SpendMedic is designed around data minimisation. Xero passwords are never collected. Accounting data is requested from Xero when required for analysis and is not intentionally archived as a second permanent ledger. We retain account data, encrypted OAuth tokens, minimal findings, recovery workflow records and audit records needed to provide and secure the service.
Depending on your connections, this can include invoice totals, supplier/contact information and payment metadata supplied by Xero, plus the account information you provide to SpendMedic.
To operate SpendMedic, detect potential spend issues, create recovery workflows, maintain security and provide support.
Provider tokens are encrypted with a server-side key and passwords are hashed. Production use also requires managed backups, monitoring, access controls and independent security review.
Customers can disconnect provider access. Before commercial launch, this policy should be reviewed for the final legal entity, contact details, subprocessors and UK GDPR obligations.