Privacy Policy & Security Architecture
1. Irrevocable Zero-Model-Training Guarantee
Closeloop explicitly warrants and guarantees that Customer Financial Data — including general ledger account names, journal entries, trial balances, transaction descriptions, vendor invoices, employee payroll lines, and banking feeds — is NEVER used to train, retrain, fine-tune, or validate any public, multi-tenant, or third-party artificial intelligence or machine learning models. All processing occurs within dedicated tenant-isolated runtimes.
2. Scope & Processing Role
This Privacy Policy governs the collection, processing, storage, and transfer of data by Closeloop Technologies Inc. ("Closeloop," "we," "us," or "our") through our continuous financial close platform, application programming interfaces (APIs), and website (closeloop.online).
Under the European Union General Data Protection Regulation (GDPR) and the UK Data Protection Act, Closeloop acts strictly as a Data Processor on behalf of our enterprise customers, who act as the Data Controllers. Under the California Consumer Privacy Act (CCPA) as amended by the CPRA, Closeloop functions as a certified Service Provider.
3. Cryptographic Standards & Technical Security
Closeloop enforces multi-layered defense-in-depth security engineered for corporate treasuries and regulated financial institutions:
- Encryption in Transit: All data transmissions between customer ERPs, banking networks, and Closeloop APIs are encrypted using Transport Layer Security (TLS) 1.3 with Perfect Forward Secrecy (PFS) and strict HSTS policy.
- Encryption at Rest: All stored database clusters, transaction graphs, audit logs, and document caches are encrypted using Advanced Encryption Standard (AES) 256-bit encryption with automated key rotation.
- Customer-Managed Encryption Keys (CMEK): Enterprise subscribers may supply their own AWS KMS or Google Cloud KMS cryptographic keys to maintain absolute cryptographic control over their stored ledger records.
- Zero Permanent Bank Credentials: Closeloop connects to financial institutions exclusively via read-only Open Banking OAuth tokens (Plaid, SWIFT MT940, or direct treasury APIs). We never store or log bank account login credentials.
4. Information We Collect and Process
In delivering continuous reconciliation and variance analysis services, Closeloop processes the following data categories:
- General Ledger & ERP Records: Chart of accounts, trial balances, journal entries, posting dates, account codes, debits, credits, and currency denominations.
- Sub-Ledger Transaction Data: Accounts payable vouchers, vendor names, accounts receivable invoices, payment terms, and PO matching lines.
- Treasury & Bank Statement Lines: Bank statement transaction IDs, settlement timestamps, deposit/wire amounts, and remittance reference tokens.
- Administrative Account Data: Name, corporate email address, role, IP address, and multi-factor authentication tokens of authorized finance staff.
5. Sub-Processors & Infrastructure Boundaries
Closeloop maintains a strict vetting protocol for infrastructure sub-processors. All production data is hosted in SOC 2 Type II and ISO 27001 certified data centers located in the United States (AWS us-east-1) and European Union (AWS eu-central-1 Frankfurt) with geographic data residency pinning available for Enterprise accounts.
| Sub-Processor | Service Purpose | Data Transferred | Hosting Region |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud compute, RDS Postgres, KMS encryption | Encrypted customer databases | USA / Germany (Pinned) |
| Plaid Technologies | Treasury bank feed API connection | Encrypted read-only statement lines | USA |
| Datadog Inc. | Infrastructure observability & APM | System performance logs (scrubbed) | USA |
6. GDPR, UK DPA & CCPA Data Rights
In accordance with applicable privacy frameworks, authorized customer personnel and individual data subjects maintain comprehensive rights:
- Right to Access & Portability: Export all ledger reconciliation workpapers, flux memorandums, and audit logs in structured, machine-readable formats (JSON/CSV) at any time.
- Right to Rectification & Deletion: Request immediate purging of administrative accounts and decommissioned tenant databases upon contract termination.
- Right to Opt-Out of Sale / Sharing: Closeloop does not sell, rent, monetize, or disclose customer financial data or personal information to third parties under any circumstances.
7. Retention & Decommissioning Policy
Customer data is retained for the active duration of the subscription agreement to maintain historical accounting auditability. Upon written contract termination or account closure:
- Customer is granted a 30-day export window to download complete audit binders.
- Within 60 calendar days of contract expiration, all customer database partitions, graph indexes, and cryptographic keys are cryptographically shredded and overwritten in compliance with NIST SP 800-88 Rev. 1 guidelines.
- A formal Certificate of Data Destruction signed by our Chief Information Security Officer will be issued upon request.
8. Data Protection Officer & Contact Inquiries
For security questionnaires, SOC report access, Data Processing Addendum (DPA) execution, or privacy inquiries, please contact our Information Security and Compliance team directly:
Enterprise Support Team: support@closeloop.online