1associate
liveNext·—d --h --m --s
Legal

Privacy policy

Last updated 4 August 2026

We hold the working records of accounting practices and the businesses they serve. This page sets out, plainly, what 1associate collects and what we do with it.

Who we are

1associate is a practice-management platform for Chartered Accountant firms, operated by Triam Technologies. This policy explains what we collect, why, and what you can ask us to do about it.

For anything in this policy, write to support@1associate.io.

Data we collect

  • Account data: your name, work email, firm name, role and password (stored only as a salted hash — we never see it).
  • Practice data you enter: clients, contacts, engagements, tasks, compliance deadlines, time entries, invoices, documents and messages.
  • Enquiry data: when you request a demo, the name, email, firm name, firm size, phone and message you submit, plus the IP address and browser string of that request (kept for abuse triage).
  • Operational logs: request paths, timestamps and error traces needed to keep the service running and secure.

How we use it

We do not sell your data, and we do not use the practice data you enter to train machine-learning models.

  • To provide the service — every feature you use operates on the practice data you enter.
  • To authenticate you and keep accounts secure, including rate limiting and abuse detection.
  • To send transactional email: email confirmation, password resets, team invitations and billing notices.
  • To respond to demo requests and support enquiries.
  • To diagnose faults and improve reliability.

Your firm's data is your firm's

Every record in the platform carries the firm that owns it, and every query is scoped to the signed-in user's firm. One firm cannot see another firm's clients, engagements, documents or messages.

Client portal accounts are scoped more tightly still: a client user sees only the records belonging to their own client record.

Processors we rely on

  • Cloud hosting and managed database — infrastructure for the application and its data.
  • Razorpay — subscription payments. Card details go directly to Razorpay; we never receive or store them.
  • Email delivery — transactional messages such as verification and password reset links.
  • Error monitoring — aggregated fault reports, configured not to send personal data.

Retention

Practice data is retained for as long as your firm has an account. If you close your account, we delete or anonymise it within 90 days, except where we are required to keep records for legal or tax purposes.

Single-use email tokens (verification, password reset, invitations) expire quickly by design and are stored only as hashes.

Demo enquiries are kept for up to 24 months so we can pick up a conversation where it left off.

Security

  • All traffic is encrypted in transit over TLS.
  • Passwords are hashed; email tokens are hashed; payment credentials never reach our servers.
  • Access to production systems is restricted and logged.
  • Sessions use short-lived access tokens, and signing out or changing a password revokes outstanding sessions.

Your rights

You can ask us to access, correct, export or delete your personal data. Write to support@1associate.io and we will respond within 30 days.

If you are a client of a firm using the platform, that firm controls your records — we will refer your request to them and support them in answering it.

Cookies

The marketing site uses no advertising or tracking cookies. The application stores your session and interface preferences (such as light or dark theme) in your browser's local storage; these are required for it to work and are never shared.

Changes

If we make a material change to this policy, we will update the date above and notify account owners by email before it takes effect.