Privacy Policy
How XTK handles personal data across the browser extension, the client portal and our backend.
Last updated:
This policy explains how OctaByte (“we”, “us”, the operator of OctaByte XTK) collects, uses and protects personal data when you use the XTK browser extension, the XTK web portal at https://xtk.octabyte.app, and this website. XTK is an independent product layered on top of Xero Practice Manager (“XPM”) and is not affiliated with or endorsed by Xero Limited.
Our two roles
XTK processes data in two capacities, and it matters which one applies:
- As a controller — for the accounts of the accountants and their staff who sign up to XTK (a “Practice”): registration details, billing data, and product usage.
- As a processor — for the client and document data a Practice manages through XTK on behalf of its own clients. The Practice is the controller of that data; we process it under their instructions and our Data Processing Addendum.
Data we collect
Account & billing data
- Name and email address of each user in a Practice.
- Authentication data (hashed passwords, session tokens).
- Subscription and billing identifiers held by our payments processor (see below). We do not store full card numbers.
Connected-service data
When a Practice connects a storage or mail provider, XTK stores encrypted OAuth tokens so it can act on the Practice’s behalf:
- Google Drive / Gmail — to store the Practice’s documents in its own Drive and to send mail from a connected mailbox.
- Microsoft OneDrive / SharePoint / Outlook — the same, for Practices that connect Microsoft instead.
OAuth tokens are encrypted at rest. We are specific about what each grant actually covers:
- Storage is a full drive scope. Google’s consent screen describes it as “see, edit, create, and delete all your Google Drive files”, and Microsoft’s equivalent is comparable. We request that scope because XTK has to work with the client documents your Practice already keeps in its own Drive, which a narrower “files this app created” scope cannot do.
- Containment is our guarantee, not Google’s restriction. Every storage operation is checked on our server before your provider is called, so it can only act inside the Main Storage Folder you designate and, within it, the folder of the client you have open. That limit is enforced by XTK’s own server-side checks — Google and Microsoft do not narrow the grant for us.
- Mail is send-only. Where you connect Gmail or Outlook so invites and requests come from your own address, only the send permission is granted. XTK cannot read your mailbox.
Client & document data
On behalf of a Practice, XTK handles the documents, e-signature requests and document-request submissions that flow between the Practice and its clients — including files, signer names and email addresses, and signature records. Where a client uses the portal, we process their name, email and the documents they exchange. This data belongs to the Practice; we process it as described in the Data Processing Addendum.
Some client details do reach our backend, though — the ones you act on — and we would rather be precise than absolute:
- Sending an e-signature or document request stores that request, including the client’s name, the recipient’s name and email address, and your subject and message.
- Inviting a portal contact stores their name and email address, and each notification stores a summary line naming the client, files and recipients involved.
- Generating a document from a template sends the set of filled-in values you confirmed in the fill dialog to our backend, because that is where the document engine runs. They are used to render your file and are not stored.
What our backend never holds is a Xero credential or token, any server-side access to your Xero account, or the contents of your documents — the operations that need a document engine (downloads, zips, PDF merges, template generation and flattening a signed PDF) stream bytes through our backend in flight, but nothing is written to disk or kept in our database. Nothing in Xero beyond client details, contacts and custom fields is read at all — not jobs, timesheets, invoices or the ledger.
Diagnostics
We use an error-monitoring service to capture crashes and performance traces across the extension, portal and backend. Where session replay is enabled it may record masked interactions to help us reproduce faults; sensitive fields are masked and this feature is governed by a remote kill-switch. See Cookies & tracking for details and controls.
How we use data
- To provide, operate and secure the XTK extension, portal and backend.
- To store and move your documents through the providers you connect.
- To send transactional mail (invites, notifications, support replies).
- To process subscriptions and prevent fraud.
- To diagnose faults and improve reliability.
- To comply with our legal obligations.
Legal bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on:
- Contract — to deliver the service to Practices that subscribe.
- Legitimate interests — to secure, maintain and improve the product (balanced against your rights).
- Consent — where required, e.g. optional diagnostics / session replay.
- Legal obligation — for tax, accounting and compliance records.
Google API Services — Limited Use
XTK’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the features you enable (Drive storage and Gmail send).
- We do not transfer or sell this data to third parties except as needed to provide the service, for security, or to comply with law.
- We do not use Google user data for advertising, and humans do not read it except with your consent, for security, to comply with law, or where it is aggregated/anonymised.
Who we share data with
We share data with the sub-processors that make XTK work — storage and mail providers, our payments processor, error monitoring and email delivery, and hosting. The current list, purposes and regions are on our Sub-processors page. We do not sell personal data.
Retention
We keep account and billing data for as long as a Practice is active and as required for legal and tax purposes afterward. Documents stored in a Practice’s connected Drive remain under the Practice’s control in its own provider. On account closure we delete or return Practice data in line with the Data Processing Addendum and Your data rights.
Security
- Documents are encrypted in transit and at rest.
- OAuth tokens are encrypted at rest with per-environment keys.
- Access to production data is restricted and logged.
International transfers
Some sub-processors are located outside your country. Where personal data is transferred internationally, we rely on appropriate safeguards such as the Standard Contractual Clauses. Regions are listed on the Sub-processors page.
Your rights
Depending on where you live, you may have rights to access, correct, delete, port or restrict your personal data, and to object to certain processing. If XTK holds your data on behalf of a Practice (as a processor), please contact that Practice; we will assist them in responding. See Your data rights & deletion for how to make a request.
Children
XTK is a business tool and is not directed to children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the “Last updated” date above and, where appropriate, notified in-product.
Contact us
Questions or requests about privacy: support@octabyte.io.
XTK is operated by OctaByte.
Give Practice Manager its missing half
Install the extension, connect your Drive, and open your first client — your whole practice can be working in context today.
30-day free trial for your whole practice — no credit card required.