Privacy Policy
How VOLUS collects, uses and protects your information.
In plain English. VOLUS reads your financial data so it can help you run your business. We are read-only: we never change anything in the systems you connect. We never train our AI on your data, and your raw financial records never leave our secure database. You stay in control, and you can delete anything you have shared at any time.
1. Who we are
VOLUS is a financial intelligence platform for small and medium-sized businesses, provided by Capsa London Ltd (“VOLUS”, “we”, “us”, “our”), a company registered in England and Wales. We are the data controller for the personal data described in this policy, except where we act as a processor on behalf of a business or accountancy firm that uses VOLUS (see section 10).
For any privacy question, or to exercise your rights, contact us at privacy@volus.co. Where we refer to our data protection contact, you can reach them at dpo@volus.co.
2. The information we collect
Information you give us
- Account details — your name, work email, business name, role, and login credentials.
- Business context you choose to share — plans, board packs, meeting notes and transcripts, spreadsheets and documents you upload so that Volu can understand your business.
- Billing details — handled by our payments provider; we store a billing reference, not your full bank or card details.
Information from the systems you connect
When you connect a source, we receive data from it on a read-only basis, using secure, revocable authorisation:
- Bank data, through an FCA-authorised open-banking provider — account balances and transactions.
- Accounting data, from Xero (and later others) — profit and loss, balance sheet, invoices and ledgers.
- CRM data, from Capsule — pipeline and expected revenue.
Information we collect automatically
- Usage and device data — how you use the platform, collected with privacy-respecting, first-party analytics (no third-party advertising trackers).
- Security logs — records needed to keep accounts and data safe.
3. How we use your information
| Purpose | What this means |
|---|
| Provide the service | Show your dashboard, forecasts, insights and The Lab; power Volu, your finance companion. |
| Understand your business | Use the context you share so Volu can give relevant, grounded answers and suggestions. |
| Keep you informed | Send alerts, reports and service messages by email through our email provider. |
| Billing | Take payment for your subscription through our payments provider. |
| Security & reliability | Protect accounts, prevent misuse, and keep the platform running. |
| Legal obligations | Meet tax, accounting and other legal duties. |
Our lawful bases under UK GDPR are: performance of a contract (to provide the service you sign up for), legitimate interests (to secure, improve and support the platform, balanced against your rights), consent (for optional analytics and any marketing, which you can withdraw), and legal obligation (for tax and compliance).
4. How Volu (our AI) uses your data — and what it never does
We never train our AI on your data. Volu understands your business through retrieval — it looks up the context you have shared when it needs it. Your information is never used to train or improve any AI model, ours or anyone else’s.
Your raw financial records never leave our database to reach the AI. When Volu needs to reason, only the specific business context required is used — not your underlying bank, accounting or CRM records.
You stay in control. Volu suggests, explains and drafts. You make the decisions. Its output is information to help you, not regulated advice.
The AI layer that powers Volu is provided by a specialist AI provider under contract. That provider processes the business-context text we send only to generate a response for you, does not retain it to train its models, and is bound by confidentiality and data-protection terms. Full details of our providers are in our Sub-processor List.
If you connect your own AI (for example your own OpenAI, Gemini, Grok or Claude account), we use it read-only and on your own account and billing. Your key is encrypted and held securely on our servers, is never shown again, and you can revoke it at any time.
5. Who we share it with
We do not sell your data, and VOLUS products are ad-free — we do not share your data with advertisers or allow anyone to pay to influence what Volu tells you. We share data only with:
- Sub-processors who help us run the service (hosting, the AI layer, email, payments). Each is bound by contract to protect your data and use it only on our instructions. See our Sub-processor List.
- Your accountant or firm, where you have chosen to connect one, and only to the extent you allow — you control what they can see.
- Authorities or advisers, where we are legally required to, or to establish or defend legal claims.
- A successor, if our business is reorganised or acquired — in which case this policy continues to apply.
6. Where your data is held
We host your data on secure infrastructure within the UK and/or European Economic Area. Where any provider processes data outside the UK/EEA, we rely on approved safeguards (such as UK International Data Transfer Agreements or the equivalent Standard Contractual Clauses) so that your data keeps the same protection.
7. How long we keep it
| Data | Retention |
|---|
| Account and business data | For the life of your account, then up to 6 years after closure to meet tax and legal duties. |
| Connected-source access | Revoked immediately when you disconnect a source or close your account. |
| Context you upload | Kept until you delete it or close your account — deletable at any time. |
| Backups | Held on a rolling basis and purged within 35 days. |
8. How we protect it
- Encryption in transit and at rest.
- Access controls and row-level security, so each business only ever sees its own data.
- Read-only connections — we never write to the systems you connect.
- Least-privilege internal access, logging, and regular review.
9. Your rights
Under UK GDPR you have the right to access your data, to correct or delete it, to restrict or object to processing, to data portability, and to withdraw consent at any time. You can exercise most of these directly in the app, or by emailing privacy@volus.co. We will respond within one month.
You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk. We would appreciate the chance to resolve your concern first.
10. When we act for your business or accountant
Where an accountancy firm or a business uses VOLUS to process personal data about their own clients or contacts, that organisation is the controller and VOLUS is the processor. In those cases our Data Processing Agreement governs how we handle the data, and this policy explains our wider practices.
11. Children
VOLUS is a business tool and is not intended for anyone under 18. We do not knowingly collect data about children.
12. Changes to this policy
We may update this policy as the platform develops. We will post the new version here with a revised “Last updated” date, and tell you about significant changes.
13. Contact
Capsa London Ltd, operating VOLUS — England and Wales. Privacy: privacy@volus.co. Data protection: dpo@volus.co. Support: support@volus.co.
Terms of Service
The agreement between you and VOLUS for using the platform.
The essentials. VOLUS gives you tools and an AI companion, Volu, to understand and plan your business finances. We provide the software; you stay responsible for your own decisions. VOLUS is not a regulated financial, investment, tax, accounting or legal adviser, and nothing it produces is regulated advice.
1. These terms
These Terms of Service (“Terms”) are a contract between you (“you”, the “customer”) and Capsa London Ltd, operating VOLUS (“VOLUS”, “we”, “us”). By creating an account or using the platform, you agree to these Terms. If you are agreeing on behalf of a business, you confirm you are authorised to bind that business.
These Terms work alongside our Privacy Policy, Acceptable Use Policy and, where relevant, our Data Processing Agreement. Together they form the whole agreement between us.
2. The service
VOLUS is a financial intelligence platform that connects to the systems you choose — your bank (through an FCA-authorised open-banking provider), your accounting software, and your CRM — and helps you see your position, forecast, plan scenarios in The Lab, and ask questions of Volu, your finance companion. We connect to these systems on a read-only basis and never change anything in them.
We may improve, add, or change features over time. We will not make a change that materially reduces the core service you are paying for without letting you know.
3. Your account
- You must give accurate registration details and keep them up to date.
- You are responsible for activity under your account and for keeping your login secure.
- You must tell us promptly at support@volus.co if you suspect unauthorised access.
- You are responsible for having the right to connect any data source and to share any information you upload.
4. Free trial and subscription
- New customers get a 14-day free trial with no card required.
- After the trial, the service continues on a paid subscription, billed through our payments provider by Direct Debit or Instant Bank Pay.
- Fees, billing frequency and any changes are shown in the app before you subscribe. We will give reasonable notice of any price change.
- You can cancel at any time; your subscription then runs to the end of the current billing period. Fees already paid are non-refundable except where the law requires otherwise.
5. Accountants and partners
If you use VOLUS as a referrer or reseller partner, or if your accountant introduces you to VOLUS, additional partner terms may apply and will be made available to you. Referral discounts and commissions are as described in those terms. Where a partner accesses a client’s data, that access is controlled by the client and governed by our Data Processing Agreement.
6. Volu and AI-assisted features — important
Volu is a decision-support tool, not an adviser. It produces estimates, projections, insights and drafts from the data you connect and the context you share. It can be wrong or incomplete. You remain responsible for checking anything important and for the decisions you take.
Not regulated advice. VOLUS is not authorised or regulated by the Financial Conduct Authority for the giving of advice. Nothing VOLUS or Volu produces is regulated financial, investment, tax, accounting or legal advice. Seek a suitably qualified professional before acting on anything significant.
We never train our AI on your data, and your raw financial records are not sent to the AI model. See our AI & Volu Transparency Notice for the full picture.
7. Your data and your content
- You own your data. Connecting a source or uploading content does not transfer ownership to us.
- You grant us the limited licence we need to host and process your data only to provide the service to you, as described in our Privacy Policy.
- You can delete your content at any time, and export your data. On account closure we handle your data as set out in the Privacy Policy.
8. Acceptable use
You agree to use VOLUS lawfully and in line with our Acceptable Use Policy. In short, you must not misuse the platform, attempt to break its security, use it to process data you have no right to, or use it to build a competing product. We may suspend access for serious or repeated breaches.
9. Availability and support
We aim to keep VOLUS available and reliable, but we do not promise it will be uninterrupted or error-free. We may carry out maintenance, ideally with notice for anything significant. Support is available at support@volus.co.
10. Intellectual property
VOLUS, Volu, the platform, and all related software, design and content are owned by us or our licensors. These Terms give you a limited, non-exclusive, non-transferable right to use the service while your subscription is active. You may not copy, resell, reverse-engineer, or create derivative works from the platform except as the law allows.
11. Our responsibility to you
Nothing in these Terms limits liability for death or personal injury caused by negligence, for fraud, or for anything that cannot be limited by law. Subject to that, and because VOLUS is a decision-support tool you use at your discretion:
- We are not liable for business decisions you take, or for indirect or consequential loss, loss of profit, revenue, goodwill or data.
- Our total liability to you in any 12-month period is limited to the fees you paid us for the service in that period.
12. Your responsibility to us
You agree to indemnify us against claims arising from your misuse of the platform, your breach of these Terms, or your sharing of data you had no right to share.
13. Suspension and termination
- You may stop using VOLUS and close your account at any time.
- We may suspend or end your access if you seriously or repeatedly breach these Terms, if payment fails and is not resolved, or if we are required to by law.
- On termination, your right to use the service ends and we handle your data as set out in the Privacy Policy.
14. Changes to these terms
We may update these Terms as the platform develops. We will post the updated version and, for material changes, give you reasonable notice. Continuing to use VOLUS after a change means you accept the updated Terms.
15. Governing law
These Terms are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute.
16. Contact
Capsa London Ltd, operating VOLUS — England and Wales. Legal: legal@volus.co. Support: support@volus.co.
Terms & Conditions
The terms for using the VOLUS website and signing up.
What this covers. These Terms & Conditions apply to the VOLUS website and to signing up for early access or the service. Your use of the platform itself is governed by our Terms of Service; how we handle data is in our Privacy Policy.
1. About us
This website is operated by Capsa London Ltd, which operates VOLUS (“we”, “us”, “our”), a company registered in England and Wales. By using this website you agree to these Terms & Conditions. If you do not agree, please do not use the site.
2. Using the website
- You may use the website for lawful purposes only.
- You must not misuse the site by knowingly introducing malicious code, attempting to gain unauthorised access, or interfering with its operation.
- You must not scrape, copy, or reuse content from the site except as permitted by law or with our written permission.
3. Early access and sign-up
VOLUS is preparing for launch. Where the site invites you to register interest, join a waitlist, or start a free trial, doing so does not create a binding contract for the service until you accept our Terms of Service and an account is created. Any dates, features or pricing described on the site are indicative and may change before launch.
4. Information on the website
Not advice. Information on this website, including any figures, examples, sample data or descriptions of what VOLUS can do, is for general information only. It is not financial, investment, tax, accounting or legal advice, and must not be relied on as a substitute for professional advice. Sample figures shown in demonstrations are illustrative and not real client data.
We take care to keep the website accurate, but we do not warrant that it is complete, current or error-free, and we may change content at any time.
5. Intellectual property
All content on this website — including text, design, logos, the VOLUS and Volu names, graphics and software — is owned by us or our licensors and is protected by law. You may view and print pages for your own reference, but you may not otherwise use our content without permission.
6. Links to other sites
Where the website links to third-party sites (for example our providers or partners), those links are provided for convenience. We are not responsible for the content or practices of external sites.
7. Cookies
The website uses a small number of cookies to work properly and to understand usage. VOLUS products are ad-free and we do not use advertising cookies or third-party ad tracking. See our Cookie Policy for details and your choices.
8. Our liability
Nothing in these Terms & Conditions excludes liability that cannot be excluded by law (including for death or personal injury caused by negligence, or for fraud). Subject to that, we are not liable for any loss arising from your use of, or inability to use, this website, or from reliance on any content on it. Fuller liability terms for the service are in our Terms of Service.
9. Changes
We may update these Terms & Conditions from time to time by posting a new version here. Please check back periodically.
10. Governing law
These Terms & Conditions are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
11. Contact
Capsa London Ltd, operating VOLUS — England and Wales. Legal: legal@volus.co.
Cookie Policy
The cookies VOLUS uses, and how to control them.
Short version. We use only the cookies we need to run VOLUS securely, to remember your preferences, and to understand — in aggregate — how the product is used. VOLUS products are ad-free: we do not use advertising cookies, and we do not allow third-party ad networks to track you across the web.
1. What cookies are
Cookies are small text files stored on your device when you visit a website or use a web app. They let a site remember things between pages and visits — for example, keeping you signed in. Some are essential; others are optional.
2. The cookies we use
| Type | What it does |
|---|
| Strictly necessary | Keep you signed in, secure your session, balance load, and protect against fraud and abuse. The platform cannot work without these, so they do not need consent. |
| Functional | Remember your preferences — for example that you have dismissed the guided tour, or your chosen style — so the app behaves the way you expect. |
| Analytics | Help us understand, in aggregate, how VOLUS is used so we can improve it. We use privacy-respecting, first-party analytics and do not build advertising profiles. |
3. What we do not use
- No advertising cookies. VOLUS products are ad-free.
- No third-party ad tracking or cross-site profiling.
- No selling of data to data brokers or advertisers.
4. Managing your choices
When you first use the site, you can accept or manage optional (functional and analytics) cookies. You can change your choice at any time from the cookie settings on the website. Strictly necessary cookies cannot be switched off, as the service relies on them.
You can also control cookies through your browser settings — including deleting existing cookies or blocking new ones. Blocking strictly necessary cookies may stop parts of VOLUS from working.
5. Cookies set by our providers
Some cookies are set by the trusted providers that help us run the service securely (for example our hosting and authentication provider). These are used to operate and protect the platform, not for advertising. Our providers are listed in our Sub-processor List.
6. Changes
We may update this Cookie Policy as the platform develops or as our cookie use changes. We will post the updated version here with a new “Last updated” date.
7. Contact
Questions about cookies? Email privacy@volus.co. See also our Privacy Policy.
Data Protection & GDPR Statement
How VOLUS meets its obligations under UK GDPR and the Data Protection Act 2018.
Our commitment. VOLUS is built to be trustworthy with financial data. We follow the UK GDPR and the Data Protection Act 2018, we minimise what we hold, we never train our AI on your data, and we give you real control. This statement explains, in one place, how we meet those obligations.
1. Scope
This statement sits alongside our Privacy Policy and Data Processing Agreement. Where they describe specific mechanics, this statement explains our overall approach to data protection and the principles we hold ourselves to.
2. Controller and processor roles
- For your account and use of VOLUS, we are the controller.
- Where a business or accountancy firm uses VOLUS to process personal data about its own clients or contacts, that organisation is the controller and VOLUS is the processor, acting on its documented instructions under our Data Processing Agreement.
3. The data protection principles, and how we meet them
| Principle | How VOLUS applies it |
|---|
| Lawfulness, fairness, transparency | We process data on clear lawful bases and explain plainly what we do, in our Privacy Policy and this statement. |
| Purpose limitation | We use data to run the service you signed up for, and not for unrelated purposes. |
| Data minimisation | We collect only what we need. Raw financial records stay in our database and are not sent to the AI model. |
| Accuracy | We work from the data your connected sources provide, and let you correct or remove what you share. |
| Storage limitation | We keep data only as long as needed — see the retention schedule in our Privacy Policy. |
| Integrity and confidentiality | Encryption in transit and at rest, strict access controls, and row-level security so each business sees only its own data. |
| Accountability | We keep records of processing, assess risk, use contracts with every provider, and can demonstrate compliance. |
4. Lawful bases we rely on
- Contract — to provide the service you have signed up for.
- Legitimate interests — to secure, support and improve the platform, balanced against your rights.
- Consent — for optional analytics and any marketing; you can withdraw it at any time.
- Legal obligation — to meet tax, accounting and regulatory duties.
5. Your rights under UK GDPR
You have the right to be informed, and to access, rectify, erase, restrict, object to, and port your data, and to withdraw consent. You can exercise most of these in the app, or by emailing dpo@volus.co. We respond within one month and do not charge for a reasonable request.
6. Automated decisions and AI
VOLUS does not make legally significant or similarly significant decisions about people by automated means. Volu produces estimates, insights and suggestions to help you decide — a human is always in control. We do not use your data to train AI models. See our AI & Volu Transparency Notice.
7. International transfers
We host data in the UK and/or EEA. Where a provider processes data elsewhere, we use approved safeguards — UK International Data Transfer Agreements or the equivalent Standard Contractual Clauses — so that your data keeps the same level of protection.
8. Security and breach response
- We apply appropriate technical and organisational measures, reviewed regularly.
- If a personal data breach is likely to risk your rights and freedoms, we will notify the ICO within 72 hours of becoming aware, and affected people without undue delay where required.
- Our providers are contractually required to tell us of any incident affecting your data without undue delay.
9. Data protection by design and by default
We consider data protection from the start of any new feature: minimising data, defaulting to the most privacy-protective settings, keeping raw financial data out of the AI path, and carrying out a Data Protection Impact Assessment where a change may present higher risk.
10. Our data protection contact
You can reach our data protection contact at dpo@volus.co for any question about how we handle personal data, to exercise your rights, or to raise a concern.
11. Complaints
If you are unhappy with how we have handled your data, please tell us first at dpo@volus.co so we can put it right. You also have the right to complain to the Information Commissioner’s Office (ICO) — ico.org.uk, 0303 123 1113.
12. Contact
Capsa London Ltd, operating VOLUS — England and Wales. Data protection: dpo@volus.co.
AI & Volu Transparency Notice
What Volu does, what it never does, and how we keep you in control.
Our promise on AI. Volu is your finance companion inside VOLUS. It reads the data you connect and the context you share so it can inform your decisions. We never train our AI on your data. Your raw financial records never leave our database to reach the AI model. And you are always the one who decides.
1. What Volu is
Volu is an AI-assisted companion built into VOLUS. It helps you understand your numbers, answers questions in plain English, models scenarios in The Lab, and suggests next moves — the way a good finance director would. It is a decision-support tool, not a person and not a regulated adviser.
2. What Volu does
- Reads the data you connect — bank, accounting and CRM — on a read-only basis.
- Remembers the context you choose to share — plans, board packs, meeting notes, documents — by retrieval, so it can be relevant to your business.
- Explains your position, projects scenarios, suggests options, and drafts things for you to review.
3. What Volu never does
| We never… | What that means for you |
|---|
| Train AI on your data | Your information is never used to train or improve any AI model — ours or a provider’s. Volu learns your context by looking it up, not by being trained on it. |
| Send raw financial records to the AI | When Volu reasons, only the specific business context needed is used. Your underlying bank, accounting and CRM records stay in our secure database. |
| Decide for you | Volu suggests and drafts. You review and decide. It does not make automated decisions about you or your business. |
| Change your systems | Connections are read-only. Volu never writes to, or alters, anything in the tools you connect. |
| Show ads or take payment to influence answers | VOLUS products are ad-free. No one can pay to change what Volu tells you. |
4. How the AI works, in brief
The AI layer that powers Volu is provided by a specialist AI provider under contract. When Volu needs to generate a response, we send it the business-context text required for that task — not your raw financial records. The provider processes it only to return a response to you, does not retain it to train its models, and is bound by confidentiality and data-protection terms. Our providers are listed in our Sub-processor List.
5. Bring your own AI
You can connect your own AI account — for example OpenAI, Gemini, Grok or Claude — so Volu can draw on your own model and knowledge. When you do:
- Access is read-only — VOLUS never changes anything in your AI.
- It runs on your own account and billing.
- Your key is encrypted and held securely on our servers, is never shown again, and you can revoke it at any time.
6. Getting the most from Volu — and its limits
Volu can be wrong or incomplete. Its figures are estimates and projections, not guarantees, and they depend on the quality of the data you connect. Always sanity-check anything important, and treat Volu’s output as information to help you decide — not as regulated financial, investment, tax, accounting or legal advice. VOLUS is not authorised or regulated by the Financial Conduct Authority for the giving of advice.
7. Your control
- Delete any context you have shared, at any time.
- Disconnect any source, which revokes access immediately.
- Export your data, and close your account, as set out in our Privacy Policy.
8. Changes
As AI develops, we will keep this notice current and tell you about material changes. Our commitments — no training on your data, raw financial data kept out of the AI path, and you in control — are principles we hold to.
9. Contact
Questions about Volu or our use of AI? Email privacy@volus.co. See also our Privacy Policy and Data Protection & GDPR Statement.
Acceptable Use Policy
The rules for using VOLUS fairly, safely and lawfully.
In short. Use VOLUS for its purpose — understanding and planning your business finances — and don’t misuse it, break its security, or use it with data you have no right to. This policy forms part of our Terms of Service.
1. Purpose
This Acceptable Use Policy sets out what you may and may not do when using VOLUS. It applies to everyone who uses the platform and forms part of our Terms of Service. If you breach it seriously or repeatedly, we may suspend or end your access.
2. You must
- Use VOLUS lawfully and honestly, for your own business.
- Only connect data sources, and only upload content, that you have the right to use and share.
- Keep your login secure and not share your account with people who should not have access.
- Respect the rights and privacy of the people whose data appears in your systems.
3. You must not
- Break, probe or bypass the security of the platform, or attempt to access data that is not yours.
- Introduce malicious code, or interfere with the operation, integrity or performance of VOLUS.
- Reverse-engineer, decompile, scrape, or copy the platform, except where the law expressly allows.
- Use VOLUS to build, train, or benchmark a competing product or service.
- Use VOLUS to process data you have no lawful basis to process, or to break any law or regulation.
- Use VOLUS to harass, defraud, or harm others, or to store or share unlawful, infringing or harmful content.
- Resell, sublicense or provide the platform to third parties except under an approved partner arrangement.
- Overload the service, or use automated means to place unreasonable demands on it.
- Misrepresent Volu’s output as regulated advice, or rely on it as such.
4. Using Volu responsibly
Volu is a decision-support tool. Do not treat its output as regulated financial, investment, tax, accounting or legal advice, and do not present it to others as such. Check anything important before you act, and take professional advice where it matters.
5. Reporting misuse
If you become aware of misuse of VOLUS, a security concern, or content that breaches this policy, please tell us at support@volus.co so we can act.
6. Enforcement
Where we reasonably believe this policy has been breached, we may investigate, restrict features, suspend access, or, for serious or repeated breaches, terminate the account. Where the law requires, we may also report unlawful activity to the authorities.
7. Changes
We may update this policy as the platform develops. The current version will always be posted, and forms part of your agreement with us.
8. Contact
Capsa London Ltd, operating VOLUS — England and Wales. Support: support@volus.co.
Data Processing Agreement
For businesses and accountancy firms whose clients' data VOLUS processes.
When this applies. This Data Processing Agreement (“DPA”) applies where you use VOLUS to process personal data about your own clients or contacts. In that case you are the controller and VOLUS is the processor. This DPA forms part of our Terms of Service and reflects Article 28 of the UK GDPR.
1. Definitions
Terms such as controller, processor, data subject, personal data, processing and personal data breach have the meanings given in the UK GDPR and the Data Protection Act 2018 (together, Data Protection Law). “Customer” means the controller using VOLUS; “VOLUS” means Capsa London Ltd as processor.
2. Roles and scope
- The Customer is the controller of the personal data it processes using VOLUS.
- VOLUS is the processor, acting only on the Customer’s documented instructions.
- Using and configuring VOLUS — including choosing what to connect and share — constitutes the Customer’s instructions. VOLUS will not process the data for any other purpose.
3. Subject matter of the processing
| Item | Detail |
|---|
| Subject matter | Providing the VOLUS financial intelligence platform to the Customer. |
| Duration | For the term of the Customer’s subscription, plus any retention period in the Privacy Policy. |
| Nature and purpose | Hosting, organising, analysing and presenting financial and business data; generating AI-assisted insights and drafts for the Customer. |
| Types of personal data | Business contact details; financial and transactional data; pipeline and customer information; content the Customer uploads. |
| Categories of data subject | The Customer’s staff, clients, customers, suppliers and contacts, as reflected in the data the Customer connects or uploads. |
4. VOLUS’s obligations
- Process personal data only on the Customer’s documented instructions, unless required by law (in which case we will tell you, unless the law prohibits it).
- Ensure people authorised to process the data are bound by confidentiality.
- Apply appropriate technical and organisational security measures (section 7).
- Respect the conditions for engaging sub-processors (section 5).
- Assist the Customer, taking into account the nature of processing, in responding to data subject requests and in meeting security, breach-notification and impact-assessment duties.
- At the Customer’s choice, delete or return the personal data at the end of the service, and delete existing copies unless the law requires retention.
- Make available the information needed to demonstrate compliance, and allow for and contribute to audits as set out in section 9.
5. Sub-processors
The Customer gives general authorisation for VOLUS to engage the sub-processors listed in our Sub-processor List, which forms part of this DPA. Each sub-processor is bound by data-protection terms no less protective than this DPA. We will give the Customer advance notice of any intended addition or replacement of a sub-processor, and the Customer may object on reasonable data-protection grounds; if we cannot resolve the objection, the Customer may terminate the affected service.
6. AI processing
The AI layer used to provide Volu is a sub-processor. It receives only the business-context text needed to generate a response — not raw financial records — processes it solely to return that response, and does not use it to train models. Personal data is not used to train any AI model. VOLUS does not carry out automated decision-making producing legal or similarly significant effects on data subjects.
7. Security
Taking account of the state of the art, the costs of implementation and the risk, VOLUS applies measures including:
- Encryption of personal data in transit and at rest.
- Access controls and row-level security ensuring each controller’s data is segregated and accessible only to authorised parties.
- Read-only connections to source systems.
- Measures to ensure ongoing confidentiality, integrity, availability and resilience, and to restore access after an incident.
- Regular testing and review of the effectiveness of these measures.
8. Personal data breaches
VOLUS will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, and will provide the information the Customer reasonably needs to meet its own notification duties to the ICO and, where required, to data subjects.
9. Audit
VOLUS will make available information reasonably necessary to demonstrate compliance with Article 28, and will allow for audits, including inspections, by the Customer or an auditor it mandates, on reasonable prior notice, no more than once a year (unless required more often by a supervisory authority or after a breach), and in a way that does not compromise the security or confidentiality of other customers’ data. Third-party certifications or reports may be provided to satisfy an audit where reasonable.
10. International transfers
VOLUS hosts personal data in the UK and/or EEA. Where a sub-processor processes data outside the UK/EEA, VOLUS ensures an appropriate transfer mechanism is in place — the UK International Data Transfer Agreement or the equivalent Standard Contractual Clauses with any required addendum — so that the data keeps an equivalent level of protection.
11. Return and deletion
On termination or expiry, and at the Customer’s choice, VOLUS will return or delete the Customer’s personal data, and delete existing copies, within a reasonable period, except where retention is required by law. Backup copies are purged on the rolling cycle described in the Privacy Policy.
12. Liability and precedence
This DPA is subject to the liability provisions of the Terms of Service. If there is a conflict between this DPA and the Terms of Service on the processing of personal data, this DPA prevails.
13. Governing law
This DPA is governed by the laws of England and Wales.
14. Acceptance
This DPA is accepted by the Customer when it accepts the Terms of Service or begins using VOLUS to process personal data of its clients or contacts. A countersigned copy is available on request from dpo@volus.co.
Sub-processor List
The trusted providers that help us run VOLUS — and what each does.
Why this list exists. To be trustworthy with your data we are open about who helps us run VOLUS. Each provider below is bound by contract to protect your data and to use it only to deliver its part of the service. This list forms part of our Privacy Policy and Data Processing Agreement.
1. Our sub-processors
| Provider | What it does for VOLUS |
|---|
| Supabase | Core hosting: database, authentication, file storage and secure server functions. This is where your data is held, encrypted and segregated per business. |
| Open-banking provider (FCA-authorised) | Provides the read-only bank account feed — balances and transactions — under open-banking rules. Our current provider is confirmed in-app when you connect your bank. |
| Xero | Read-only accounting data (profit and loss, balance sheet, invoices, ledgers), connected by you through secure authorisation. |
| Capsule | Read-only CRM data (pipeline and expected revenue), connected by you through secure authorisation. |
| Anthropic (Claude) | The AI layer that powers Volu. Receives only the business-context text needed to generate a response — not raw financial records — and does not use it to train models. |
| GoCardless | Payments and billing (Direct Debit / Instant Bank Pay). Acts as payment processor; we hold a billing reference, not your full bank details. |
| Resend | Sends transactional email — alerts, reports and service messages. |
| Netlify | Serves the VOLUS website and app securely over a content delivery network. |
2. What they may and may not do
- Each provider may process your data only to deliver its specific function for VOLUS.
- None may use your data for its own purposes, and none is permitted to train AI models on your data.
- Each is bound by confidentiality and data-protection terms no less protective than our own.
3. Where data is processed
We host your data in the UK and/or EEA. Where a provider processes data outside the UK/EEA, we rely on approved safeguards — the UK International Data Transfer Agreement or the equivalent Standard Contractual Clauses — so your data keeps the same level of protection.
4. Your own connections
If you choose to connect your own AI account (for example OpenAI, Gemini, Grok or Claude), that provider acts under your account and terms, on a read-only basis. Your key is encrypted, held securely, and revocable at any time.
5. Changes to this list
As VOLUS develops we may add or replace providers. We will update this list and, for customers covered by our Data Processing Agreement, give advance notice of any addition or replacement so you can raise any reasonable data-protection objection.
6. Contact
Questions about our providers? Email dpo@volus.co. See also our Privacy Policy and Data Processing Agreement.
Anti-Money Laundering & Financial Crime Policy
Our commitment to keeping VOLUS free of money laundering, fraud and financial crime.
In short. VOLUS is a software platform, not a bank or a regulated financial business — we don’t hold your money or move it. We still take financial crime seriously: we monitor the platform for misuse, we rely on FCA-authorised partners for the regulated parts, and we act on anything suspicious. This policy explains how, and where your responsibilities sit.
1. Who this policy is from
This policy is issued by Capsa London Ltd, operating VOLUS, a company registered in England and Wales. It applies to everyone who uses the VOLUS platform, and sits alongside our Terms of Service and Acceptable Use Policy.
2. Our position under the Money Laundering Regulations
VOLUS is a financial-intelligence software platform. We do not hold client money, take deposits, execute payments, or provide regulated financial services. Because of this, VOLUS is not a “relevant person” supervised for anti-money-laundering purposes under the UK Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (the “MLRs”), and we are not authorised or regulated by the Financial Conduct Authority. The regulated activity — moving and holding money — is carried out by the FCA-authorised partners described in section 5, who apply their own AML controls.
3. Our commitment
We have zero tolerance for the use of VOLUS to facilitate money laundering, terrorist financing, fraud, bribery, sanctions evasion or any other financial crime. We are committed to detecting and preventing misuse of our platform, and to cooperating with banks, partners and the authorities where financial crime is suspected.
4. How we monitor and detect
VOLUS operates automated monitoring and anomaly-detection across the platform. This continuously reviews signals such as account sign-up and onboarding, access and usage patterns, and unusual or suspicious activity in how the platform is used, and flags anomalies for human review. Where our checks raise a concern, we may investigate, request further information, restrict or suspend features or accounts, and preserve the relevant records.
What this is — and isn’t. Our detection protects the integrity of the platform and helps us spot misuse. It is not a regulated transaction-monitoring or suspicious-activity-reporting service, and it does not replace the anti-money-laundering controls carried out by your bank and our regulated partners, or any AML obligations that apply to your own business.
5. Reliance on FCA-authorised partners
Your bank connection is made through an FCA-authorised open-banking provider on a read-only basis, and payments and billing are handled by a regulated payments provider. These regulated firms carry out the customer due diligence, verification and transaction monitoring required of them under the MLRs. VOLUS never moves your money and never sees your banking login.
6. Your responsibilities
- Use VOLUS lawfully, and never to facilitate, conceal or plan money laundering, fraud or any other financial crime.
- Only connect data and accounts that you have the right to use, and that you have no reason to believe are connected to financial crime.
- If your own business is subject to AML obligations, you remain responsible for meeting them. VOLUS is a decision-support tool and does not discharge those duties for you.
7. Sanctions
We do not knowingly provide VOLUS to individuals or entities subject to applicable financial sanctions, and we screen where appropriate. If we become aware that an account is connected to a sanctioned party, we may suspend it and take the steps the law requires.
8. Reporting and cooperation
If you suspect that VOLUS is being used for financial crime, please tell us at support@volus.co. Where we reasonably suspect financial crime, we may report it to the relevant authorities (such as the National Crime Agency) and cooperate with law enforcement. In some cases the law may require us to make such a report and to limit what we are able to tell you about it.
9. Records
We keep records of our monitoring and of any investigation for as long as we need them for these purposes and to meet our legal obligations. Personal data within those records is handled in line with our Privacy Policy.
10. Governance and review
Responsibility for this policy sits with VOLUS management, who keep our financial-crime controls and this policy under regular review as the platform grows. Relevant staff receive guidance on recognising and escalating financial-crime concerns.
11. Changes
We may update this policy as VOLUS develops. The current version will always be posted here and forms part of your agreement with us.
12. Contact
Capsa London Ltd, operating VOLUS — England and Wales. Email support@volus.co. See also our Acceptable Use Policy and Terms of Service.