Privacy Policy

Last updated: August 31, 2026

This policy explains how we collect, process, and protect your personal data, in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and, for the UK entity, the UK GDPR and Data Protection Act 2018.

1. Data Controller

Which Onetribe entity controls your data depends on which site or service you used.

For this website (cfoupgrade.com), onetribeadvisory.com, and services contracted with the UK entity:

ONETRIBEADVISORY LTD Company number 13151758, incorporated and registered in the United Kingdom Registered office: 71–75 Shelton Street, London, Greater London, WC2H 9JQ, United Kingdom Email: support@onetribeadvisory.com

For onetribe.sk, onetribe.cz and onetribe.pl, and services contracted with the EU entity:

Onetribe s.r.o. Daxnerovo nám. 4, 821 08 Bratislava, Slovak Republic Email: support@onetribeadvisory.com

Either entity will accept a request under this policy and route it to the right controller. You do not need to work out which one applies before contacting us.

2. Data We Collect

2.1 Data you provide directly

  • Full name
  • Email address
  • Phone number
  • Company name and registration number
  • Billing information

2.2 Data collected automatically

  • IP address and browser type
  • Website usage data (cookies, analytics)
  • Technical access logs for the platform

2.3 Data processed within the platform

  • Client ERP system data (Pohoda, Helios, Money ERP, and others)
  • Analytics outputs and reports generated by the platform
  • User queries and interactions with the AI analyst

2.4 Correspondence you send us

  • The content of emails, form submissions and documents you send us, and our replies

3. Purposes of Processing

We process your personal data for the following purposes:

PurposeLegal Basis
Contract performance and service deliveryArt. 6(1)(b) GDPR
Invoicing and accountingArt. 6(1)(c) GDPR
Communication and customer supportArt. 6(1)(b) GDPR
Correspondence handling, including AI-assisted triage and draftingArt. 6(1)(f) GDPR — see §4
Website analyticsArt. 6(1)(a) GDPR (consent)
Protection of legitimate interestsArt. 6(1)(f) GDPR

4. Correspondence, and where we use AI

When you email us, use a form on this site, or send us a document, we treat your message as business correspondence: we log it in our standard systems, route it to the right person, keep a record of what was said, and answer it.

Some of that handling uses AI tools — to summarise long threads, classify and route messages, extract action points, and draft replies for a person to review. A person reads and sends every reply. Nothing you send us gets an answer that a human has not approved.

Legal basis: legitimate interests, Art. 6(1)(f) GDPR — and Art. 6(1)(b) where your message concerns a contract with us, or steps taken before entering one.

We do not ask you to consent to this, and sending us an email is not treated as consent. Consent has to be a free and specific choice, and you have no real choice about whether we read a message you have already sent us. Relying on legitimate interests instead puts the burden on us: we have to justify the processing, tell you how it works, and stop if you object.

4.1 Our legitimate interests assessment

Legitimate interests is not a label a company gets to assert. It requires an assessment, and we think you should be able to read the result rather than take our word for it.

The interest we are pursuing. Running a professional services business: understanding what is sent to us, answering it accurately and quickly, keeping a reliable record of what was agreed, and protecting our systems from misuse.

Why the processing is necessary. We cannot answer correspondence without processing it. The narrower question was whether using AI to help is proportionate, or whether the same result is reasonably available a less intrusive way. It is not: the volume, and the range of languages across the markets we serve, mean the realistic alternative is slower and less consistent handling with more missed detail — not less processing of your data.

The balance, and what we changed because of it. Our interest does not automatically outweigh yours. We considered what someone sending us a message would reasonably expect, and what could go wrong, and we constrained how we work in five ways:

  • The tools cannot learn from your message. We use business and enterprise tiers under agreements that contractually exclude the use of our data to train models.
  • No decisions about you are made by a machine. AI drafts and summarises; people decide and reply. There is no automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR.
  • Recruitment is excluded entirely. If you send us a CV or a job application, it is read by a person. We do not use AI to screen, score or evaluate candidates.
  • Special category data is excluded. If a message contains health, trade union, religious, biometric or similar data, that content is kept out of AI tools. Please do not send us such data unless we have asked for it.
  • We keep correspondence only as long as we need it — see §7.

Your right to object. You can object at any time under Art. 21(1) GDPR on grounds relating to your particular situation. If you want your correspondence kept out of AI tools specifically, email support@onetribeadvisory.com with “no AI processing” in the subject line and we will handle it manually. This is separate from, and does not limit, your right to object to the processing as a whole.

4.2 Client data inside the platform is different

Everything above concerns correspondence sent to Onetribe. Data inside the platform — your ERP and accounting data — is processed under your service agreement and the data processing agreement attached to it, where we act as your processor and you determine what happens to it. Where the platform’s AI layer reads your governed model, it does so under those terms and within your own environment. We do not add AI processors to your data without your agreement.

4.3 The AI tools we use

  • Anthropic (Claude) — business tier, under a data processing agreement, with model training on our data contractually excluded. Transfers outside the EEA are covered by standard contractual clauses under Art. 46 GDPR.
  • OpenAI models deployed within our own Microsoft Azure environment. The models run inside our Azure tenant, so Microsoft is the processor and your data is not sent to OpenAI. Training on our data is contractually excluded.

4.4 AI literacy

Under Art. 4 of the AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744), we support the development of AI literacy among the people who operate these tools on our behalf. Our staff are briefed on what the tools may and may not be used for, and on the limits set out above.

5. Data Security

Your data is protected in a secure Microsoft Azure environment with enterprise-grade standards:

  • Entra ID — identity and access management
  • Encryption — data encrypted in transit (TLS) and at rest (AES-256)
  • MFA — multi-factor authentication
  • GDPR — full compliance with European data protection regulations
  • ISO 27001 — information security standards

6. Data Sharing

We never sell your personal data, and we do not disclose it to third parties for their own purposes. We share it only with:

  • Infrastructure providers: Microsoft Azure (data processor within the EU)
  • AI tool providers: as named in §4.3, under Art. 28 data processing agreements
  • Accounting and legal services: to the extent necessary for legal compliance
  • Public authorities: when required by law

Your ERP data processed within the platform is used solely to generate analyses for you. It is never sold or disclosed to third parties for their own purposes, and it is handled only by us and by the processors named in this policy, acting on our instructions or yours.

7. Data Retention

  • Contractual data: for the duration of the contract and 5 years after termination
  • Correspondence: 24 months from our last contact with you. Correspondence forming part of a contract follows the contractual rule above
  • Accounting documents: 10 years in accordance with accounting legislation
  • Website analytics data: 26 months
  • Platform ERP data: for the duration of the subscription; deleted within 30 days after termination

8. Your Rights

Under the GDPR, you have the right to:

  • Access — obtain information about what data we process about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your data
  • Restriction of processing — limit how we use your data
  • Data portability — receive your data in a structured format
  • Object — object to processing based on legitimate interest, including the AI handling described in §4
  • Withdraw consent — withdraw consent at any time (e.g., cookies)

To exercise your rights, contact us at support@onetribeadvisory.com .

You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner’s Office; in Slovakia, the Office for Personal Data Protection.

9. Cookies

Our website uses cookies for proper functionality and traffic analytics. You can review and configure cookie preferences via the cookie banner displayed on your first visit.

10. Changes to This Policy

We reserve the right to update this policy. We will notify you of material changes via email or a notice on our website.

11. Contact

If you have questions about the protection of your personal data:

ONETRIBEADVISORY LTD 71–75 Shelton Street, London, Greater London, WC2H 9JQ, United Kingdom Company number 13151758

Onetribe s.r.o. Daxnerovo nám. 4, 821 08 Bratislava, Slovakia

Email: support@onetribeadvisory.com Phone: +421 910 830 235