Privacy

Privacy Policy

How FinData4AI collects, uses, shares, protects, and retains account, billing, API usage, support, and security data.

Last updated: August 15, 2026Effective date: August 15, 2026

Payment data

Full card numbers are processed by Waffo Pancake or the payment provider shown at checkout.

API data

We process request metadata, usage logs, and diagnostics to operate, secure, and bill the service.

No sale

We do not sell personal information as defined by applicable privacy laws.

Rights window

Privacy requests are normally handled within 30 calendar days after verification.

This policy is written for a financial data API and SaaS service. If a signed data processing agreement, order form, or privacy addendum applies to your account, that document controls where it conflicts with this policy.

1. Data Controller

The data controller for the service is FinData4AI or the FinData4AI contracting entity identified in your checkout flow, invoice, order form, or enterprise agreement.

  • Privacy contact: [email protected]
  • Support contact: [email protected]
  • Security contact: [email protected]
  • Data Protection Officer: not appointed unless required for a specific enterprise agreement or jurisdiction.
  • Postal address: the address shown on the applicable invoice, order form, or contracting entity record.

2. Personal Information We Collect

We collect information you provide directly, information generated by your use of the service, and limited information from payment, identity, analytics, security, and infrastructure providers.

  • Account information: name, email address, organization, role, language preference, password hash, authentication metadata, and account settings.
  • Billing information: plan, billing region, tax or invoice details, transaction amount, renewal status, payment status, and limited payment method metadata. We do not store full card numbers.
  • API and product usage: API keys, endpoint usage, request timestamps, response status, credit consumption, rate-limit events, dashboard actions, feature usage, and diagnostics.
  • Device and network data: IP address, browser type, operating system, time zone, device identifiers, session identifiers, and approximate region derived from network information.
  • Support and communications: emails, tickets, forms, feedback, meeting notes, sales requests, and related attachments you send to us.
  • Security logs: authentication attempts, suspicious activity signals, abuse reports, audit logs, and operational incident data.

Do not send sensitive personal data, regulated secrets, or third-party confidential information through prompts, API parameters, support tickets, or uploaded files unless your agreement permits it and appropriate safeguards are in place.

3. How We Use Personal Information

PurposeLegal basis
Provide and maintain the service, APIs, dashboard, documentation, and supportContract performance
Process billing, subscriptions, credits, invoices, taxes, and renewalsContract performance / legal obligation
Authenticate users, manage API keys, and secure accountsContract performance / legitimate interests
Measure usage, enforce rate limits, monitor reliability, and troubleshoot errorsLegitimate interests
Detect fraud, abuse, security incidents, and prohibited useLegitimate interests / legal obligation
Improve product quality, documentation, coverage, and customer experienceLegitimate interests
Send service notices about billing, security, policy updates, and operational changesLegitimate interests / contract performance
Send marketing communications where permittedConsent or legitimate interests, depending on jurisdiction
Comply with laws, enforce terms, and respond to lawful requestsLegal obligation / legitimate interests

We may aggregate or de-identify information so it no longer identifies a specific person. We may use such data for analytics, reliability, product improvement, benchmarking, and business reporting.

4. Cookies and Tracking Technologies

TypePurposeCan be disabled
Strictly necessaryAuthentication, sessions, security, checkout, and core service operationNo
FunctionalLanguage, theme, dashboard preferences, and saved settingsYes
AnalyticsUsage statistics, performance measurement, product improvement, and error analysisYes
MarketingCampaign attribution and marketing effectiveness where enabledYes

You can control cookies through browser settings and, where available, the product cookie preferences interface. Disabling non-essential cookies may reduce personalization or analytics accuracy but should not block core service access.

5. Sharing and Disclosure

We do not sell personal information, including as the term "sale" is defined under the California Consumer Privacy Act and similar privacy laws. We share information only as needed for the purposes below.

  • Service providers: cloud hosting, databases, observability, analytics, customer support, communications, identity, security, and payment processors under confidentiality and data protection obligations.
  • Payment processors: payment card data is processed by Waffo Pancake or the PCI-DSS compliant provider shown at checkout and is not stored on FinData4AI application servers.
  • Enterprise administrators: if your account belongs to an organization, account administrators may see users, roles, API keys, usage, billing, and audit information for that organization.
  • Data providers and compliance partners: limited information may be shared where needed to comply with licensing, market data, abuse prevention, or contractual data obligations.
  • Legal and regulatory recipients: courts, regulators, law enforcement, tax authorities, or other parties when required by law or to protect rights, safety, and security.
  • Business transactions: information may be transferred in connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to continuing protection obligations.
  • With your consent: we may share information for other purposes when you instruct us or give consent.

6. Data Security

  • Transport encryption using TLS / HTTPS.
  • Hashed or encrypted handling for passwords and sensitive credentials.
  • Access controls based on least privilege and role separation.
  • Operational logging, monitoring, vulnerability management, and incident response procedures.
  • API key controls, rate limiting, abuse detection, and security review for privileged access.

No system is perfectly secure. If a security incident is likely to materially affect your rights or obligations, we will notify affected users and regulators as required by law, and where legally required we aim to do so within 72 hours after confirmation.

7. Retention

Data typeTypical retentionHandling after retention
Account profile and organization dataAccount lifetime plus 90 days after closureDelete or anonymize unless needed for legal or security reasons
Billing, invoices, and tax records7 years or the period required by applicable lawArchive securely, then delete or anonymize
API usage, credits, and rate-limit logs24 months unless a plan or order form states otherwiseDelete, aggregate, or anonymize
Security and audit logs12 months unless needed for investigation or complianceSecure deletion or restricted archive
Support tickets and communications3 years after resolutionDelete or anonymize
Marketing preferencesUntil you unsubscribe or the data is no longer neededSuppress, delete, or anonymize

8. Your Privacy Rights

Depending on your location, you may have the rights below. To exercise rights, contact [email protected]. We may need to verify your identity and authority before fulfilling a request.

RightDescription
Know / be informedUnderstand what personal information we collect and how we use it
AccessReceive a copy of personal information we hold about you
CorrectionCorrect inaccurate or incomplete information
DeletionRequest deletion where legally available
RestrictionAsk us to restrict certain processing
PortabilityReceive certain data in a machine-readable format
ObjectionObject to processing based on legitimate interests or direct marketing
Withdraw consentWithdraw consent for processing based on consent
Opt out of sale or sharingWe do not sell personal information, but you may contact us with opt-out requests where applicable

We normally respond within 30 calendar days after verification unless law allows or requires a different timeline. You may also complain to your local data protection authority.

9. Marketing Communications

Where permitted, we may send product updates, educational content, event invitations, offers, or market coverage announcements. You can opt out by using the unsubscribe link in an email, adjusting account settings where available, or contacting us.

Opting out of marketing does not stop service-required messages such as billing, security, policy, support, or operational notices.

10. International Transfers

FinData4AI, its infrastructure, and its service providers may process information in the United States, Singapore, the European Economic Area, Hong Kong, mainland China, and other locations where we or our providers operate.

When personal information is transferred internationally, we use safeguards such as data processing agreements, standard contractual clauses where applicable, access controls, security measures, and transfer assessments required by law.

11. Children

FinData4AI is intended for users who are at least 18 years old and for business or professional use. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information, contact us so we can take appropriate action.

12. Third-Party Links and Services

The service may link to or integrate with third-party websites, data providers, payment providers, identity providers, analytics tools, support tools, and developer platforms. Their privacy practices are governed by their own policies, not this policy.

13. Changes to This Policy

We may update this policy from time to time. If changes are material, we will provide notice through the service, by email, or another reasonable method at least 15 days before they take effect when practicable.

14. Contact Us

For privacy questions, requests, or complaints, contact us using the channels below. Please include your account email and describe the request clearly so we can verify and process it.

Privacy contacts

We route privacy and security requests to the appropriate internal owner.