Redirect to fintable.io →

Privacy & Security

This notice explains how Fintable handles personal data when you visit our websites, use our service or contact us. Our public subprocessor register identifies service providers, their purposes and known processing locations. Our security and compliance documents describe our security program.

1. Who we are

Fintable is operated by Fintable LLC, Ukraine (ТОВ «ФІНТЕЙБЛ», Ukrainian company registration number 45534002). Contact us about privacy or to exercise your rights at [email protected].

We act as a controller for customer relationships, billing, support, security and website activities whose purposes we determine. When an organization uses Fintable to process personal data on its behalf, we act as its processor, or as a subprocessor where that organization is itself a processor. That organization determines the purposes and instructions for its client data. This notice does not replace a data-processing agreement or authorize new uses of that data.

2. Data we collect and its sources

  • Account and Workspace data: names, email addresses, organization details, account identifiers, authentication information, preferences, membership and permissions, supplied by you or your Workspace administrator.
  • Financial data: account names and identifiers, balances, transactions, descriptions, counterparties, categories and investment holdings, supplied by the bank or financial-data provider you connect. Descriptions can reveal information about other people or sensitive matters.
  • Integration data: connection identifiers, access and refresh tokens, API keys, selected destinations, spreadsheet or database identifiers, field mappings and synchronization results, from you and authorized services. Bank authorization normally takes place with the bank or connection provider; we retain tokens needed to maintain the connection.
  • Billing data: subscription and order details, payment status, amounts, currency, billing contacts, provider references and limited payment-method details. Payment providers collect full card details through their payment flows; we do not store full card numbers.
  • Support and feedback: messages, attachments, screenshots and information supplied during an investigation, including relevant account, financial and destination data.
  • Technical and usage data: IP addresses, browser and device information, timestamps, visited pages, referrals, cookie identifiers, account activity and diagnostic logs. API and integration logs can contain request or response content, with secret redaction and size limits.

Contact and authentication details are needed to create and secure an account. A connection and its permitted financial data are needed for synchronization; billing details are needed for a paid subscription. Without them, we cannot provide the corresponding service. Marketing participation is optional.

Where we act as controller and the GDPR applies:

  • Service and pre-contract enquiries: performance of our contract with you, or steps you request before a contract. For an organization's representatives, our legitimate interest is administering that business relationship.
  • Billing, record keeping and legal requests: contract performance and applicable accounting, tax and other legal obligations.
  • Support, troubleshooting and security: our legitimate interests in resolving problems, preventing misuse and keeping the service reliable. For data processed on a customer's behalf, we follow its instructions and applicable processing terms.
  • Understanding use and improving Fintable: our legitimate interest in understanding performance and usability. Consent is required where applicable law requires it for cookies or similar tracking.
  • Marketing and advertising measurement: consent where required, or a permitted legitimate interest in communicating relevant offers to existing customers. You may object to direct marketing at any time.

Our interests do not override your rights. This notice is not blanket consent to process your clients' data for our own purposes.

4. Recipients and AI assistance

Authorized Fintable personnel and suppliers involved in delivery networks, backups, email, AI assistance, analytics and payments may access relevant data to operate, secure and support the service. See the subprocessor register for their purposes and roles.

Workspace administrators and authorized team members may access data according to their permissions. Banks and connection providers exchange information for connections you authorize. Destinations such as Airtable, Google Sheets and Notion receive data you choose to synchronize and process their copies under their own terms. Professional advisers and authorities may receive information needed to comply with law or establish, exercise or defend legal claims.

Fintable's AI services assist support investigations, searches of related enquiries, attachment interpretation, reply drafting, engineering and security work. They can process correspondence, screenshots, diagnostic logs and relevant personal or financial data. Category-rule assistance can process your prompt and example transaction. The register identifies providers and fallback services. Retention and model-training terms vary by provider and account; we do not claim identical protections across them.

AI assistants you connect through MCP can request profile, Workspace, connection, account, transaction, holding, category and integration information within their permitted access, and perform available authorized actions. Tool results do not return passwords or provider access tokens. Your chosen provider receives results under its own terms and may retain them independently. Disconnect it from Security → API tokens & connected apps to stop future access; this does not remove copies already received. This is separate from Fintable's own AI assistance.

Security engineering: Fintable participates in Anthropic's Cyber Verification Program. Engineering material and security-research activity may be subject to Anthropic's monitoring under that program. Diagnostic material can contain customer data; it is not necessarily free of personal or financial information.

5. Locations and international transfers

Fintable's servers are hosted in Ukraine, except where an agreement or law requires otherwise. For example, data from Akoya connections is hosted in the United States.

We keep encrypted backups in Ukraine and an encrypted off-site backup in Frankfurt, Germany. Controlled support, development and recovery environments can also contain production copies. Their complete country and remote-access inventory is still being verified.

Suppliers may process data elsewhere, including the United States and, for the configured DeepSeek AI fallback, China. Headquarters do not establish processing location. See the register for known locations and outstanding verification. This notice does not promise EU-only processing.

Where GDPR transfer rules apply, transfers require an applicable adequacy decision or another lawful mechanism, such as appropriate standard contractual clauses and necessary supplementary measures. We have not yet completed verification of contractual transfer safeguards for every processing route. We do not assert that clauses have been executed with every supplier or that its published terms alone establish coverage for Fintable. Contact [email protected] for the safeguards applicable to a proposed arrangement and copies of applicable safeguards, subject to necessary redactions.

6. Retention

  • Account and financial data: maintained for the account, connection, synchronization history and API access. Disconnecting a bank or deleting an account starts the relevant financial-data cleanup. Account deletion is asynchronous and retains an account record that permits restoration; it does not immediately erase every record about you. Contact us to request erasure of remaining personal data.
  • Application, API and MCP log files: configured to rotate after 30 days. Detailed outbound-provider HTTP log files rotate after 2 days. These periods do not cover every support record, event record or backup.
  • Support and investigation records: retention depends on resolving and following up on enquiries, maintaining relevant support history, investigating security incidents and handling disputes.
  • Billing and legal records: retention depends on applicable accounting and tax obligations and the need to establish, exercise or defend legal claims.
  • Backups and investigation copies: live deletion does not immediately remove every copy. Retention depends on backup rotation, recovery requirements and the continuing investigation need. A single verified maximum period across all copies has not yet been established.
  • Marketing preferences: unsubscribe and objection records may be retained to respect your choice. Other marketing and analytics retention depends on purpose, provider settings and applicable law.

Your bank, destination and independently selected AI provider apply their own retention rules to their copies. Disconnecting them does not delete those copies.

7. Your rights

Depending on applicable law and circumstances, you may request access, correction, erasure, restriction of processing or a portable copy of your personal data. You may withdraw consent at any time without affecting earlier lawful processing.

You may object to processing based on legitimate interests, and to direct marketing at any time. Use an email's unsubscribe link or contact [email protected]. Essential account and service messages may still be necessary.

Send privacy requests to the same address. We may ask for information reasonably needed to verify identity. Where the GDPR applies, we respond without undue delay and normally within one month; we explain any permitted extension within that month. We will explain lawful exceptions where relevant. For data processed for an organization, we assist it in responding.

You may complain to the data-protection authority where you live, work or believe an infringement occurred. These include the Ukrainian Parliament Commissioner for Human Rights, the supervisory authority of your EU/EEA country and the UK's ICO.

8. Cookies and advertising

Cookies and similar storage support sign-in, security, preferences and attribution. Google Analytics can receive page and usage events, cookie and account identifiers, and subscription-purchase events. Where enabled, OpenAI advertising measurement receives advertising identifiers, browser and IP information, registration and checkout events, and hashed email or account identifiers. Hashing does not make these identifiers anonymous. These advertising events do not include connected bank transactions.

Manage cookies through your browser and contact us about marketing or advertising objections. Blocking cookies may affect sign-in and other features. This notice does not itself obtain consent or replace a consent choice where required.

9. Security, incidents and changes

We use access controls, encrypted connections, encrypted integration credentials, backups and monitoring. No system guarantees absolute security. Report suspected incidents to [email protected].

As processor, we notify the relevant controller of a personal-data breach without undue delay after becoming aware of it. As controller, we notify regulators and affected people when applicable law requires it. These notification commitments supersede longer periods in older security documents; any stricter legal or contractual deadline takes precedence.

We update this notice and the register as practices change; the date above identifies this version. Publication does not replace any further notice or consent required by law.

Language
Currency
Number Format