Building this screen.
Building this screen.
Verity, a product of Settiq Labs Ltd
Last updated: 20 July 2026
Effective: 20 July 2026
Verity is a product operated by Settiq Labs Ltd, a company registered in England and Wales (company number 17202827), whose registered office is at 773 Melton Road, Thurmaston, Leicester LE4 8EE, United Kingdom.
In this policy, "we", "us" and "our" mean Settiq Labs Ltd. "You" means a user of Verity, and "your organisation" means the business on whose behalf you use it.
If you have any question about this policy or about how we handle data, contact us at info@settiq.co.uk.
We have not appointed a Data Protection Officer, as we are not required to do so.
Verity reads a business's bank transaction data, classifies each transaction into an expense category, and sets out how that category is treated under the US federal tax code, citing the relevant authority for each determination. Where the system is not confident, it flags the transaction for a person to review rather than deciding on its own.
Verity does not prepare or file tax returns, does not provide tax advice, and does not present its output as authoritative. Every determination it produces is marked as pending professional review. Verity does not initiate payments, move funds, or access your accounts for any purpose other than reading the data described below.
We act as a data controller in respect of account data: the details you give us when you create and use an account.
We act as a data processor in respect of the financial data your organisation connects, processing it on your organisation's instructions for the purposes described in this policy. Your organisation is the controller of that data and determines why it is processed.
Account data, collected directly from you. When you create an account we collect your name, email address, and the name of your organisation. If you sign in with Google, we receive your name, email address, and the fact that Google has verified that address. We do not receive or store your Google password.
Financial data, obtained from your bank through Plaid. When you connect a bank account through Plaid, we receive:
The source of this data is your bank or financial institution, transmitted to us by Plaid Inc. We do not receive or store online banking credentials at any point. Plaid handles the connection to your bank and provides us with an access token, which we hold in encrypted form.
Transaction records may contain the names of individuals your organisation has paid or been paid by. We did not obtain that information from those individuals directly. It reaches us from your organisation's bank records.
Usage data. We collect basic technical information generated when you use the service, including sign-in events and the review decisions you make within the product.
We do not collect special category data as defined by UK GDPR, and Verity is not designed to receive it. Please do not upload or enter it.
| Purpose | Lawful basis under UK GDPR |
|---|---|
| Providing the service: classifying transactions and deriving tax treatment | Performance of a contract |
| Authenticating you and securing your account | Legitimate interests (keeping the service secure) |
| Responding to your support requests | Performance of a contract |
| Improving classification accuracy within your own organisation's data | Legitimate interests (improving a service you use) |
| Meeting our legal and accounting obligations | Legal obligation |
On improving the service. When someone at your organisation corrects a classification, Verity uses that correction to improve how it classifies similar transactions for your organisation only. Corrections made by one customer are not used to classify transactions for any other customer, and are not used to train any third-party model.
Where we rely on legitimate interests, these are the interests concerned.
For security: our interest in preventing unauthorised access to financial data, protecting our customers from account compromise, and maintaining the integrity of a system that holds sensitive commercial information. We consider this proportionate because the processing is limited to authentication events and access logs, and because the alternative, an unsecured system, would cause our customers substantially greater harm.
For accuracy improvement: our interest in providing a service that becomes more useful the longer it is used, and our customers' interest in not correcting the same misclassification repeatedly. We consider this proportionate because corrections are used only within the organisation that made them, are limited to classification behaviour, and involve no profiling of individuals.
Providing your name, email address and organisation name is a contractual requirement. Without it we cannot create an account or provide the service.
Connecting a bank account is optional and is a decision for your organisation. Verity has nothing to classify without it, so the service will not produce results, but no other consequence follows from declining.
We do not sell your data. We do not share it for advertising. We share it only with the service providers below, each of whom processes it on our instructions under a written agreement.
| Provider | What they process | Why | Where |
|---|---|---|---|
| Plaid Inc. | Your bank connection and the transaction, liability and investment data it returns | To connect your accounts and retrieve data. Plaid's own privacy policy governs their handling of your information. | United States |
| Neon Inc. | All stored application data | Database hosting | United Kingdom |
| Netlify Inc. | Traffic to and from the application | Application hosting | United States |
| Google LLC | Your name, email address, and verification status | Sign-in, only if you choose to sign in with Google | United States |
| OpenAI, L.P. | A redacted subset of transaction data. See section 9. | Classifying transactions the deterministic rules cannot resolve | United States |
We may also disclose data where we are legally required to, or to establish or defend legal claims.
This section matters more for Verity than for most services, because automated classification is what the product does. So we want to be precise about it.
Verity proposes. People decide.
Every transaction is classified automatically in the first instance. Around seven in eight are resolved by deterministic rules, which apply fixed logic rather than prediction. The remainder are referred to a language model for a suggested category. Each classification is then mapped to a US federal tax treatment, with the statutory authority cited.
No determination Verity produces is treated as final. Every one is presented to a person at your organisation for review, and is marked as pending professional review until they act on it. A person can approve, correct, or reject any determination. Once a person has made a decision, the system cannot overwrite it. This is enforced at the database level, not merely as a matter of policy.
Where the system cannot reach a confident conclusion, it flags the transaction for human attention rather than guessing.
We therefore do not make decisions about individuals based solely on automated processing, and we do not carry out profiling. The processing classifies business expenditure, not people. It produces no legal effect on any individual and nothing similarly significant. If that ever changes, we will tell you before it does, and set out your rights under Article 22 of the UK GDPR.
Roughly one transaction in eight cannot be resolved by Verity's deterministic rules. For those, and only those, we send a reduced description to OpenAI to obtain a second opinion on the category.
Before anything is sent, we remove the transaction amount and any account identifier. The model receives a description of the merchant or counterparty and enough context to suggest a category. It does not receive amounts, account numbers, balances, your organisation's name, or the identity of any individual.
OpenAI does not train on data submitted through its API. Inputs may be retained by OpenAI for up to 30 days for abuse monitoring before deletion. We have disabled all data sharing options available to us on our OpenAI account.
The model's suggestion is never applied automatically to anything a person has already reviewed, and never overrides a human decision.
Application data is stored in the United Kingdom.
Four of the providers named above, Plaid, Netlify, Google and OpenAI, process data in the United States. The United States does not benefit from a general UK adequacy decision. These transfers are made under the International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018, or under the equivalent International Data Transfer Agreement, together with a transfer risk assessment.
You can obtain a copy of the safeguards in place for any of these transfers by emailing info@settiq.co.uk. We will provide it within one month.
If we add a provider processing data in another country, we will update this section before that processing begins.
No system is perfectly secure and we do not claim otherwise. If we become aware of a breach affecting your personal data, we will notify the Information Commissioner's Office within 72 hours where required, and will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
We keep your account data for as long as your organisation has an account with us.
We keep financial and decision data for seven years after the end of your relationship with us. This period reflects the record retention expected in connection with US tax positions, and supports the auditability that the service is designed to provide.
When you disconnect a bank account, we stop retrieving new data from it immediately and revoke the access token.
If you are in the UK, you have the right to:
To exercise any of these, email info@settiq.co.uk. We will respond within one month and will tell you if we need longer. There is no charge.
Separately from the rights above, you have the right to object at any time to processing we carry out on the basis of legitimate interests. Those purposes are identified in the lawful basis section. If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or that the processing is necessary for legal claims. To object, email info@settiq.co.uk and say what you are objecting to.
You can complain to the Information Commissioner's Office at any time, and you do not need to raise it with us first, though we would prefer the chance to put things right. The ICO can be reached at ico.org.uk, by telephone on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Our customers are US businesses, and most of the data we handle is business information rather than consumer personal information. Where US state privacy law does apply to you, you may have the right to know what personal information we collect, to request its deletion, to have it corrected, and not to be discriminated against for exercising those rights.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use it for targeted advertising or for any profiling that produces legal or similarly significant effects.
To make a request, email info@settiq.co.uk. We will verify your identity before acting, and will respond within the period required by your state's law.
Settiq Labs is not a financial institution and is not a consumer reporting agency. We do not furnish or use consumer reports.
One thing you should know about erasure. Verity's decision records are append-only by design: this is what makes every classification auditable and is central to what the product does. When you ask us to erase your data, we do not silently keep it. We render it permanently unrecoverable by destroying the keys required to read it and removing all identifying content, while leaving the structural record that a decision occurred. The result is that your data cannot be recovered by us or by anyone else, but the integrity of the audit chain is not broken.
Where we are required by law to retain certain records, we will tell you which, and why, rather than erasing them silently.
Where backups exist, erased data may persist in point-in-time restore history for up to 6 hours, after which it is unrecoverable. This history is encrypted and access to it is restricted.
Verity uses only the cookies necessary to keep you signed in and to keep the service secure. Because these cookies are strictly necessary, no consent is required and there is nothing to opt out of.
Verity is a business product and is not directed at anyone under 18. We do not knowingly collect data from children.
If we make a material change, we will tell you by email or in the application before it takes effect. The date at the top of this page shows when it was last revised.
Settiq Labs Ltd
773 Melton Road, Thurmaston, Leicester LE4 8EE, United Kingdom
info@settiq.co.uk