Data Policy — Saturnique Inc.

Effective date: Feb 10, 2026

This Data Policy explains how Saturnique Inc. ("Saturnique", "we", "us", or "our") collects, uses, stores, discloses, and protects data in connection with our services, website, and related products. It applies to clients, prospects, partners, vendors, and visitors ("you" or "your"). We are committed to protecting your privacy and handling your data responsibly and in accordance with applicable data protection laws.

1. Scope & Purpose

Saturnique Inc. provides professional services including Bookkeeping & Cloud Accounting, Financial Analysis & Insights, Process Management & Automation, and Change Management. Our operations inherently involve processing sensitive client and business data. This Policy applies to all data processed in the course of our business activities.

Our purpose is to protect privacy, ensure lawful processing, maintain data security, and support transparent data handling consistent with applicable laws and contractual obligations.

2. Types of Data We Collect

2.1 Personal Data (examples):

  • Contact details: name, email, phone, job title, business address.
  • Identity and verification data: ID numbers, taxpayer IDs, date of birth (when required for payroll or compliance).
  • Financial-related personal data: payroll records, bank account details (for direct deposit), payment transaction details.
  • Usage & technical data: IP address, device identifiers, login metadata, and cookies.
  • Communications: emails, support tickets, meeting notes, and recorded consent.

2.2 Business & Operational Data (examples):

  • Accounting and bookkeeping records: ledgers, invoices, bills, receipts, reconciliations.
  • Transactional data: sales, purchases, vendor records, AR/AP, inventory-related entries.
  • Aggregated and analytical data: KPIs, dashboards, forecasts, models, and derived insights.
  • System integration data: CRM records, ERP extracts, payroll system exports.

2.3 Sensitive Data:

We generally avoid processing special categories of sensitive personal data (e.g., health, racial/ethnic origin, political opinions). If such data is provided or required, we will only process it with explicit client instruction, documented lawful basis, and enhanced protections.

3. Legal Bases for Processing

Where applicable law requires, we process personal data under one or more of these legal bases:

  • Contractual necessity: to perform services under client agreements.
  • Legitimate interests: to operate, improve and secure our business, provided your rights are not overridden.
  • Consent: where required (e.g., marketing communications, cookies).
  • Legal compliance: to comply with laws, tax reporting, audits, or lawful requests by authorities.

Clients remain responsible for ensuring they have lawful bases to share personal data with us where required by law.

4. How We Use Data

We use data to:

  • Provide, maintain, and improve our Services (bookkeeping, cloud accounting, analytics, automations).
  • Configure, integrate, and migrate client systems and data.
  • Communicate with clients, respond to inquiries, deliver reports and invoices.
  • Build dashboards, models, forecasts, and analyses per engagement terms.
  • Ensure security, prevent fraud, and investigate incidents.
  • Meet legal, tax, and regulatory obligations and assist with audits.
  • Conduct aggregated, anonymized analytics to improve our offerings and for marketing (no personally identifiable data unless consented).
  • Send marketing or promotional communications where permitted; recipients may opt out.

5. Data Sharing & Disclosure

We may disclose data to:

  • Service providers and sub processors: cloud hosting, backup, analytics, payment processors, identity verification, and software vendors engaged under contracts that require confidentiality and security.
  • Affiliates and subcontractors engaged to perform parts of an engagement (Saturnique remains responsible).
  • Legal and regulatory authorities when required by law, court order, or to protect rights and safety.
  • Prospective buyers or investors in the event of a merger, acquisition, or sale of assets (with appropriate protections and notice where required).
  • With client consent or at client direction (e.g., sharing with external auditors, banks, or advisors).
  • We do not sell personal data as defined under privacy laws without explicit consent.

6. Cross-Border Transfers

Processing may involve transfers to jurisdictions outside the country of collection, including cloud providers and subcontractors in other regions. We will ensure lawful transfer mechanisms where required (e.g., adequacy decisions, or client-authorized transfers) and maintain appropriate protections.

7. Data Retention & Deletion

  • Retention periods are defined in client agreements or governed by applicable laws (e.g., tax record retention).
  • We retain personal and business data only as long as necessary to fulfil contractual obligations, comply with legal requirements, or meet legitimate business needs.
  • Upon contract termination or at client request (subject to agreed terms), we will delete or return client data within agreed timeframes, except to the extent we must retain data to comply with legal obligations or for legitimate business reasons—upon which we will isolate and protect retained data.

8. Security Measures

We implement reasonable technical and organizational measures appropriate to the risk, including:

  • Access controls and role-based permissions.
  • Encryption in transit (TLS) and at rest where appropriate.
  • Network security, firewalls, and intrusion detection.
  • Regular backups, patch management, and secure development practices.
  • Vendor risk assessments and contractual security obligations for sub-processors.
  • Incident response planning, periodic audits, and staff training.
  • While we use commercially reasonable measures, no system is fully secure. We are not liable for breaches resulting from factors outside reasonable control (e.g., zero-day exploits, sophisticated nation-state attacks).

9. Data Subject Rights

Where applicable, individuals have rights subject to law, including:

  • Access: request copies of personal data we hold about them.
  • Rectification: request correction of inaccurate or incomplete data.
  • Deletion/Erasure: request deletion where lawful basis permits.
  • Restriction: request limitation of processing in certain circumstances.
  • Objection: object to processing based on legitimate interests or direct marketing.
  • Portability: request a machine-readable copy of data provided to us.
  • Withdraw consent: where processing is based on consent.

To exercise rights or submit requests, contact us.

10. Sub-processors & Third Parties

We maintain a list of sub-processors (third-party vendors engaged to process data) and will make it available upon request. We require sub-processors to maintain confidentiality and security commensurate with this policy and applicable law. Clients may object to a new sub-processor for reasonable cause; we will discuss alternatives in good faith.

11. Incident Response & Notification

In the event of a data breach affecting personal data, Saturnique will:

  • Contain and investigate the incident promptly.
  • Notify affected clients without undue delay and provide relevant details and mitigation steps.
  • Where legally required, notify supervisory authorities and affected data subjects within applicable timeframes.
  • Cooperate with client-led investigations and provide reasonable assistance.

12. Changes to This Policy

We may update this Data Policy periodically. Material changes will be posted with an updated "Last updated" date and, when appropriate, notified to clients and users. Continued use after changes indicates acceptance.

Contact Us

If you have any questions or concerns, please contact us.