MSPBilling.cloud

    Privacy Policy

    Last updated: 18 September 2026

    Deliberately Simple Digital t/a MSP Billing ("we", "us", "our") operates MSP Billing (the "Service"), a platform that helps managed service providers (MSPs) reconcile billing data across their PSA, RMM, distributor, and accounting systems, and generate client invoices. This policy explains what data we collect, why, and how it's handled — including during the development, support, and improvement of the Service.

    By creating an account, or by continuing to use the Service, you agree to the collection and use of information as described in this policy. If you do not agree with this policy, please do not use the Service.

    1. Who this applies to

    This policy covers MSP Billing account holders ("you", "your organisation") and, where relevant, the end-client data your organisation processes through the Service on your customers' behalf ("End-Client Data").

    If you are an MSP using the Service to manage billing for your own clients, you are responsible for having a lawful basis to share that End-Client Data with us, and for your own privacy obligations to your clients. This policy is intended to support that by being transparent about how we, as your sub-processor, handle the data you share with us.

    2. What we collect

    Account information. Name, email address, and organisation details when you create an account or are invited to one.

    Connected service credentials. When you connect a third-party system (e.g. QuickBooks, Xero, HaloPSA, ConnectWise, Pax8, NinjaOne, and similar tools), we store either an OAuth access/refresh token or an API key/credential set, depending on what that provider supports. These are encrypted at rest and used solely to retrieve the billing/service data described below on your behalf.

    Billing and service data. Once connected, we pull line-item data from your connected systems — client names, product/service names, quantities, unit prices, and invoice totals, and, where relevant, contact details returned by those systems — to reconcile discrepancies and, where you've configured it, generate invoices via your accounting or invoicing platform. We do not access data outside the scope you authorise when connecting each service.

    Usage and audit data. We log actions taken within the platform (e.g. connector setup, invoice pushes, data corrections) for audit and support purposes.

    Data processed during development, debugging, and support. Building and operating a platform like this involves ongoing engineering work: fixing bugs, developing new features, and investigating issues you report to us. This work is sometimes done using third-party software development tools, including AI-assisted coding and support tools ("Development Tools"). In the course of this work, real data from connected systems — including End-Client Data such as business names, pricing, and, occasionally, contact details — may be visible to engineering personnel and processed by Development Tools, for example when reproducing or diagnosing a reported issue.

    We take reasonable steps to minimise this, including using anonymised, synthetic, or minimised data wherever practical, and limiting real data exposure to what is genuinely necessary to diagnose a specific issue. However, you should be aware that this kind of incidental processing can occur as an ordinary part of operating and improving the Service, and is not always predictable or scheduled in advance.

    Any Development Tools we use are provided by reputable third-party vendors, are bound by their own data protection and security commitments, and are not used to train publicly available AI models on your data without an appropriate agreement in place, where applicable to that vendor.

    3. How we use this data

    • To operate the core reconciliation and billing functionality of the Service
    • To detect and surface billing discrepancies between your connected systems
    • To generate and, where authorised, push draft invoices to your accounting platform
    • To provide customer support and investigate reported issues
    • To develop, test, debug, and improve the Service, including using the Development Tools described in Section 2
    • To maintain the security and integrity of the Service
    • To comply with our legal and regulatory obligations

    We do not sell your data or your clients' data, and we do not use it for advertising.

    4. How we store and protect data

    Connected-service credentials (OAuth tokens, API keys) are encrypted at rest. Access to production data — including access during development, debugging, and support work — is restricted to personnel who need it to operate and support the Service.

    We use reputable third-party infrastructure and software providers, including hosting providers and Development Tools, to operate and improve the Service; those providers may process data on our behalf under their own security commitments and applicable data processing terms.

    We maintain internal practices intended to reduce the amount of real client data handled outside production systems, but you acknowledge that, given the nature of software development and support work, we cannot guarantee that no real data will ever be viewed or processed by personnel or Development Tools in the course of that work.

    5. Data sharing

    We share data only with:

    • The third-party services you explicitly connect (e.g. sending a draft invoice to Xero happens because you explicitly run that workflow)
    • Infrastructure, hosting, and Development Tool providers who process data on our behalf, as described in Sections 2 and 4
    • Professional advisors (e.g. legal, accounting) where necessary, under confidentiality obligations
    • Where required by law, regulation, or a valid legal process, or to protect our legal rights
    • In connection with a merger, acquisition, financing, or sale of some or all of our business, subject to standard confidentiality protections

    6. Data retention

    We retain account and billing reconciliation data for as long as your account is active, and for a reasonable period afterward to meet legal, accounting, or dispute-resolution obligations.

    Data processed in the course of development, debugging, or support work (Section 2) is retained according to the retention practices of the relevant third-party tool or vendor, which may differ from our own retention periods for production data, and over which our control may be limited. Where practical, we take steps to have such data removed once an issue is resolved.

    You can request deletion of your account and associated data by contacting us (see Section 9); some records may be retained longer where we're legally required to, or where deletion is not fully within our control (see above).

    7. Your rights

    If you're located in the UK or EEA, you have rights under UK GDPR / EU GDPR including the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us using the details below. We will also make reasonable efforts to assist you in responding to similar requests from your own end-clients regarding data processed through the Service.

    8. International transfers

    Where data is transferred outside the UK/EEA — for example, to a hosting provider, Development Tool provider, or infrastructure provider with operations in another region — we take steps to ensure an adequate level of protection, such as relying on Standard Contractual Clauses or an equivalent safeguard.

    9. Contact us

    Questions about this policy or your data:

    james.doherty@avad.group
    30 Kings Court, Commerce Square, Nottingham, NG1 1HS

    10. Changes to this policy

    We may update this policy from time to time, including to reflect changes in the tools and vendors we use to operate and improve the Service. Material changes will be notified via the Service or by email. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.