Xero
Technology & SaaS
No relevant claims found in policy. Overall: Good with minor gaps.
10 dimensions · 65 claims · assessed 11 May 2026 · methodology · source policy ↗
Score Breakdown
Transparency
Good with minor gaps
7.83/107.83/10
Transparency
Good with minor gaps
Transparency & Clarity
8/10Comprehensive scope statement, clear definitions, detailed table of contents, specific contact information, current version date, and multiple accessibility formats. Strong navigation and clarity features exceed basic requirements.
Purpose Limitation & Use
8/10Comprehensive list of primary purposes, explicit secondary use limitations, detailed marketing and analytics disclosures, and clear consent requirements. Strong commitment to purpose limitation with specific use cases enumerated.
Policy Maintenance & Accountability
7/10Clear update notification process, version history with archived versions available, specific contact details, and SOC 2 audit framework mentioned. Good governance structure though lacks specific review frequency commitments.
Data Protection
Good with minor gaps
7.11/107.11/10
Data Protection
Good with minor gaps
Data Collection Disclosure
8/10Detailed enumeration of specific data categories collected, clear collection methods, explicit sensitive data handling, and comprehensive legal basis disclosure. Goes beyond generic categories with granular data type specifications.
Third-Party Sharing & Disclosure
7/10Clear categories of third parties with specific purposes, named service provider types, and detailed safeguards for international transfers. Good specificity on sharing contexts though some recipients remain categorical rather than named.
Data Security
6/10General security commitment with SOC 2 certification available on request and some specific monitoring tools mentioned. Adequate but lacks detailed technical safeguards and specific encryption or breach notification commitments.
Cross-Border Data Flows
7/10Specific countries named (Australia, New Zealand, US), adequacy mechanisms for EEA/UK transfers, and standard contractual clauses mentioned. Clear disclosure of transfer locations with appropriate safeguards specified.
Your Rights
Room for improvement
5.2/105.2/10
Your Rights
Room for improvement
Consumer Rights & Control
7/10Complete enumeration of consumer rights including access, correction, deletion, and objection rights with clear exercise mechanisms. Response timeframe is vague ('reasonable time') but complaint escalation pathways are specified.
Automated Decision-Making
6/10AI/ML usage disclosed for service delivery and improvement, with rights against wholly automated decisions clearly stated. However, lacks detailed transparency about decision-making logic and specific opt-out mechanisms for automated processing.
Children's Data
not assessedNo relevant claims found in policy.
No specific findings.
Sector Comparison
Technology & SaaS comparison