Privacy Policy
What Isletek holds, why we hold it, who else sees it, and how long it stays. Written to be read rather than skimmed past.
Last updated 25 August 2026.
Who is responsible for what
Isletek provides Isletek.
Two different relationships sit inside one product, and it is worth separating them:
- For your business data — invoices, products, prices, stock, suppliers, claims — you are the data controller and we are your processor. We handle it on your instructions, to run the service.
- For your account and our own records — the names and email addresses of people who sign in, billing details, support conversations, security logs — we are the controller.
What we hold
- People who use Isletek: name, email address, role, and either a password (stored only as a cryptographic hash) or a link to your Google or Microsoft sign-in. A profile picture if your sign-in provider supplies one.
- Supplier paperwork: invoice and credit-note PDFs and the figures read from them — supplier, date, invoice number, products, quantities, prices, VAT and totals.
- Your shop's trading data: products, barcodes, costs, shelf prices, stock levels, sales history read from your till, promotions, suppliers, orders, claims and the resulting credit notes.
- Credentials for systems you connect: supplier portal logins, mailbox access, and accounting-software authorisations. These are encrypted at rest and used only to do the thing you connected them for.
- Email: where you connect a mailbox, we read messages in the folders you nominate to find supplier invoices and price lists, and send email on your behalf to suppliers.
- Photographs and attachments you add — pictures of damaged stock on a claim, product photos, screenshots sent with feedback.
- Activity records: who did what and when, which is what makes the audit trail in the app possible, plus technical logs needed to run and secure the service.
Isletek is a tool for businesses. We do not seek out information about your customers, and the till data we read is about products and sales totals, not shoppers.
Why we hold it
To provide the service you have asked for — that is the legal basis for most of it (performance of a contract). We also rely on legitimate interests to keep the service secure, prevent abuse, fix faults and improve how well invoices are read; and on legal obligation where we must keep records.
Automated reading of invoices
Invoices and supplier price emails are read automatically. Most are handled by our own software. Where the layout defeats it, the document is sent to a third-party AI provider — currently Anthropic or Google — purely to extract the figures printed on it, and the answer comes straight back to us. These providers act as our processors, do not use the content to train their models, and are bound by their agreements with us.
Nothing read this way is acted on by itself. The results are shown to you, and the steps that matter — receiving stock, agreeing a price change, sending a claim, posting to your accounts — need a person. There is no automated decision-making producing legal or similarly significant effects.
What is shared between shops, and what is not
Isletek keeps a shared catalogue of descriptive product facts: barcodes, product names, brands, pack sizes and product photographs, including barcodes staff have taught it by scanning a carton. This is shared across every shop using Isletek, so a product identified once does not have to be identified again.
Commercial information is never shared. What you pay, what you charge, what you sell, your stock, your suppliers, your invoices, your claims and your accounts stay within your business and are not visible to any other shop.
Who else processes it
We use a small number of service providers, each under contract and only for the purpose listed:
- Hosting and databases for the application and its data (in the UK/EU or under equivalent safeguards).
- Anthropic and Google — reading invoices and price emails, as described above.
- Cloudflare — storing invoice PDFs, photographs and product images.
- Email delivery, for notifications and the messages you send to suppliers.
- Intuit (QuickBooks) — where you connect it, so purchases can be posted to your accounts.
- Google and Microsoft — where you sign in with them, or connect a mailbox.
We do not sell personal data, and we do not share it for advertising. Where a provider is outside the UK, transfers are covered by adequacy regulations or standard contractual clauses.
QuickBooks
If you connect QuickBooks, Isletek uses that connection to do one thing: create bills and vendor credits in your company from invoices and credit notes you have already checked, and read the accounts, vendors and VAT codes it needs to post them correctly. It requests accounting access only.
We store the authorisation token — encrypted — and the identifier of the company you chose, so the connection keeps working. We do not read your customers, employees, payroll or bank feeds. Disconnecting in Settings revokes our access immediately; bills already created stay in your books, because they are your records.
How long we keep it
Business records — invoices, claims, stock movements and the audit trail — are kept for as long as you use Isletek, because they are the history of your trading and you may need them for VAT and accounting purposes. Original invoice PDFs are kept for the period agreed with you.
When your account closes we delete or anonymise your business data within a reasonable period on request, other than what we must keep by law, or what has entered the shared descriptive catalogue described above — which contains no commercial or personal information. Technical logs are kept for a short period and then discarded.
Keeping it safe
Access is restricted by role, so people only see what their job needs. Credentials and tokens are encrypted at rest, traffic is encrypted in transit, and access to production systems is limited to those who need it. The connector that reads your till runs on your own computer and makes only outbound connections — nothing is opened up to the internet on your premises.
If a breach occurs that is likely to affect your rights, we will tell you and the ICO within the time the law requires.
Your rights
Where we are the controller, you can ask for a copy of your personal data, ask us to correct or delete it, object to or restrict how we use it, or ask for it in a portable form. Where we are your processor, we will help you answer a request someone makes to you.
Write to privacy@isletek.co.uk. If you are unhappy with how we have handled it you can complain to the Information Commissioner's Office at ico.org.uk.
Cookies
Isletek uses only what it needs to work: a stored sign-in token to keep you logged in, and local storage for your own preferences and for work-in-progress on a device — an unfinished goods-in count, for example. No advertising or cross-site tracking cookies.
Changes
If we change this policy we will update the date at the top, and tell you by email or in the app where the change is significant.