Terms of Service & Privacy Policy
1. What Finacra does
Finacra is an agentic compliance, accounting, and reporting platform. We process company information you provide — registration identifiers, financial facts, employee headcount, documents, integration data — to generate compliance trackers, file-ready reports, and operational recommendations.
2. Data we process
- Identifiers (PAN, TAN, CIN, LLPIN, GSTIN, CR, VAT TIN, etc.).
- Compliance facts you declare (turnover, headcount, payroll, ownership).
- Documents you upload (returns, certificates, registrations, payslips).
- Integration data you authorise (accounting ledgers, payroll, banking).
- Operational metadata (logins, IP, audit trail of edits).
3. Purposes
We use the data above to (a) generate the compliance calendar that drives the Tracker, (b) classify and link documents in the Vault, (c) compute amounts, penalties, and reports, (d) issue reminders, and (e) deliver agentic recommendations that you review before execution.
4. Data-protection law
We process the data above in compliance with the laws applicable to the company you onboard, including:
- DPDP Act 2023 (India) for Indian entities.
- PDPL (Royal Decree M/19) for Saudi Arabian entities.
- UK GDPR for entities in the United Kingdom.
- UAE Federal Decree-Law 45/2021 for entities in the UAE.
5. Cross-border transfer
Finacra hosts data on cloud infrastructure that may reside outside the country in which the data was collected. We rely on standard contractual clauses and the cross-border-transfer mechanisms permitted by each governing law above. When a jurisdiction requires in-region hosting (e.g. specific PDPL tiers), we will surface that requirement and offer a compliant deployment before you onboard.
6. Retention & deletion
We retain company data for as long as the company is active in Finacra plus the statutory retention period applicable to the underlying records (typically 7 years for tax-relevant data). On deletion request, we delete primary records within 30 days; audit trail and statutory copies survive until their retention period expires.
7. Sub-processors
We use third-party processors for hosting, AI inference, document OCR, email delivery, and your authorised accounting / payroll / banking integrations. The complete list, with each vendor's region and DPA link, is published at /sub-processors. Material additions are notified 30 days in advance via email + an in-app banner.
8. Your rights
Across DPDP, GDPR/UK GDPR, PDPL, and UAE Federal Decree-Law 45/2021, you have:
- Access — get a JSON copy of everything we hold via /me/data-export (self-service).
- Rectification — correct any field on the Manage tab; the audit log captures the edit.
- Erasure — delete your account + all associated data via /me/delete-account (30-day grace).
- Portability — same export endpoint, machine-readable JSON.
- Withdraw consent — anytime, for the consent recorded at company-create.
DPO: ibrahim@finacra.com. Full rights detail, lawful-bases mapping, and retention windows are at /privacy. Our processor-side contract is at /dpa. Security posture is at /security.
9. Acceptance
By ticking the consent box on the company-create form, you acknowledge you have read and agree to this Policy (version 2026-06-25) and the linked Privacy Policy, Data Processing Agreement, Sub-processors list, and Security posture, for the company you are onboarding. We persist your acceptance with a timestamp and your IP address as the audit record. When this Policy is updated to a new version, we will require fresh acceptance before further company-create actions.