Privacy Policy
1. Who we are (the controller)
Finacra Technologies (“Finacra”, “we”, “us”) is the data controller for information you provide directly to us (your account email, name, billing). For information you ingest into Finacra about your company, vendors, employees, and customers (ledger lines, payroll, invoices, contacts), you are the controller and we are your processor — see our DPA.
For DPDP correspondence (India), our Data Protection Officer is reachable at ibrahim@finacra.com. For GDPR/UK GDPR correspondence (EU/EEA/UK), the same DPO is the EU representative until we appoint a dedicated representative under Article 27.
2. What we collect, why, and how long we keep it
Every row below names a real data category we hold, the lawful basis under GDPR Art. 6 (which DPDP mirrors at Section 7), the purpose, and the retention window. We don't collect anything not on this list.
| Category | Examples | Lawful basis | Retention |
|---|---|---|---|
| Account identity | Email, name (from Google OAuth or magic-link), profile photo URL | Contract (Art. 6(1)(b)) | Active account + 30 days post-deletion |
| Company profile | CIN, PAN, TAN, registered address, directors, GST registrations, compliance profile (turnover, headcount, regime) | Contract | Active company + 7 years (statutory tax-records retention) |
| Compliance facts | Has-imports/exports flag, rent-payments flag, voluntary PF/ESI, NIC code, MSME status | Contract | Same as company profile |
| Documents (Vault) | Filings, certificates, payslips, invoices you upload | Contract | Per company until deleted + 30-day soft delete grace + statutory retention (typically 7yr) |
| Integration data | Ledger / payroll / bank lines pulled via Zoho, QuickBooks, Tally, Marg, etc. | Contract | Cached up to 90 days; re-fetched on demand. Encrypted OAuth tokens until you Disconnect. |
| Reminders + notifications | Email / WhatsApp / SMS recipient addresses, delivery webhooks (Resend) | Contract | Sent items: 1 year. Recipient addresses: until you remove the team member. |
| Audit + activity logs | Sign-in events, who edited what, consent timestamps, IP at consent time | Legitimate interest + legal obligation | 3 years from event |
| Operational telemetry | Latency, error rates, route counts (no PII) | Legitimate interest | 90 days |
What we don't collect: we don't place advertising trackers, don't sell data to brokers, don't train AI models on your data, and don't enrich your records against third-party demographics or marketing databases.
3. How AI / LLM features handle your data
Several Finacra features (Ask, Forecast, Completeness Critic, document OCR + classification, the ITR canvas) call LLMs hosted by third parties. Your data is sent to the LLM provider only for the duration of the request and only the minimum slice needed for the task.
- OpenRouter — fronts our OCR + chat calls. We pin zero-retention model endpoints; provider does not log or train on prompts.
- Azure OpenAI / Perplexity — used for structured extraction and regulatory research. Both contracts specify no-training.
- No customer PII enters a fine-tuning corpus. Period.
The full list of LLM and other sub-processors with regions and DPAs is on our Sub-processors page.
4. Lawful basis (GDPR Art. 6) + DPDP grounds (Sec 4 + 7)
Most processing is on contract (you signed up; we have to process your data to deliver the service you asked for). Some processing is on legitimate interest (audit logs, fraud prevention, security telemetry) — we balance these against your rights and document the assessment internally.
The DPDP Act recognises “legitimate uses” (Sec 7) and consent (Sec 6); we rely on legitimate uses for service performance and explicit consent (timestamped + version-pinned at company-create) for any processing that extends beyond what the service strictly needs to function.
5. Your rights
You have the following rights across DPDP, GDPR/UK GDPR, PDPL, and the UAE Federal Decree-Law 45/2021. Where laws differ we apply the strictest treatment.
- Access (GDPR Art. 15 / DPDP Sec 11) — get a JSON copy of everything we hold on you. Self-service: /me/data-export.
- Rectification (Art. 16 / Sec 12) — edit any field on the Manage tab or via the appropriate canvas. The audit log captures the change.
- Erasure (Art. 17 / Sec 12) — delete your account + all associated data. Self-service: /me/delete-account. 30-day grace; then irrecoverable except records held under statutory retention obligations.
- Restriction (Art. 18) — pause processing while a complaint is resolved. Email ibrahim@finacra.com.
- Portability (Art. 20) — export your data in a machine-readable JSON via the export endpoint above.
- Object (Art. 21) — opt out of any legitimate-interest processing. We'll honour or explain why we believe the interest still balances in our favour.
- Withdraw consent (DPDP Sec 6(4) / GDPR Art. 7(3)) — withdraw the consent recorded at company-create. We will stop the consent-dependent processing prospectively.
- Lodge a complaint — with the Data Protection Board of India (DPDP), your local supervisory authority (GDPR), the SDAIA (PDPL), or the UAE Data Office. We'd rather you tell us first at ibrahim@finacra.com so we can fix it.
We respond to rights requests within 30 days (the strictest of DPDP/GDPR windows). Identity verification: we'll use the email on record; if it's been compromised, ask via a verified support channel.
6. Cross-border transfer
Finacra runs on Vercel (United States) with database hosting on Supabase (Postgres in the AWS Seoul region, ap-northeast-2) and LLM inference via providers in multiple jurisdictions. When data crosses a border we rely on:
- GDPR/UK GDPR: Standard Contractual Clauses (2021 module 2 + module 3) with each sub-processor.
- DPDP: we transfer only to countries that are not on the negative-list notified under DPDP Sec 16, and only for purposes you'd reasonably expect from a SaaS platform.
- PDPL: for Saudi entities we offer in-region deployment options on request.
- UAE: we observe Federal Decree-Law 45/2021 Art. 22 cross-border requirements.
The complete list of sub-processors with their regions, contact details, and DPA references is on our Sub-processors page.
7. How we protect it
All data is encrypted in transit (TLS 1.3) and at rest. Secret values (OAuth tokens, portal credentials) use AES-256-GCM application-layer encryption on top of disk encryption. RBAC scopes access to the company (or set of companies) you're a member of. Sign-in supports email magic link + Google OAuth, with database-backed sessions.
The detailed security controls — vulnerability disclosure, incident response, audit-log scope, MFA roadmap — are on the Security posture page.
8. If something goes wrong (breach notification)
If a personal-data breach occurs we notify affected customers within 72 hours of becoming aware (the GDPR window), and notify the Data Protection Board of India within the DPDP window (currently 72 hours from awareness, as set by Rule 7 of the DPDP draft rules). Notification includes nature, categories, approximate numbers, containment, and remediation.
9. Children
Finacra is a B2B compliance tool; we don't intend to process the data of anyone under 18. DPDP Sec 9 + GDPR Art. 8 children's-data rules apply if a child's information enters Finacra inadvertently (e.g. as a beneficiary listed in a director's declaration). In that case we will process only the minimum necessary for the statutory record and delete on request from the verifiable parent / guardian.
10. Changes to this Policy
When we update this Policy we bump the version constant (currently 2026-06-25) and require fresh consent before further company-create actions. Active users see a banner. The version + your IP at acceptance time are persisted as an audit record.
11. Contact
DPO / privacy: ibrahim@finacra.com
Security incidents: ibrahim@finacra.com
Legal: legal@finacra.co