Privacy Policy
Legix is software for accounting firms, provided by Sous, Inc. doing business as Legix. This page explains what we collect, who else touches it, and what we will not do with it. If you are a client of a firm that uses Legix, your firm controls your data here. Please send any request to your firm.
What we collect
From you and your firm: your name and email through our sign-in provider, your firm and workspace members, the notes and questions you enter in the product, files you upload, and anything you send us directly.
From the systems your firm connects: transaction and contact records from your clients' books in QuickBooks Online, including the chart of accounts, customers, vendors and employees, and the documents attached to them. Contact records can include names, addresses, phone numbers, email addresses and limited tax identifiers as QuickBooks provides them. If your firm connects bank accounts through Plaid, we receive account details, balances and transactions. We do not store full bank account numbers.
Automatically: analytics on our marketing website, and operational records inside the product showing what changed, who changed it and when.
How we use it
To run the service for your firm: syncing your clients' books, classifying transactions, proposing journal entries for your review, answering your questions, keeping an audit trail, providing support, and protecting security.
Legix learns inside your account, keeping context about your clients so it gets better at your work over time. That learning stays in your firm's workspace.
We do not sell your information or your clients'. We do not share it for advertising, and we do not market to your firm's clients.
Who else touches it
We use a small number of vendors, each bound to use your data only to provide their service to us: Google Cloud (hosting, database and file storage), Temporal Cloud (background work, which receives only data we encrypt first), Clerk (sign-in), Anthropic and Fireworks AI (AI models), SigNoz (monitoring), and Google Analytics and Meta on our marketing website only. All are in the United States.
Our AI providers do not train on your data. Our agreements with them prohibit it, and we do not use your data to train or improve any model shared across our customers. Model providers do hold request data briefly for abuse monitoring under their own terms, so "not used for training" is not the same as "not retained."
QuickBooks Online. When your firm connects a QuickBooks company, Intuit and Legix each control the data we hold. Legix is not Intuit's processor. Intuit may change or end our access to its API at any time.
Plaid. Plaid's own End User Privacy Policy governs what Plaid does with the bank data it collects, and it reserves rights we cannot promise away on its behalf.
A small number of Legix staff can reach production data for support, debugging and accuracy work. We also share information when the law requires it, and with an acquirer if Legix is acquired, in which case the commitments here travel with the data.
Retention and deletion
You can export your data at any time. Disconnecting a client immediately revokes the connection and stops syncing, and we keep the data already collected so your firm keeps its history.
After your account ends you have 30 days to export. We delete your data within 90 days of that window closing, or within 90 days of your written request, and we confirm it in writing. Email [email protected].
Your choices
Email [email protected] to access, correct, export or delete your information. We will not treat you differently for asking. Depending on where you live, state privacy law may give you more rights, including opting out of sale or targeted advertising: we do not sell personal information and we do not share it for cross-context advertising. You can opt out of website analytics through your browser.
For your clients' data we act as a service provider: we use it only to provide the service and never combine it with another customer's data.
Security
Your data is encrypted in transit and at rest. Bank connection tokens are encrypted with a separate key. Every request that touches a client record is checked against the firm it belongs to. Sign-in fails closed. Your data is stored and processed in the United States, including the AI processing we run on it.
So you do not have to guess: Legix does not hold a SOC 2 report or ISO certification today. We will say so here when that changes.
If we discover a security incident affecting your data, we will tell you promptly, on suspicion rather than waiting for certainty, and give you what you need for your own obligations.
Changes
We will post changes here and update the date above. For changes that materially expand how we use data, customers get at least 30 days' notice.
Contact
[email protected] · Sous, Inc. d/b/a Legix, 1301 N. Scottsdale Road, Ste 4037, Scottsdale, AZ 85257