Invoice data & privacy
Bill is restricted to authorized DJA accounting/office users. Uploaded PDFs are temporarily processed on the server and are not archived. Ordinary extracted rows and results remain in the current browser page and clear on refresh; server-side temporary artifacts are removed after the worker completes.
Classification sends extracted invoice item descriptions, limited invoice identity/context and CSI catalog criteria to TypeSafe. An administrator can explicitly retain extracted text as a benchmark and send it to OpenAI for comparison. OpenAI response storage is disabled in the request; this does not assert zero provider-side retention. Each provider’s applicable data policy still governs its processing.
Saved benchmarks include the upload filename, extracted line text, limited supplier/invoice identity, optional context, reviewed labels, runs and failures. They are available only to Bill administrators and remain until deleted. PDFs, bank details and customer addresses are not needed for classification. Avoid placing sensitive information in optional context.