AI Processing Notice
Version and last updated: 15 September 2026
Receipt scanning is enabled by default, but that setting alone sends nothing. AI processing happens only when someone submits a receipt, and scanning can be turned off beforehand.
What is sent
When an authorised company user enables AI receipt processing and a receipt is submitted, the receipt image or document and extraction instructions are sent to the configured AI provider. A receipt can contain supplier details, names, addresses, transaction dates, items, amounts, tax information, payment fragments and handwritten notes. Do not submit special-category or unrelated personal data.
Purpose and output
The provider returns proposed structured fields such as vendor, date, amount, currency and VAT. Astrocounts validates the response and presents it for review. AI output can be wrong. It is not professional advice and does not replace source-document review. No user is subjected to a solely automated legal or similarly significant decision by this feature.
Provider and data governance
The current hosted deployment uses OpenAI's API. Where Astrocounts acts as processor, OpenAI acts as an authorised subprocessor under contractual data-protection terms. API content is not used to train OpenAI models by default, but limited retention for abuse monitoring or legal requirements may apply under the provider's current enterprise/API controls. Provider identity, locations, subprocessors or material retention controls will be disclosed before subsequently submitted documents are processed under materially changed conditions. A self-hosting operator that configures another provider must replace this information with accurate details.
Your choice
Leaving scanning on does not transmit anything. Uploading, photographing or forwarding a receipt instructs Astrocounts to process that document. Turning scanning off prevents new AI submissions; prior lawful processing and records already stored in Astrocounts are unaffected. Manual expense entry remains available at all times.
Data protection roles
For organisational records, the Customer determines whether receipt content may lawfully be processed and is normally controller for people named in it; Astrocounts is processor and the configured AI provider is its subprocessor under the DPA. For personal use where no other controller exists, Astrocounts processes the document to perform the user's requested extraction. Submitting a receipt does not by itself supply a lawful basis for unrelated third-party data.