RemitClear

Security

Effective 27 May 2026 · Version 2026-05-27

An overview of the measures we use to keep your data safe. We are happy to answer specific security questions from prospective and current customers.

What RemitClear holds

RemitClear is an accounts-receivable tool. It reads remittance advices, matches them to invoices in your own accounting system, and records the resulting payments. The data it holds is limited to what that job needs:

  • From your accounting system: open invoices and credit notes, their numbers, amounts and dates, the associated contact name, your bank account list and your base currency. The connection is scoped to those permissions, so payroll and employee records stay out of reach.
  • The remittance documents you upload or forward, retained as supplied so you can audit any payment we recorded against the document it came from. A remittance is retained as you sent it, so it holds whatever is printed on it, which on some documents includes the names of individuals.
  • The data extracted from those documents, which is invoice numbers, amounts, dates, references and the payer name.
  • Your account details: name, email and workspace membership.

RemitClear connects to Xero and QuickBooks Online only. It holds no clinical, care or case-management records, and it connects to no government or sector portal.

Hosting and infrastructure

RemitClear runs on established cloud infrastructure providers that maintain their own physical and network security programmes. Our data and backend services are hosted with Supabase, and the web application is delivered through Vercel. The full list of providers is on our Sub-processors page.

Data location and international transfers

Your database, file storage and backups are held together on AWS infrastructure in Ireland (EU), encrypted at rest and in transit. A small number of sub-processors carry out specific functions from other regions: document extraction runs on an AI provider in the United States under business terms that do not permit your content to be used to train general-purpose models, and our email and billing providers operate from the United States and the EU. Each one, its purpose and its location is listed on our Sub-processors page.

Where personal data is processed outside its country of origin we rely on signed data-processing agreements and Standard Contractual Clauses, and we remain accountable for our sub-processors. For customers in Australia, this is the basis contemplated by Australian Privacy Principle 8, which permits personal information to be held overseas where the discloser takes reasonable steps and stays accountable for it. For customers in the UK and EU, our DPA sets out the equivalent terms.

If your sector or your own compliance obligations require something different from the above, contact privacy@remitclear.com and we will go through your specific requirements with you.

Encryption

Data is encrypted in transit using TLS. Stored data, including uploaded documents, is held by our infrastructure providers with encryption at rest.

Availability

We target 99% monthly availability, excluding planned maintenance and events beyond our reasonable control. Service credits are not offered at current pricing tiers. Customers on bespoke or enterprise contracts can negotiate a separate availability commitment.

Access control and tenant isolation

  • Each customer's data is isolated per workspace and enforced at the database level with row-level security.
  • Accounts support multi-factor authentication, which we recommend enabling, and access within a workspace is governed by roles (owner, admin, member).
  • Our team operates on least-privilege access, and payment posting actions are logged for audit.
  • Connections to your accounting system use authorised OAuth tokens; we never see or store your accounting system password.

AI processing

Document extraction uses an AI provider under business terms that do not permit your content to be used to train general-purpose models. Documents are sent for the purpose of extraction only.

Data retention and deletion

We retain data only as long as needed to provide the Service and meet legal obligations. Uploaded remittance data is deleted within 30 days of the end of the relevant subscription. See the Privacy Policy and DPA for detail.

Incident response

We monitor for issues and maintain a process to investigate and respond to security incidents. In the event of a personal data breach, we notify affected customers without undue delay and provide the information they need to meet their own obligations.

Reporting a vulnerability

If you believe you have found a security issue, please contact privacy@remitclear.com. We welcome responsible disclosure and will work with you to confirm and resolve genuine issues.