Finacra

Privacy Policy

Version 2026-06-25 · Effective 25 June 2026
This Privacy Policy applies to the Finacra agentic-compliance platform served at app.finacra.com, app.itr.finacra.com, and the marketing sites at www.finacra.com, itr.finacra.com. It is read together with our Terms of Service, the Sub-processors list, the Security posture page, and the Data Processing Agreement.

1. Who we are (the controller)

Finacra Technologies (“Finacra”, “we”, “us”) is the data controller for information you provide directly to us (your account email, name, billing). For information you ingest into Finacra about your company, vendors, employees, and customers (ledger lines, payroll, invoices, contacts), you are the controller and we are your processor — see our DPA.

For DPDP correspondence (India), our Data Protection Officer is reachable at ibrahim@finacra.com. For GDPR/UK GDPR correspondence (EU/EEA/UK), the same DPO is the EU representative until we appoint a dedicated representative under Article 27.

2. What we collect, why, and how long we keep it

Every row below names a real data category we hold, the lawful basis under GDPR Art. 6 (which DPDP mirrors at Section 7), the purpose, and the retention window. We don't collect anything not on this list.

CategoryExamplesLawful basisRetention
Account identityEmail, name (from Google OAuth or magic-link), profile photo URLContract (Art. 6(1)(b))Active account + 30 days post-deletion
Company profileCIN, PAN, TAN, registered address, directors, GST registrations, compliance profile (turnover, headcount, regime)ContractActive company + 7 years (statutory tax-records retention)
Compliance factsHas-imports/exports flag, rent-payments flag, voluntary PF/ESI, NIC code, MSME statusContractSame as company profile
Documents (Vault)Filings, certificates, payslips, invoices you uploadContractPer company until deleted + 30-day soft delete grace + statutory retention (typically 7yr)
Integration dataLedger / payroll / bank lines pulled via Zoho, QuickBooks, Tally, Marg, etc.ContractCached up to 90 days; re-fetched on demand. Encrypted OAuth tokens until you Disconnect.
Reminders + notificationsEmail / WhatsApp / SMS recipient addresses, delivery webhooks (Resend)ContractSent items: 1 year. Recipient addresses: until you remove the team member.
Audit + activity logsSign-in events, who edited what, consent timestamps, IP at consent timeLegitimate interest + legal obligation3 years from event
Operational telemetryLatency, error rates, route counts (no PII)Legitimate interest90 days

What we don't collect: we don't place advertising trackers, don't sell data to brokers, don't train AI models on your data, and don't enrich your records against third-party demographics or marketing databases.

3. How AI / LLM features handle your data

Several Finacra features (Ask, Forecast, Completeness Critic, document OCR + classification, the ITR canvas) call LLMs hosted by third parties. Your data is sent to the LLM provider only for the duration of the request and only the minimum slice needed for the task.

The full list of LLM and other sub-processors with regions and DPAs is on our Sub-processors page.

5. Your rights

You have the following rights across DPDP, GDPR/UK GDPR, PDPL, and the UAE Federal Decree-Law 45/2021. Where laws differ we apply the strictest treatment.

We respond to rights requests within 30 days (the strictest of DPDP/GDPR windows). Identity verification: we'll use the email on record; if it's been compromised, ask via a verified support channel.

6. Cross-border transfer

Finacra runs on Vercel (United States) with database hosting on Supabase (Postgres in the AWS Seoul region, ap-northeast-2) and LLM inference via providers in multiple jurisdictions. When data crosses a border we rely on:

The complete list of sub-processors with their regions, contact details, and DPA references is on our Sub-processors page.

7. How we protect it

All data is encrypted in transit (TLS 1.3) and at rest. Secret values (OAuth tokens, portal credentials) use AES-256-GCM application-layer encryption on top of disk encryption. RBAC scopes access to the company (or set of companies) you're a member of. Sign-in supports email magic link + Google OAuth, with database-backed sessions.

The detailed security controls — vulnerability disclosure, incident response, audit-log scope, MFA roadmap — are on the Security posture page.

8. If something goes wrong (breach notification)

If a personal-data breach occurs we notify affected customers within 72 hours of becoming aware (the GDPR window), and notify the Data Protection Board of India within the DPDP window (currently 72 hours from awareness, as set by Rule 7 of the DPDP draft rules). Notification includes nature, categories, approximate numbers, containment, and remediation.

9. Children

Finacra is a B2B compliance tool; we don't intend to process the data of anyone under 18. DPDP Sec 9 + GDPR Art. 8 children's-data rules apply if a child's information enters Finacra inadvertently (e.g. as a beneficiary listed in a director's declaration). In that case we will process only the minimum necessary for the statutory record and delete on request from the verifiable parent / guardian.

10. Changes to this Policy

When we update this Policy we bump the version constant (currently 2026-06-25) and require fresh consent before further company-create actions. Active users see a banner. The version + your IP at acceptance time are persisted as an audit record.

11. Contact

DPO / privacy: ibrahim@finacra.com
Security incidents: ibrahim@finacra.com
Legal: legal@finacra.co