Solvent
Early accessPrivacySign in
DRAFT — pending legal review. Not yet legally binding.

Legal

Privacy Policy

How RHND Innovations GmbH processes personal data when you visit or use Solvent.

Last updated: 2026-07-13

This Privacy Policy explains how Solvent processes personal data when you visit our website, create an account, use the Solvent application, or connect optional integrations. It is designed for the EU General Data Protection Regulation (GDPR), including the information duties in Articles 13 and 14.

1. Who We Are

Solvent is operated by RHND Innovations GmbH ("Solvent", "we", "us").

Contact: [FOUNDER TO CONFIRM: legal/privacy contact email] VAT ID: ATU79789114 Supervisory authority: Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, Austria

RHND Innovations GmbH is established in the EU, so no Article 27 EU representative is required. A Data Protection Officer need-assessment is kept under review as the service scales. Until a DPO is appointed, privacy requests should be sent to [FOUNDER TO CONFIRM: legal/privacy contact email].

2. Our Roles

Solvent has two different GDPR roles, depending on the data.

RoleWhat It CoversWhat It Means
ControllerYour account, login, billing, audit, support and product-security dataWe decide why and how this data is processed.
ProcessorBusiness data you enter about your own customers, subscribers, suppliers, client companies, invoices, costs and bank transactionsYou are the Controller. We process this data on your documented instructions under our Data Processing Agreement.

For accountants, corporate service providers and practices, your client companies remain your clients. Solvent provides the technical workspace; it does not become the accountant of record, tax filer, payroll provider or statutory representative.

3. Personal Data We Process

Data CategoryExamplesPurposeLegal Basis
Account and authentication dataName, email, password hash, login metadataCreate accounts, authenticate users, keep the service secureContract, GDPR Art. 6(1)(b); legitimate interests, Art. 6(1)(f)
Workspace and entity dataCompany name, addresses, VAT numbers, role assignments, practice/client-entity linksProvide the multi-company finance workspace and access controlsContract, Art. 6(1)(b)
Business finance dataSubscribers, suppliers, invoices, costs, payments, bank transactions, tax calculations, planning dataDeliver invoicing, reconciliation, reporting, planning and advisory finance workflowsContract, Art. 6(1)(b); as Processor where this includes your customers' personal data
Audit and security logsUser ID, organisation/entity ID, action, timestamp, IP/device metadata where availableSecurity, fraud prevention, tenant isolation, abuse detection, support and incident investigationLegitimate interests, Art. 6(1)(f)
Billing dataPlan, subscription status, invoice reference, billing contact, Stripe customer referenceManage trials, subscriptions, invoices, payment status and tax recordsContract, Art. 6(1)(b); legal obligation, Art. 6(1)(c)
Support and feedbackMessages, diagnostics you submit, feature requests, attachments you choose to provideResolve issues, answer requests, improve the productContract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f)
Product telemetryPseudonymous usage events, feature adoption, error and performance dataKeep the service reliable and improve onboarding and product qualityLegitimate interests, Art. 6(1)(f), unless consent is required for a particular tool

We ask you not to enter special-category personal data into Solvent unless you have a lawful basis to do so and it is necessary for your own records. Solvent is not designed to process health, biometric, genetic, political, religious or similar special-category data.

4. Optional Features

The following processing only happens if you enable the relevant feature.

FeatureWhat HappensLegal Basis / Control
AI assistantRelevant prompt context may be sent to Anthropic Claude or another configured AI provider so the assistant can answer questions or draft proposed actions. The assistant is advisory and requires human approval for write actions.Consent, Art. 6(1)(a), or your own provider contract if you bring your own key. You can disable the feature.
Billing via StripeStripe processes payment and subscription data when you subscribe to a paid plan.Contract, Art. 6(1)(b).
Accounting and bank integrationsXero, QuickBooks Online, Wise, Payoneer or similar providers exchange data you authorise through OAuth or API keys. Tokens are encrypted at rest.Consent or contract, depending on the integration. You can disconnect integrations.
Marketing emailsWe send product or commercial updates only where permitted or with consent.Consent, Art. 6(1)(a), or legitimate interests for limited B2B communications where permitted.
Non-essential analytics or trackingWe may use analytics, attribution or monitoring tools only after the required consent mechanism is in place.Consent where required under ePrivacy rules.

Exchange-rate lookups through Frankfurter / ECB do not send personal data.

5. AI, Automation and Tax Outputs

Solvent is a finance operations tool. It helps you prepare, reconcile, project and understand your data, but it does not file tax returns and it does not replace your accountant or tax adviser.

The AI assistant and finance engines are advisory. They may produce drafts, classifications, explanations, forecasts, tax-threshold warnings or suggested actions. They do not make solely automated decisions with legal or similarly significant effects under GDPR Article 22. Write actions require meaningful human approval, and filings remain your responsibility.

We maintain privacy and risk assessments for AI features where required, including DPIA review as processing scale, feature scope or risk changes.

6. Recipients and Sub-processors

We use service providers to host and operate Solvent. Core sub-processors are used for all accounts; optional sub-processors are used only when you enable a feature. The current list is maintained in our Sub-processor List.

Core providers include hosting, authentication and database infrastructure. Optional providers include AI, billing, accounting, bank-feed and support integrations.

We require sub-processors to process personal data under appropriate contractual terms. Where we act as your Processor, sub-processor use is governed by the Data Processing Agreement.

7. International Transfers

Some providers may process personal data outside the EEA, including in the United States or the United Kingdom. Where personal data is transferred outside the EEA, we rely on one or more of the following safeguards:

  • an adequacy decision, including the EU-US Data Privacy Framework where the

recipient is certified;

  • the European Commission's Standard Contractual Clauses;
  • supplementary contractual, organisational or technical measures where needed.

You may request more information about the transfer mechanism for a specific provider by contacting [FOUNDER TO CONFIRM: legal/privacy contact email].

8. Retention

We keep personal data only as long as needed for the purpose for which it was processed, unless a longer retention period is required by law.

DataTypical Retention
Account dataFor the life of the account, then deleted or anonymised within a reasonable period after closure.
Business finance dataFor the life of the workspace or entity, then exported, deleted or anonymised according to the account closure flow and legal-retention limits.
Statutory bookkeeping and billing recordsRetained for applicable accounting and tax periods. The exact period depends on the record type and governing law.
Audit and security logsKept for security, integrity, abuse-prevention and dispute purposes, then deleted or anonymised.
Support requestsKept while needed to resolve the request and maintain a support history, then deleted or anonymised.
Optional AI and integration dataRetained according to Solvent settings, provider terms and any legal-retention requirement that applies to the underlying business record.

If you request erasure, we delete data unless we must keep it for legal obligations, legal claims, security, audit integrity or another lawful exception.

9. Your Rights

Under the GDPR, you may have the right to:

  • access your personal data;
  • correct inaccurate personal data;
  • delete personal data;
  • restrict processing;
  • object to processing based on legitimate interests;
  • receive a portable copy of your data;
  • withdraw consent where processing is based on consent;
  • complain to the Austrian Datenschutzbehörde or another competent supervisory

authority.

You can use the in-app account area to export data and submit erasure requests. You can also contact [FOUNDER TO CONFIRM: legal/privacy contact email]. We may need to verify your identity before acting on a request.

Where Solvent acts as Processor for data controlled by one of our customers, we will redirect or assist the relevant customer unless the law requires us to respond directly.

10. Security

Solvent is designed for multi-tenant financial data. Our measures include:

  • per-organisation access scoping and tenant isolation;
  • role-based permissions for workspaces and entities;
  • encryption in transit;
  • encrypted storage of OAuth tokens and AI provider keys;
  • audit logging for sensitive actions;
  • least-privilege operational access;
  • backups and recovery procedures;
  • monitoring, incident response and abuse detection.

No system is perfectly secure, but we work to protect the confidentiality, integrity and availability of the service.

11. Children

Solvent is a business finance product and is not directed at children. Do not create an account for a child or intentionally submit children's personal data.

12. Changes

We may update this Privacy Policy as the service, providers, law or product features change. The latest version will be posted with a new "Last updated" date. Material changes will be notified in-app or by email where appropriate.

13. Contact

For privacy questions or requests, contact:

RHND Innovations GmbH [FOUNDER TO CONFIRM: full street address] 1170 Vienna, Austria [FOUNDER TO CONFIRM: legal/privacy contact email]

14. Current Sub-processors

We use the following providers to operate Solvent. Optional services are only used when the relevant feature is enabled or consented to.

ProviderPurposeStatus and control
SupabaseDatabase and authenticationCore service provider.
Anthropic and OpenAIOptional AI assistanceOff by default and consent-gated. AI proposes; a human approves.
StripeBilling and payment processingDormant until paid billing launches.
ResendTransactional email deliveryUsed for service communications.
VercelApplication hosting and deliveryCore hosting provider.
UpstashRate limiting and abuse preventionStrictly necessary security processing.
AWS KMSEncryption key managementUsed to protect encrypted integration credentials.
Wise and PayoneerCustomer-initiated transaction importOnly when a customer connects the service using their own key.

[FOUNDER TO CONFIRM: each provider's current legal entity, processing location, DPA status, retention and final production inventory.]

15. International Transfer Basis

Where personal data leaves the EEA, we rely on the EU-US Data Privacy Framework where the recipient is certified. We use the European Commission's 2021 Standard Contractual Clauses, normally Module 2 for controller-to-processor transfers, as a documented fallback together with supplementary measures where needed.

The Data Privacy Framework remains valid at the date of this draft, but a CJEU appeal challenging it was filed on 31 October 2025. We therefore retain the SCC fallback rather than relying on the Framework alone. [FOUNDER TO CONFIRM: transfer assessments and provider certifications before publication.]

16. Austrian Statutory Retention

Financial, bookkeeping and billing records may need to be retained for Austrian statutory periods that are commonly around seven years under § 132 BAO and § 212 UGB. [FOUNDER TO CONFIRM: the final retention schedule by record type and jurisdiction.]

17. Complaints to the Austrian Data Protection Authority

You may lodge a complaint with the Österreichische Datenschutzbehörde (DSB), Barichgasse 40–42, 1030 Wien, Austria, by email at dsb@dsb.gv.at or through www.dsb.gv.at.

18. UK GDPR Addendum

For people in the United Kingdom, references to the GDPR include the UK GDPR and the Data Protection Act 2018 where applicable. You may complain to the Information Commissioner's Office. International transfers may rely on the UK extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, as applicable.

[FOUNDER TO CONFIRM: whether an Article 27 UK representative is required and, if so, its identity and contact details.]

19. United States Privacy Addendum

For California residents, Solvent does not sell personal information and does not share personal information for cross-context behavioural advertising. [FOUNDER TO CONFIRM: CCPA/CPRA applicability, request channels, verification procedure and final “sell/share” assessment.]

Solvent
ImprintPrivacyTermsCookies

© 2026 RHND Innovations GmbH