Legal

Privacy policy

Last updated 30 August 2026 Applies to vatasystems.com and Vata Assembly

This policy explains what Vata Systems collects, why, how long it is kept, and what you can ask us to do with it. It is written to be read, not to be survived.

The short version

We hold your account details, a read-only copy of the QuickBooks Online records needed to plan a build, and a permanent record of every build we made for you. We do not sell anything, we do not advertise, and we do not use your accounting data to train models. You can disconnect QuickBooks Online at any time, and you can ask us to delete your workspace.

01Who we are

Vata Systems ("we", "us") provides Vata Assembly, a web application that automates assembly builds for businesses using QuickBooks Online. We are the controller of the personal data described in this policy.

Our postal address is 5245 Ramsey Way #8, Fort Myers, FL 33907, United States.

Questions, requests and complaints: use the privacy request form.

02What this covers

This policy covers the vatasystems.com website and the Vata Assembly application. It does not cover QuickBooks Online itself, which is operated by Intuit under Intuit's own privacy policy. Connecting the two does not make us responsible for what happens inside your QuickBooks Online company.

03What we collect

Account and workspace data

The name, work email address and assigned role of each person you invite, plus the settings your workspace holds: build policies, schedules, rounding rules, unit conversions and account mappings. Authentication is by email and password; passwords are stored only as salted hashes and are never recoverable in readable form.

QuickBooks Online data

When you connect a company, we read and store a working copy of:

  • Items, accounts and vendors — the directory we match your assembly components against.
  • Inventory valuation detail — the report we rebuild cost layers from before a build.
  • Transactions we created — read back after posting to confirm what landed.
  • Company metadata — the company identifier and the company's own current date.

This is business record data. It is not intended to contain personal data, but vendor records commonly hold an individual's name, email address, telephone number and address, so in practice some personal data is present and this policy applies to it.

Records the service creates

Every build produces a permanent record: the plan, the approvals and who signed them, the accounting evidence captured before and after posting, the identifiers of the transactions created, and the outcome. Automation runs produce a similar record per night. These records exist so that a build can be explained after the fact, and several of them cannot be edited or deleted once written — see retention and deletion.

Technical data

Server logs recording request paths, timestamps, response status, and the account acting. Logs are filtered to strip credential-bearing fields — tokens, passwords, cookies and the QuickBooks company identifier — by field name, before they are written.

This website

The marketing site has no analytics, no advertising trackers and no cookies. Typefaces and every other asset are served from this domain, so loading a page contacts nobody else.

Cloudflare delivers this site for us, so it necessarily receives the IP address and request details of anyone who loads a page. That is an ordinary consequence of serving a website rather than a choice to collect anything, and we do not join it to anything else or use it to build a profile.

The early-access request is a Google Form, hosted by Google and opened in a new tab. It asks for your name and work email, and optionally your company, what you assemble, and roughly how many items are in your QuickBooks Online company. Responses go to a private Google Sheet in our own Google Workspace. We use them to contact you about early access and for nothing else: no newsletter you did not ask for, no sale, no sharing with anyone.

The form does not require you to sign in to Google, and we have not enabled the option that records a responder's Google account. What Google itself collects when you load the form is covered by Google's privacy policy.

Ask us at any point to delete an early-access enquiry and we will remove the row. Unlike the build records described above, this data is ordinary and deletable.

04How we use it

  • To operate the service — plan builds, run the nightly lane, post to QuickBooks Online, and show you what happened.
  • To keep an auditable record of every action taken on your behalf.
  • To authenticate people and enforce the role each one holds.
  • To diagnose faults, and to contact you about incidents, changes and — while you are in early access — how the product is working for you.
  • To meet legal and tax obligations, and to establish or defend legal claims.

We do not sell personal data, share it for cross-context behavioural advertising, or use your QuickBooks Online data to train machine-learning models.

05Legal bases

Where UK or EU data protection law applies, we rely on: performance of a contract for operating the service; legitimate interests for security, fault diagnosis, audit records and service-related communication; and legal obligation where we must keep or produce records. Where we rely on legitimate interests you may object, and we will stop unless we have compelling grounds to continue.

06Your QuickBooks Online connection

The connection is made through Intuit's OAuth 2.0 flow. You sign in at Intuit; we never see your Intuit credentials. You choose which company to connect, and you can revoke the connection from inside QuickBooks Online or from our settings screen at any time.

Access tokens are held in memory only. The refresh credential is stored encrypted. Every request we send is scoped to the single company you connected, and the application refuses to act if the company identifier it sees does not match the one it was authorised for.

What disconnecting does

Disconnecting immediately revokes our access and stops all automation for that company. Transactions we already created stay in your QuickBooks Online company — they are your accounting records and only you can change them. The working copy of your item, account and vendor data is deleted within 30 days. Build records and accounting evidence are retained as described below, because they are the record of postings that exist in your books.

07Who else sees it

We use a small number of processors, each bound by contract to act only on our instructions:

Processors used by Vata Systems
ProcessorPurposeLocation
Amazon Web ServicesApplication hosting, database, encrypted object storageUnited States (us-east-1)
IntuitThe QuickBooks Online company you connectUnited States
CloudflareDNS, website delivery, and mail routing for our vatasystems.com addressesUnited States
Google Workspace and Google FormsEarly-access enquiries from this website, and our own emailUnited States

We will also disclose data if legally compelled, and we will tell you first unless we are prohibited from doing so. If the business is acquired, your data may transfer as part of it; the buyer remains bound by this policy until you are notified otherwise.

08Retention and deletion

Different records have different lifetimes, and one category is deliberately permanent.

Retention periods by data category
CategoryKept for
Account and workspace settingsLife of the workspace, then 30 days
Working copy of QuickBooks Online directory dataUntil disconnect or workspace deletion, then 30 days
Build records, approvals and accounting evidence7 years from the build date
Server logs90 days
Early-access enquiries from this website24 months, or until you ask us to delete it

Please read this one

Approvals, attempts, outcomes and accounting evidence are append-only. The database itself refuses to update or delete them, and that refusal is the point: it is what makes the record trustworthy to an auditor. Corrections are made by appending a new entry, never by editing history.

A consequence follows. If you ask us to erase personal data that appears inside a build record — the name of the person who approved a posting, for example — we cannot surgically remove it and leave the record intact. What we can do is delete the workspace and everything in it. Where erasure is a legal right, we will honour it by deleting the whole record rather than pretending we can edit part of it.

On workspace deletion, all data is removed from live systems within 30 days and from encrypted backups within 90 days. The periods in the table above are how long we keep each category while the workspace exists — deleting the workspace ends them early, including the seven-year one. The only thing that overrides this is a legal obligation to retain a specific record, such as a tax requirement or a preservation order. Where that applies we keep only what we are required to keep, only for as long as we are required to keep it, and we use it for nothing else.

09Security

  • Encrypted in transit (TLS) and at rest.
  • Accounting evidence is encrypted per object and bound to its storage address, so a file moved or renamed will not decrypt.
  • Every evidence record is content-addressed with a SHA-256 digest and rejected if payload and digest disagree.
  • Approvals, attempts, outcomes and evidence are append-only at the database level, enforced by the database rather than by application code.
  • Access is role-gated. Evidence is readable only by Accountant and Auditor seats; the exception queue only by Operators.
  • The application's own database accounts hold no superuser rights and cannot disable those protections.

What we do not claim

Vata Systems holds no SOC 2 report, ISO 27001 certificate or equivalent third-party attestation, and has not completed an external penetration test. We would rather tell you that than let a page of security vocabulary imply otherwise. If your procurement process requires an attestation, talk to us before you rely on the product.

10Your rights

Depending on where you live, you may have the right to access, correct, delete, port or restrict use of your personal data, to object to processing, and to withdraw consent. Residents of California, Colorado, Connecticut, Utah, Virginia and other US states with their own consumer privacy statutes have equivalent rights, including the right not to be discriminated against for exercising them.

Use the privacy request form, which asks only for what we need to find your data and act on it. We respond within 30 days and will not charge you for a reasonable request. Because most of the data we hold belongs to a business customer, we may direct your request to the workspace administrator where they are the controller.

If you are in the UK or EU and we have not resolved your concern, you may complain to your supervisory authority.

11International transfers

We process data in the United States. Where data is transferred from the UK or EU, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with technical measures including encryption in transit and at rest.

12Children

Vata Assembly is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.

13Changes

We will post any change here and update the date at the top. If a change materially reduces your rights or materially expands how we use your data, we will email workspace administrators at least 30 days before it takes effect.

14Contact

Use the privacy request form for anything in this policy, or the support form for everything else. We publish forms rather than email addresses so that neither fills up with scraped spam.