Palo360

Privacy

Palo360 keeps your books in the organisation you signed into. This page is the plain-language note for the in-app assistant and related processing.

In-app assistant

The assistant starts in generic mode. In that mode it can explain how to use Palo360 and answer general BURS and accounting questions. It does not query this organisation’s invoices, VAT returns, till, payroll, or ledger.

An Owner can turn on context-aware mode from Settings after ticking an explicit consent box. While that mode is on, messages in an assistant conversation — and a permission-scoped snapshot of the organisation’s records — are sent to OpenAI’s API in the United States for that conversation. This is outside Palo360’s Azure / Neon database boundary. Turning the setting off stops new context from being sent; it does not delete OpenAI’s processing of conversations already sent.

Bank and mobile account numbers, employee Omang, passport numbers, TIN, and authenticator secrets stay field-encrypted and are never decrypted into an assistant prompt or reply, in either mode.

Palo360 stores your assistant thread (redacted) in its own database so you can scroll earlier messages. History is kept for 90 days and you can delete it from the assistant panel. Usage (mode, organisation, length — not the full prompt) is written to the audit log.

Other processors

Sign-in, documents, and reminders may use other configured services (for example transactional email and receipt scanning). Those keys stay on the server. Palo360 does not sell organisation books.