Privacy Policy — Tejas

Effective Date: 1 August 2026

Last Updated: 1 August 2026

This Privacy Policy describes how Ruly Data Ltd ("we", "us", "our") collects, uses and discloses information when you use Tejas, our Microsoft Excel add-in and its supporting service (together, "the Service").

We are committed to protecting your personal data and complying with applicable privacy laws including the UK General Data Protection Regulation (UK GDPR), the EU GDPR, the

California Consumer Privacy Act (CCPA) and the California Online Privacy Protection Act (CalOPPA).

1. What the Service does

Tejas connects to your accounting system — QuickBooks Online or Xero — and builds management reports (Monthly Trial Balance, Profit & Loss, and Balance Sheet & Cash Flow)

inside your own Excel workbook.

The Service’s access to your accounting system is read-only. We never create, modify or delete any record in QuickBooks Online or Xero.

2. Information we collect

2.1 Account and sign-in data

  • Email address

  • Display name, where you provide one

  • Account status and role (for example, whether an administrator has approved your access)

  • Sign-in request records, including the IP address and browser user-agent from which a sign-in link was requested

  • Session records

We use passwordless sign-in. We do not store passwords. Sign-in links and session tokens are stored only as irreversible hashes.

2.2 Accounting connection data

When you connect QuickBooks or Xero, The Services store:

  • Your Quickbooks or Xero user identifier

  • The QuickBooks or Xero company identifier

  • The company name

  • OAuth access and refresh tokens, encrypted at rest

2.3 Reporting configuration

  • Your chart of accounts — account codes, account names and accounting types

  • The management-reporting categories you assign to those accounts

  • Any standing instructions you save for the mapping or analysis assistants

2.4 What we do not store

Trial balance figures and the financial statements built from them are not retained on our servers. They are retrieved from your accounting system when you request a report, passed through to the add-in, and written into your own Excel workbook, which stays under your control.

We do not collect payment or billing information. We do not use advertising or behavioural-tracking technologies.

3. How we use your information

  • To authenticate you and maintain your session

  • To connect to your accounting system on your instruction and retrieve the data needed for the reports you request

  • To store your reporting configuration so your mappings persist between sessions

  • To operate, secure and troubleshoot the Service

We do not send marketing email, display advertising, or sell or rent personal data.

4. Accounting system data

4.1 QuickBooks Online

When you connect a QuickBooks Online company, the Service reads only:

Company information: company name and financial year start

Chart of accounts: account codes, names and types

Trial Balance report: for the periods you request

Each QuickBooks authorisation covers a single company. If you work with more than one company, each is connected separately.

The Service issues no request that creates, modifies or deletes anything in your QuickBooks company.

4.2 Xero

When you connect Xero, the Service requests only read-only permissions. The scopes granted are `accounting.reports.read` and `accounting.settings.read`, together with `openid`,

`email` and `offline_access` for sign-in and session renewal. No write permission is requested, so the Service is incapable of altering your Xero data.

Within those permissions the Service reads:

Organisation details: organisation name and financial year end

Chart of accounts: account codes, names and types

Reports: Trial Balance, Profit & Loss, Balance Sheet and Bank Summary, for the periods you request

A single Xero authorisation may grant access to more than one organisation. You choose which organisation a workbook is bound to, and the Service reads only from the organisation

you have selected.

4.3 Common to both

Data read from your accounting system is used solely to produce reports for you, in your own workbook. It is never disclosed to any other customer or user of the Service.

A connection belongs to the individual who authorised it. No other user of the Service, including our administrators, can access your accounting data through the application.

5. Service providers (sub-processors)

We use the following providers to operate the Service. We do not sell, rent or share personal data with third parties for their own commercial purposes.

Microsoft Azure (UK South)

Purpose: Application hosting, database storage, encryption-key management

Scope: All data described in Section 2

Microsoft 365 / Microsoft Graph

Purpose: Sending sign-in emails

Scope: Your email address only. No accounting data.

OpenAI

Purpose: Optional AI features (Section 6)

Scope: Only the data described in Section 6, and only when you use those features

Anthropic

Purpose: Optional AI features (Section 6)

Scope: Only the data described in Section 6, and only when you use those features

6. Optional AI features

The Service includes two optional, assistant-style features. They are never invoked automatically. No data is sent to an AI provider unless you open one of these assistants

and submit a request, and the core reporting functions of the Service — connecting to your accounting system and producing your Trial Balance, Profit & Loss and Balance Sheet & Cash Flow — make no AI calls at all. You can use the Service in full without any data being sent to an AI provider.

Mapping assistant. When you submit an instruction, we send your account list (account codes, names, accounting types and current reporting categories) together with your

instruction. No balances or transaction amounts are included. Suggestions are advisory and nothing changes in your workbook until you accept them.

Analysis and insights. When you ask a question about data in your workbook, we send the relevant table values from that workbook along with your question, and return a written

commentary.

We never include authentication credentials or OAuth tokens in any request to an AI provider. AI output is never written back to your accounting system.

7. Retention and deletion

We retain your account and reporting configuration for as long as your account is active.

Disconnecting your accounting system. You can disconnect QuickBooks Online or Xero at any time from within the add-in. When you do, the Service immediately stops accessing that company and the connection is marked revoked.

Deleting your account. You may request deletion of your account and associated data by writing to privacy@rulydata.com. We will action the request within 30 days.

You can revoke this application's access at any time from within QuickBooks Online itself, under Apps → Connected apps, independently of anything you do in the Service.

8. Security

  • All traffic to the Service is over HTTPS; TLS 1.2 is the minimum accepted version

  • OAuth tokens are encrypted at rest using AES-256-GCM

  • Encryption keys and application secrets are held in Azure Key Vault, never in source code

  • Session and sign-in tokens are stored only as SHA-256 hashes

  • Access to your accounting data is scoped to your own user account

No system is completely secure, and you are responsible for the security of the email account used to receive sign-in links.

9. Children's privacy

The Service is not intended for anyone under 13. We do not knowingly collect personal data from children under 13, and will delete any such data promptly if we become aware of it.

10. Your rights

Under the UK GDPR and EU GDPR, you have the right to access the personal data we hold about you; request its correction or deletion; object to or restrict our processing; request portability; and lodge a complaint with the UK Information Commissioner's Office.

Under the CCPA, California residents have the right to know what personal data is collected, to request access to and deletion of it, and to opt out of its sale. We do not sell personal data.

Under CalOPPA, we disclose our identity and contact details (Section 12), what information is collected and how it is used, and that you may request changes to your data using the contact details below.

11. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last Updated" date above. Material changes affecting how your accounting data is handled will be notified to you within the Service.

12. Contact us

Privacy enquiries: privacy@rulydata.com

Product support: support@rulydata.com

Ruly Data Ltd

Privacy Request

Scottish Provident Building

7 Donegall Square West

Belfast BT1 6JH

United Kingdom