Privacy policy
How Unapprove handles your data. Last updated 2026-09-21. This policy covers the service at https://unapprove.atesensoftware.com.
This policy is written to describe what the software actually does. It has not yet been reviewed by a lawyer, and it will be before the paid launch.
Who we are
Unapprove is operated by Samet Ateşen, trading as Atesen Software, Sakarya, Türkiye ("we", "us"). You can reach us at support@atesensoftware.com.
What we collect
- Account data. Your name, email address and Xero user ID, received from Xero when you sign in.
- Organisation data. The organisation name, its tenant ID, and the settings a job needs to be safe — for example the period lock dates.
- Access tokens. The OAuth tokens issued by Xero, stored encrypted with AES-256-GCM.
- Document data. The invoices and bills you select are read through the Xero API while a job runs. A snapshot of each processed document (its header and lines, never its attachments) is stored encrypted for 30 days, so that you can download a backup and so that an interrupted job can be resumed.
- Job logs. Document IDs, numbers, actions and results, kept for 12 months so that you have an audit trail.
- Billing data. Handled by Stripe. We do not see or store full card numbers.
- Technical logs. IP address and request logs, for security, kept for 30 days.
What we do not do
We do not sell your data, use it for advertising, or use it to train AI models. We do not store your attachments: files are streamed from the original document straight to the new draft and are not written to our disks.
Why we process it
To provide the service you signed up for (contract), to keep that service secure and working (legitimate interest), and to meet our legal and tax obligations (legal obligation).
Service providers
- Railway — application hosting and the database.
- Stripe — payments.
- [transactional email provider — to be confirmed before launch] — account and job emails.
They process your data only on our instructions.
International transfers
Our providers may process data outside the country you are in. We rely on the contractual safeguards those providers offer.
Retention and deletion
- When you disconnect an organisation, its stored tokens are deleted immediately.
- Document snapshots are deleted within 30 days.
- Job logs are kept for 12 months, then deleted.
- Technical logs are kept for 30 days.
- You can ask us to delete your account and its logs at any time, and we will do so within 30 days.
- If your subscription ends, we disconnect your organisation after 7 days.
Security
Tokens and snapshots are encrypted at rest. Everything travels over HTTPS. We request the narrowest set of API permissions the job needs, and our own admin accounts use two-factor authentication. If we become aware of a breach affecting your data, we will notify you and Xero promptly.
Your rights
Depending on where you are — for example under the GDPR and UK GDPR, the Australian Privacy Act, the New Zealand Privacy Act, or Türkiye's KVKK — you may ask for access to your data, correction of it, deletion of it, or a copy of it in a portable form. Email support@atesensoftware.com from the address on your account and we will answer within 30 days. If you are not satisfied, you may complain to your local data protection authority.
Children
Unapprove is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes to this policy
We will post updates on this page and change the "last updated" date above. If a change is material, we will email you about it before it takes effect.
How to ask us something
Email support@atesensoftware.com. The support page explains what to include so that we can answer on the first reply.