under Anthropic's commercial terms, Anthropic does not use this data to train its models.
- We keep the recent turns of a conversation for up to 4 hours so that follow-up questions make sense. They then expire automatically.
- No automated decisions: Scout provides informational analysis only. It does not execute trades, modify hedging positions, or make financial decisions on your behalf.
2.4 Automatically Collected Information
- Usage Data: Pages viewed, features used, time spent
- Technical Data: IP address, browser and device information, session data
- Cookies: Session cookies for authentication, and analytics cookies if you consent (see Section 9)
3. How We Use Your Information
- Service Delivery: Calculate FX exposure, analyze currency risk, generate reports
- Authentication: Maintain secure access to your account
- Communication: Send service notifications, respond to support requests
- Improvement: Analyze usage patterns to improve our platform
- Legal Compliance: Meet legal and regulatory obligations
4. Legal Basis for Processing
- Consent (POPIA s11(1)(a) / GDPR Art 6(1)(a)): You authorize access when you connect an accounting platform, and when you share your portfolio with an adviser
- Contract Performance (POPIA s11(1)(b) / GDPR Art 6(1)(b)): Processing is necessary to provide our services under our Terms of Service
- Legitimate Interests (POPIA s11(1)(f) / GDPR Art 6(1)(f)): Security monitoring and fraud prevention
- Legal Obligations (POPIA s11(1)(c) / GDPR Art 6(1)(c)): Compliance with applicable laws in South Africa, the United Kingdom and the European Union
5. Data Storage and Security
5.1 Where We Store Your Data
- Application servers, databases and cache: Railway, in the European Union (Netherlands)
- Website: Netlify
- Accounting data: We read it live from your provider and do not keep a copy of your ledger. We store a daily snapshot of your dashboard figures, and bank-ledger events, so that the dashboard loads quickly and can show what changed.
5.2 Security Measures
- Encryption in transit: All data between your browser and our servers uses TLS
- Token encryption: Accounting access tokens are encrypted at rest with AES-256-GCM
- Password hashing: Account passwords are stored only as salted bcrypt hashes
- Adviser redaction: On an aggregated share, names are removed on our servers before data reaches your adviser
- Session management: Secure session handling with automatic expiry
5.3 Data Retention
- Account data, dashboard snapshots, bank-ledger events and adviser sharing records: Retained while your account is active
- OAuth tokens: Deleted when you disconnect your accounting platform
- Scout conversation context: Expires automatically after 4 hours
- Account deletion: Personal data deleted within 30 days of your request, unless the law requires us to keep it
6. Sharing Your Information
We do not sell your personal information. We share data only in the following circumstances.
6.1 Service Providers (Sub-processors)
- Railway: Hosting, databases and cache (data stored in the EU, Netherlands; Railway may access it from the USA)
- Netlify: Website hosting (USA)
- Anthropic: AI processing for Scout (USA). It receives your question and the relevant dashboard data, which can include customer and supplier names.
- Google: Email delivery (Google Workspace), and usage analytics (Google Analytics, with your consent)
- Stripe: Subscription billing and payments. Stripe collects your card details directly; we never see them.
- Exchange-rate sources: Market data only. They receive no personal data.
The accounting platforms you connect act under your own agreement with them. The full sub-processor list is in our Data Processing Agreement.
6.2 Advisers You Invite
You can invite an adviser, such as your FX broker, to view your Hedgr portfolio. We share your data with an adviser only after you accept the sharing consent, and the adviser has read-only access. You choose the level:
- Full: your adviser sees the portfolio as you see it.
- Aggregated: we remove customer, supplier and bank account names on our servers before any data reaches your adviser. Amounts and currencies stay visible.
You can revoke an adviser's access at any time, and access stops at their next request. We record each adviser view, so that we can tell you when your adviser viewed your portfolio.
6.3 Legal Requirements and Business Transfers
We may disclose information if required by law, court order or a regulator. If Hedgr is part of a merger, acquisition or sale, we will give you notice before your information moves to the new owner.
7. Your Rights Under POPIA and GDPR
- Right of Access: Request a copy of all personal information we hold about you
- Right to Correction: Request correction of inaccurate or incomplete data
- Right to Deletion: Request deletion of your personal data
- Right to Object: Object to processing of your personal information
- Right to Restrict Processing: Request that we limit how we use your data
- Right to Data Portability: Request your data in a structured, machine-readable format
- Right to Withdraw Consent: Disconnect your accounting platform, or revoke an adviser's access, at any time
- Right to Complain: Lodge a complaint with the Information Regulator of South Africa or the Information Commissioner's Office (UK)
To exercise any of these rights, contact our Information Officer at [email protected]. We will respond within 30 days.
8. International Data Transfers
We process your data outside South Africa and outside the UK. Our main data location is the European Union (Netherlands). Our sub-processors in the USA are listed in Section 6.1.
- South Africa (POPIA s72): We transfer personal information only to recipients bound by a law, binding corporate rules or a binding agreement that gives protection substantially similar to POPIA.
- UK and EU: We rely on adequacy decisions, or on the UK International Data Transfer Addendum or Standard Contractual Clauses in our agreements with these providers.
9. Cookies and Tracking Technologies
- Essential Cookies: Required for authentication and core functionality (cannot be disabled)
- Analytics Cookies: Google Analytics, set only after you consent through our cookie banner
We do not use cookies for advertising or sell data to advertisers.
10. Children's Privacy
Hedgr is intended for business use only and is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors.
11. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this policy and notify you by email or through a notice in the platform.
12. Contact Information
Information Officer: Timmy Elenjical
Email: [email protected]
Business Address: 16 Mandalay Road, London, SW4 9EE
Phone: +447356642143
Information Regulator (South Africa):
If you are not satisfied with our response, you may lodge a complaint with the Information Regulator:
inforegulator.org.za
Complaints: [email protected]
Information Commissioner's Office (UK): ico.org.uk