GDPR Compliance
Last Updated: September 10, 2026 Version: 1.4
This page explains how Incremenza handles personal data for European users and business customers under the General Data Protection Regulation. It is written for business owners evaluating whether Incremenza is appropriate for their European operations. It is not legal advice.
If you need a signed Data Processing Agreement for your organization, see our Data Processing Addendum or write to [email protected].
1. Who this page is for
If you are a business in the EU or EEA using Incremenza to process financial data that includes personal data about your customers or employees, this page explains the legal basis for that processing and what your options are.
If you are an individual whose data appears inside an Incremenza account belonging to a business you deal with, see Section 8 for how to exercise your rights.
2. Our role under GDPR
GDPR distinguishes between the party that decides why data is processed (the controller) and the party that processes it on the controller's instructions (the processor). Incremenza is both, depending on the data.
Where Incremenza is the controller
For your account information, your team's details, your billing records, and how you use the product, we decide the purposes and means of processing. We are the controller.
Where Incremenza is the processor
For personal data about your customers, contacts, and employees, which arrives in Incremenza through your connected integrations or through data you upload, you decide what happens to it. You are the controller and we are the processor.
Our Data Processing Addendum governs that relationship and contains the Standard Contractual Clauses.
Why this matters in practice. If one of your customers asks to have their data erased, that request belongs to you, not to us. We provide the tools to act on it and we will assist, but you make the decision. Section 8 explains how we handle requests that come to us directly.
3. Legal bases for processing
Where Incremenza acts as controller, we rely on these bases.
Performance of a contract, Article 6(1)(b). Providing the Service you subscribed to, managing your account, and billing you.
Legitimate interests, Article 6(1)(f). Securing the platform, preventing fraud and abuse, improving the product, and communicating with existing customers about the service they use. We balance these interests against your rights and document that assessment.
Legal obligation, Article 6(1)(c). Meeting tax, accounting, and financial record-keeping requirements.
Consent, Article 6(1)(a). Optional marketing communications only. You can withdraw consent at any time without affecting your use of the Service.
Where Incremenza acts as processor, the legal basis is determined by you as controller. We process only on your documented instructions.
4. Where your data is stored
Customer Data is stored on servers in the United States, operated by DigitalOcean.
Product usage analytics are stored in the European Union, in Frankfurt, Germany.
Storing customer data in the United States means personal data of European individuals is transferred outside the European Economic Area. For those transfers we rely on Standard Contractual Clauses approved by the European Commission, together with the corresponding UK International Data Transfer Addendum and the Swiss adequacy mechanism.
Standard Contractual Clauses are binding contractual commitments requiring us to protect personal data to GDPR standards regardless of where it is processed. They are contained in our Data Processing Addendum.
We also carry out supplementary measures as recommended by the European Data Protection Board, including encryption in transit and at rest, strict access controls, data minimization before transferring anything to third-party providers, and a commitment to challenge any government request for your data that we believe is unlawful and to notify you where legally permitted.
If your organization requires all data to be stored within the EU, contact us at [email protected] so we can discuss what is possible.
5. Sub-processors
We engage a limited number of third-party providers to help deliver the Service. Each is bound by a written agreement imposing data protection obligations at least as protective as those we owe you.
The complete, current list is published at incremenza.com/legal/sub-processors, showing what each provider does, what data it handles, where it is located, and the transfer mechanism that applies.
We publish this as a live page rather than a static table so that it cannot drift out of date.
Notice and objection
We give at least 30 days' notice before a new sub-processor begins processing personal data. Notice goes by email to account administrators and the page is updated.
If you object on reasonable data protection grounds, write to [email protected] within the notice period. We will work with you to find a resolution. If we cannot, you may terminate your subscription and receive a refund of prepaid fees for the unused portion of your term.
6. Data minimization and automated features
Some features use machine learning models operated by Google and Anthropic. We apply data minimization before anything leaves our systems:
- Personal details such as addresses and phone numbers are removed from merchant names
- Only aggregated financial summaries are sent for insight generation, never individual transaction records
- Account numbers, card numbers, and credentials are never sent
- Most transaction classification happens through internal matching, so external models are the last step rather than the first
We use paid enterprise tiers under agreements that prohibit training on customer data. Neither provider retains your data beyond the duration of the request.
7. Data retention
| Data | Retention period |
|---|---|
| Account and business data, while subscribed | Duration of your subscription |
| Account and business data, after cancellation | 90 days, then permanently deleted automatically |
| Data from disconnected integrations | Kept while your account remains open, so your historical records stay intact. Deleted when your account is closed |
| Billing and tax records | 7 years, to meet financial record-keeping obligations |
| Support communications | 2 years |
| Product usage analytics | Up to 12 months |
| Security and authentication audit records | 2 years |
| Backups | Up to 90 days before being overwritten |
| Aggregated, anonymized statistics | Kept indefinitely. This contains no information that identifies any person or organization |
Deletion after the 90-day window is automatic, carried out by a scheduled process, not by manual request. You receive advance notice by email before it happens.
One narrow exception. A record that someone unsubscribed from email is kept even after the related contact is deleted, limited to the email address, reason, and date. Without it, a re-imported contact could start receiving email again despite having opted out. This is a legitimate interest in honoring a prior objection, and it is a smaller intrusion than the alternative.
Faster erasure on request. Write to [email protected]. We complete erasure requests within 30 days.
8. Your rights
If you are in the EEA, the UK, or Switzerland, you have the following rights.
Access. Obtain confirmation of whether we process your personal data and receive a copy of it.
Rectification. Have inaccurate or incomplete personal data corrected.
Erasure. Have your personal data deleted in the circumstances set out in Article 17.
Restriction. Have processing limited in the circumstances set out in Article 18.
Portability. Receive your personal data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. An Admin on your account can export the company's data at any time from Settings, under "Export company data," delivered as structured CSV files. If you need a copy of your own personal data specifically, write to [email protected].
Objection. Object to processing based on legitimate interests, and object to direct marketing at any time with no exceptions.
Not to be subject to solely automated decisions producing legal or similarly significant effects. Incremenza does not make such decisions. Automated scores and guidance in the product are informational and are always reviewed by a person before any action is taken.
How to exercise them
Write to [email protected]. We respond within 30 days, as required by Article 12. We may need to verify your identity, which protects you against someone else making a request in your name.
There is no charge, and exercising a right will never result in different treatment.
If your data sits in an account belonging to one of our customers, that business is the controller and your request belongs to them. Contact them directly. If you contact us, we will tell you so promptly and assist that business in responding.
Complaints
If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. We would appreciate the opportunity to address your concern first.
9. Security
Our security measures are described in full on our Security page and in Annex II of our Data Processing Addendum. In summary: encryption in transit and at rest, backups encrypted at rest with additional independent redundancy, strict isolation of each organization's data at the database query level, multi-factor authentication required for every user, with phishing-resistant passkeys required for administrators and managers, logged staff access, and automatic removal of sensitive values from error reports.
Breach notification. If a personal data breach affects data we process for you, we will notify you without undue delay and within 48 hours of becoming aware of it, giving you time to meet your own obligation under Article 33.
10. Data protection contact
We have not appointed a Data Protection Officer, and we are not required to. Our processing is not large-scale systematic monitoring, and we do not process special categories of data at scale. Data protection inquiries are handled directly by our leadership team.
Incremenza LLC
2108 N ST STE N Sacramento, CA 95816 United States
We aim to respond to data protection inquiries within 5 business days, and to formal data subject requests within 30 days.
This page is provided for information and does not constitute legal advice. For binding commitments, see our Data Processing Addendum and Terms of Service.