Privacy policy
This policy explains how personal data is handled in the Merlon service (merlon.schotteniuspartners.com) and on this website (www.merlon.se).
1. Who is responsible
The Merlon service is operated by Schottenius & Partners AB (org.nr 556673-1898), registered in Sweden at Norrgatan 10, 432 41 Varberg (“we”, “us”). We act as the data controller for the processing described in this policy.
Where Merlon processes personal data on behalf of a customer organization using the service, that organization may instead be the controller and we act as its processor under a data processing agreement.
Questions about this policy or about your personal data: merlon@schotteniuspartners.com.
2. What data we process
Account and sign-in data
Users sign in with their work account, through their organization's sign-in (single sign-on). From that sign-in we receive and store your name, work email address(es), and your organization identifiers. If you link several work email identities to one Merlon account, each linked identity is stored.
Receipt and expense data
Receipts you submit (as photos, uploaded files, or emails) are stored together with the details extracted from them: supplier, date, amounts, VAT, currency, and similar bookkeeping fields. Receipts are associated with the user who submitted them and the company they belong to.
Transaction data from connected services
When an organization connects its accounting system, company-card provider, or bank, Merlon syncs financial data from those services: booked accounting data, card transactions (which can identify the card holder), and bank account transactions and balances. This data is used for receipt matching and finance reporting.
Email data
Email reaches Merlon in two distinct ways, handled differently:
-
Forwarding addresses. Each user has personal
receipts@merlon.seforwarding addresses. Emails sent to such an address, including attachments, are stored and processed as receipts. Mail from an unknown sender is held in a visible review queue until a person accepts or rejects it; rejected mail is discarded. - Connected mailboxes (optional). A user can choose to connect their work mailbox for automatic receipt detection. When a mailbox is connected, Merlon checks the sender and subject of incoming email against a list of known suppliers. If an email matches, it is captured and stored as a receipt. Emails that do not match are not stored by Merlon. Connecting a mailbox is always the user's own, explicit choice, made through their mail provider's consent flow, and a connected mailbox can be disconnected at any time.
Technical data
Like most web services, we keep technical logs (such as IP addresses, timestamps, and events in the service) for operating and securing the service. This website (www.merlon.se) is a static site and sets no cookies and uses no analytics. The application at merlon.schotteniuspartners.com uses only strictly necessary session cookies for sign-in.
3. Why we process it, and on what legal basis
- Providing the service
- Receiving receipts, extracting their details, matching them to transactions, producing finance reports, and exporting finished bookkeeping to the accounting system. Legal basis: performance of a contract with the user's organization and our legitimate interest in operating the service for the organizations that use it (Article 6(1)(b) and (f) GDPR).
- Automatic receipt detection in connected mailboxes
- Detecting supplier invoices in a mailbox the user has chosen to connect, as described in section 2. Legal basis: the user's consent (Article 6(1)(a) GDPR), given via the mailbox connection flow. Disconnecting the mailbox withdraws the consent.
- Bookkeeping and legal obligations
- Receipts and accounting records are part of the organization's statutory bookkeeping material. Legal basis: compliance with legal obligations (Article 6(1)(c) GDPR), including retention requirements under the Swedish Bookkeeping Act.
- Security and operations
- Logging, abuse prevention, troubleshooting, and keeping the service available and secure. Legal basis: our legitimate interest (Article 6(1)(f) GDPR).
4. Who processes data on our behalf
We use a small number of service providers (processors/subprocessors):
- Amazon Web Services (AWS): hosting and storage. The service runs in the EU (AWS region eu-north-1, Stockholm).
- OpenAI: automated extraction of receipt details (supplier, date, amounts, VAT) from submitted receipt images, documents, and receipt emails. See section 6 on international transfers.
In addition, data flows to and from the services an organization itself connects: its accounting system, company-card provider, bank, and identity/mailbox provider. Each of those providers processes data under its own agreement with the organization and its own privacy terms; Merlon exchanges data with them only as needed to provide the service the organization has connected.
We will update this policy if the list of service providers changes.
5. How long we keep data
- Receipts and bookkeeping-related data: kept for seven years, in line with the retention requirements for accounting material under the Swedish Bookkeeping Act.
- Account data: kept while the account is active, then deleted or anonymized within 90 days after the account is closed, except where longer retention is legally required.
- Held-for-review email that is rejected: deleted within 30 days after rejection.
- Technical logs: kept for 30 days.
6. International transfers
The service is hosted in the EU (AWS eu-north-1, Stockholm). The use of OpenAI for receipt data extraction may involve transferring personal data to the United States. Such transfers are made subject to appropriate safeguards, such as the EU Standard Contractual Clauses and, where applicable, the provider's certification under the EU–U.S. Data Privacy Framework.
7. Your rights
Under the GDPR you have the right to:
- request access to the personal data we hold about you;
- have inaccurate data corrected;
- have data erased, where the law allows it (note that bookkeeping material must be retained for its statutory period);
- restrict or object to processing based on legitimate interest;
- receive data you have provided in a portable format;
- withdraw consent at any time where processing is based on consent, for example by disconnecting a connected mailbox.
To exercise these rights, contact merlon@schotteniuspartners.com. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY, www.imy.se) or your local supervisory authority.
8. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the service, and the “Last updated” date above always reflects the current version.