DATA PRIVACY & SECURITY PROTOCOLS

Privacy Policy

Effective Date: May 13, 2026  ·  Last Updated: August 15, 2026

Our Core Privacy Principle

Nexora Software Solutions operates Nexora Accbot on a strict zero-monetization data policy. We do not sell, rent, license, or monetize your accounting ledgers, invoices, customer directories, or financial balances. Your data belongs exclusively to your business organization and is used solely to execute your accounting workflows.

01.Information We Collect

To provide multi-tenant cloud accounting, automated financial statements, cheque tracking, and secure invoice generation, we collect the following categories of information:

Account & Tenant Profile Information

When you register a workspace, we collect your full name, business name, business registration number, corporate email address, phone number, physical address, and password hash (one-way encrypted via BCrypt with adaptive cost factor).

Accounting & Operational Financial Data

Financial records entered by your authorized team members, including Sales Invoices, Purchase Orders, General Ledger Journal Entries, Chart of Accounts, Bank Accounts, Supplier & Customer Directories, Cheque Serial Numbers, Maturity Dates, and Transport Ledger Bills.

Payment & Billing Transaction Metadata

Subscription order numbers, currency, payment reference IDs, receipt tokens, and uploaded bank transfer deposit slips. Full credit/debit card numbers are captured and tokenized exclusively by certified payment gateways (PayHere, PayPal) and are never stored on Nexora servers.

Security & Audit Trail Telemetry

IP addresses, browser client headers, session tokens, login timestamps, and immutable audit logs recording creation, modification, and deletion of financial transactions to preserve forensic data integrity.

02.How We Use Your Data

  • Executing Core Accounting Calculations: Generating real-time Balance Sheets, Trial Balances, Profit & Loss statements, General Ledger postings, and Cheque status feeds.
  • Multi-Tenant Isolation & Authorization: Validating tenant boundary constraints so that users only access records belonging strictly to their registered business workspace.
  • Subscription Management & Invoicing: Generating automated PDF subscription tax receipts, processing renewals, and activating workspace service tiers.
  • Security Protection & Fraud Prevention: Identifying suspicious login spikes, unauthorized API token manipulation, or breach attempts.
  • Customer Support: Investigating reported bugs or ledger synchronization discrepancies at your explicit request.

03.Multi-Tenant Architecture & Data Security

We implement enterprise-grade technical and organizational security controls designed specifically for multi-tenant financial SaaS applications:

TLS Encryption in Transit

All data transmitted between your browser and our cloud servers is encrypted using modern TLS/HTTPS protocols (TLS 1.2 or higher, as negotiated by the hosting infrastructure).

Tenant-Scoped Isolation

Database queries enforce automatic, strict tenant-scoping middleware to prevent cross-tenant data leakage.

Encrypted Backups

Daily incremental and weekly automated snapshots are vaulted in georedundant, encrypted cloud storage.

Role-Based Security

Granular permission matrix prevents unauthorized staff from viewing sensitive ledgers or settings.

04.Third-Party Sub-Processors & Infrastructure

We partner with industry-leading infrastructure and payment partners to deliver the Service. These partners have access to data solely to perform designated services:

  • Cloud Hosting & Database Providers: Enterprise cloud infrastructure hosting encrypted database clusters and microservices.
  • Payment Processing Partners: PayHere and PayPal process payment card authorizations and subscription tokenization under strict PCI-DSS Level 1 compliance.
  • Transactional Mail Delivery: Dedicated transactional SMTP relays for delivering password resets, subscription receipts, and security alerts.

05.Data Retention, Export & Account Deletion

We retain your accounting records for as long as your workspace maintains an active subscription or archived status.

Data Export Rights: At any time, Organization Owners can export their financial records, invoices, ledgers, and trial balances in CSV, Excel, and PDF formats.
Permanent Workspace Purge: If you close your account and request permanent data eradication, your tenant database records will be permanently purged within thirty (30) days, subject to mandatory legal accounting retention obligations under Sri Lankan tax statutes.

06.Your Rights & Privacy Choices

Subject to applicable data protection laws, you retain the right to:

  • Access and review all personal and organization information held by Nexora Accbot.
  • Rectify inaccurate business profile records or contact emails.
  • Request full deletion of your user profile and workspace credentials.
  • Revoke user authorizations or cancel active subscription billing.

To exercise any of these privacy rights, please submit a written request to our Data Protection Officer at support@mail.nexorasoftwaresolution.com.

07.Cookies & Local Storage

Nexora Accbot uses essential cookies and browser local storage strictly for platform functionality. We do not use third-party tracking, advertising, or analytics cookies.

NameTypePurposeDuration
accessTokenHttpOnly CookieAuthenticates your session securelyShort-lived (server-controlled)
refreshTokenHttpOnly CookieEnables silent session renewal without re-loginUp to 14 days (if Remember Me)
accbot_last_activityLocal StorageTracks last activity timestamp for inactivity timeoutUntil logout
accbot_remember_meLocal StorageStores your session duration preferenceUntil logout
accbot-themeLocal StorageRemembers your dark/light mode preferencePersistent
accbot_permissionsLocal StorageCaches role-based UI permissions for your sessionUntil logout

These storage mechanisms are strictly necessary for the Service to function and cannot be disabled without breaking core authentication and user experience features.

08.Data Breach Notification

In the unlikely event of a data breach that compromises your personal or financial information, Nexora Software Solutions commits to notifying affected users within seventy-two (72) hours of confirmed discovery via email and in-platform notification.

Our notification will include: (a) the nature and scope of the breach; (b) the categories of data affected; (c) the corrective measures taken; and (d) recommended actions for affected users. We will also notify relevant regulatory authorities where required by applicable law.

09.Contact Our Privacy & Security Team

Data Controller

Nexora Software Solutions

Nexora Accbot Data Governance

Privacy Inquiries
support@mail.nexorasoftwaresolution.com

Attn: Data Protection Officer

Physical Office

Kandy

Sri Lanka · WhatsApp: +94 77 232 3941

Desktop Device Required

Nexora AccBot is optimized for desktop viewports. To securely perform double-entry bookkeeping, general ledger adjustments, and manage transport invoices, please log in using a desktop computer or wider tablet device.

Viewport: < 1280x720px