SweetFA

Privacy Policy

Effective date: 26 April 2026

1. Introduction

Sweet Docs Ltd trading as SWEETFA (“we”, “us”, “our”) is the data controller for the personal data described in this policy. Sweet Docs Ltd is registered in England and Wales under company number 17081987 and is registered with the Information Commissioner's Office under reference ZC104490.

This policy explains how we collect, use, and protect your personal data when you use the SWEETFA invoicing service on web, WhatsApp, or Telegram.

2. Data We Collect

  • Business Details: Business name, address, email, bank details (sort code, account number), VAT number (if applicable), and trade type.
  • Customer Details: Names and addresses of the customers you invoice through our service, plus any email address or phone number you provide when you ask us to deliver an invoice link or related document to that customer.
  • Invoice Data: Line items, amounts, dates, and PDF documents generated through the service.
  • Conversation History: Messages exchanged with our bot via WhatsApp, Telegram, or web chat. For WhatsApp users this specifically includes: your mobile phone number, your WhatsApp profile name, the text content of your messages, any voice notes or images you send, message timestamps, and the delivery metadata Meta includes in the webhook payload.
  • Voice Note Audio: When you send a voice note, the audio is downloaded via the WhatsApp Cloud API Media endpoint, transcribed, and used to generate your document. See Section 5 for retention.
  • Usage Data: How you interact with the service, pages visited, and errors encountered.

2a. Lawful Basis

We process your data under the lawful bases set out in Article 6 of the UK GDPR:

  • Performance of a contract (Article 6(1)(b)) for the core service — receiving your messages, generating documents, delivering invoices, and operating your account.
  • Legitimate interests (Article 6(1)(f)) for minimal product analytics, fraud prevention, and service improvement, balanced against your rights and freedoms.
  • Legal obligation (Article 6(1)(c)) for retaining invoice records to meet HMRC requirements.

3. How We Use Your Data

  • To create and send invoices, quotes, and other documents on your behalf.
  • To store your business details so future invoices are faster.
  • To deliver transactional invoice links and related documents to your named recipients by WhatsApp, email, or SMS when you choose that delivery path.
  • To improve the accuracy and experience of our service.
  • We do not sell your personal data. We share personal data only where needed to run the service, process payments, deliver messages, host infrastructure, and comply with legal obligations.

4. Third-Party Services (Sub-Processors)

We use the following sub-processors to run the service. Each processes personal data only under our instructions and their own contractual data protection terms.

  • Meta Platforms (WhatsApp Business Platform) — message delivery, webhook metadata, business profile hosting, and media storage for WhatsApp users.
  • Telegram FZ-LLC — message delivery for Telegram users.
  • Anthropic — language-model processing of your message content to extract invoice fields (customer, line items, amounts). Inputs are processed transiently and are not used to train Anthropic models.
  • OpenAI — transcription of voice notes via the Whisper API. Audio is sent for transcription and is not used to train OpenAI models.
  • Supabase — secure data storage, database hosting, and authentication.
  • Stripe — payment processing when you purchase credits. Stripe handles your payment details directly; we do not store card numbers.
  • Vercel — application hosting and edge infrastructure.
  • Resend — transactional email delivery (invoices, receipts, account notifications).
  • Twilio and downstream mobile carriers — transactional SMS delivery when a tradesperson asks us to send an invoice link or related document to a recipient phone number.

5. Data Retention

  • Account data — kept for the life of the account.
  • Voice note audio — retained for 30 days after receipt, then deleted. The text transcription is retained with the rest of your message history.
  • Message history (text and transcriptions) — retained on a 12-month rolling basis for service delivery and dispute resolution.
  • Invoice and financial records — retained for 6 years from creation to meet HMRC record-keeping requirements, even after account deletion.
  • After account deletion — personal data is held for up to 90 days in backup and deletion queues before being permanently removed, except where legally required to retain it longer (see invoice records above).
  • Inactive lead accounts (those that never accepted terms) are cleaned up after 90 days of inactivity.

6. Your Rights

Under the UK GDPR you have the following rights:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data (subject to legal retention obligations such as HMRC record-keeping).
  • Restriction — ask us to pause processing of your data in certain circumstances (for example, while you contest its accuracy).
  • Objection — object to processing carried out on the basis of legitimate interests (Article 6(1)(f)).
  • Portability — receive the data you have provided to us in a structured, machine-readable format.
  • Withdraw consent — where we rely on consent as the lawful basis, you can withdraw it at any time without affecting the lawfulness of prior processing.

You can delete your account from Settings or by saying “delete my account” in chat. Full instructions are on our data deletion page. For other requests, email support@sweetdocs.co.uk.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your personal data has been handled unlawfully. Contact the ICO at ico.org.uk or by telephone on 0303 123 1113.

7. Stopping WhatsApp Messages

You can stop receiving WhatsApp messages from SWEETFA at any time by replying STOP in your WhatsApp chat with the SWEETFA business number, or by emailing support@sweetdocs.co.uk. Opting out of WhatsApp messaging does not delete your account — for that, see the data deletion page.

Registered with the ICO - ZC104490.