Privacy notice
Last updated 7 October 2026.
Who is responsible
Daybook Capture is used by bookkeeping and accounting firms to collect and check their clients' receipts and invoices. The firm decides what is uploaded and why, so for those documents the firm is the controller and Daybook Capture processes them on its behalf. For the accounts people use to sign in, Daybook Capture is the controller.
Questions about this notice: info@kadiryaz.com. Questions about a business's own documents are best sent to its bookkeeper first.
What we hold
- Sign-in details: your email address and, if you turn it on, a two step verification factor.
- Firm and client details entered by the firm, such as names, company and VAT numbers and contact emails.
- Uploaded receipts and invoices, and the details read from them: supplier, dates, amounts, VAT and line items. These can include names and other personal details printed on a document.
- An audit log of who did what and when, such as signing in, viewing, approving and exporting.
We do not use advertising or analytics trackers. The only cookies are the ones that keep you signed in.
Why we use it
- To provide the service the firm signed up for: reading, checking and exporting documents (contract).
- To keep accounts and documents secure and to investigate misuse, using the audit log (legitimate interests).
- To keep business records for as long as UK tax rules expect (legal obligation, through the firm).
- To find and fix faults, using error reports from which email addresses, amounts and document contents are removed (legitimate interests).
Where it is stored and who processes it
Data is stored in the United Kingdom. We use a small number of service providers, each under a contract that only lets them process data on our instructions:
- Hosting, database and file storage (United Kingdom).
- Reading documents with AI (United States). Each document is sent only to be read and is not used to train models.
- Scheduling background work (United States). It receives internal references only, never document contents.
- Error monitoring (European Union).
- Sending sign-in codes and invitations by email (European Union).
Sending documents to the United States for reading is covered by the safeguards UK law requires for international transfers, set out in a data processing agreement. Firms using Daybook Capture can ask us for these providers by name, and are told before one is added or replaced.
How long we keep it
Each firm sets how long documents are kept, 6 years by default, counted from the end of the financial year a document belongs to. After that the document, its file and the details read from it are deleted automatically. A firm can delete a client, or all of its data and its members' accounts, at any time. Deleted data is not kept in the app, and database backups roll over within 7 days.
Your rights
Under UK data protection law you can ask for a copy of your data, ask for it to be corrected or deleted, object to how it is used, and ask for it in a portable format. Firms can download all data held about a client, and delete it, from the app. If you are not happy with how your data is handled, you can complain to the Information Commissioner's Office at ico.org.uk.
Security
Each firm's data is kept apart at the database level. Files are private and opened only through links that expire within minutes, after an access check. Sign-in uses one-time email codes, and two step verification is available to everyone. Every view, change and export is recorded in the firm's audit log.