Privacy Policy
Effective Date: March 10, 2026
This document is currently maintained in English only. Contact us if you need assistance in another language.
1. Introduction
Welcome to Financial Suite ("Financial Suite," "we," "us," or "our"). Financial Suite is an AI-first fintech software-as-a-service company headquartered in Wilmington, Delaware, United States. We are committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website at financial-suite.ai, use our products and services (including Financial Suite, ProAnalysis, InvestPlus, BudgetPlus, and BizAnalysis), or otherwise interact with us. It applies to all users of our platform, including visitors, trial users, paying subscribers, and business contacts.
By accessing or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please discontinue use of our services immediately.
This Privacy Policy should be read in conjunction with our Terms of Service, Cookie Policy, and GDPR Compliance documentation, which together form the complete legal framework governing your use of Financial Suite.
2. Information We Collect
We collect various types of information to provide, maintain, and improve our services. The categories of data we collect include the following:
2.1 Personal Data You Provide Directly
When you create an account, request a demo, subscribe to our services, or contact us, you may provide us with personal data including but not limited to:
- Identity data: Full name, job title, company name, and professional role.
- Contact data: Email address, telephone number, and business mailing address.
- Account data: Username, password (stored in hashed form), account preferences, and notification settings.
- Financial data: Billing address, payment card details (processed securely via Stripe -- we do not store full card numbers on our servers), subscription plan, and transaction history.
- Communication data: Records of correspondence when you contact our support team, submit feedback, or participate in surveys.
- Form submission data: Information provided through our demo request forms, contact forms, and newsletter sign-up forms on our website.
2.2 Data We Collect Automatically (Usage Data)
When you access and use our website or platform, we automatically collect certain technical and usage information, including:
- Device and browser information: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
- Usage data: Pages visited, features used, time spent on pages, click patterns, navigation paths, search queries within the platform, and frequency of use.
- Log data: Server logs that record access times, referring URLs, error logs, and API request data.
- Performance data: Page load times, application response times, and error reports to help us identify and resolve technical issues.
- Location data: Approximate geographic location derived from your IP address (we do not collect precise GPS-based location data).
2.3 Cookies and Tracking Technologies
We use cookies, web beacons, pixels, and similar tracking technologies to collect information about your interactions with our website and services. These technologies help us:
- Remember your preferences and settings (including theme preferences).
- Authenticate your identity and maintain your session.
- Analyse website traffic and usage patterns.
- Measure the effectiveness of our marketing campaigns.
- Deliver relevant content and advertisements.
For detailed information about the specific cookies we use, their purposes, and how to manage your cookie preferences, please refer to our Cookie Policy.
2.4 Data from Third-Party Sources
We may also receive personal data about you from third-party sources, including:
- Business partners: Companies that refer customers to our services or integrate with our platform.
- Payment processors: Transaction confirmation and fraud prevention data from Stripe.
- Public sources: Publicly available business information from company registries, professional networking platforms, and industry directories.
3. How We Use Your Information
We use the personal data we collect for the following purposes:
3.1 Service Delivery and Operations
- To create, manage, and maintain your user account.
- To provide access to our financial analysis platform and related products.
- To process subscriptions, payments, and billing operations.
- To deliver AI-powered financial insights, reports, and analyses you request.
- To provide customer support and respond to your enquiries.
- To send transactional communications, including account confirmations, invoices, technical notices, and security alerts.
3.2 Analytics and Product Improvement
- To analyse how users interact with our platform to identify usage trends and improvement opportunities.
- To train, improve, and refine our AI and machine learning models to deliver better financial insights.
- To conduct A/B testing and evaluate new features before general release.
- To monitor platform performance, diagnose technical problems, and ensure system reliability.
- To generate aggregated, anonymised analytics reports for internal business purposes.
3.3 Marketing and Communications
- To send promotional emails about new products, features, special offers, or events that may be of interest to you (only with your prior consent where required by law).
- To personalise your experience and display content relevant to your interests and industry.
- To measure the effectiveness of our marketing campaigns and outreach efforts.
- To conduct market research and analyse customer demographics.
You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email, adjusting your notification preferences in your account settings, or contacting us at privacy@financial-suite.ai.
3.4 Legal and Compliance Obligations
- To comply with applicable laws, regulations, and legal processes, including EU financial regulations and data protection requirements.
- To enforce our Terms of Service and other contractual agreements.
- To detect, prevent, and investigate fraud, security breaches, and other prohibited or illegal activities.
- To protect the rights, property, and safety of Financial Suite, our users, and the public.
- To respond to lawful requests from public authorities, including law enforcement and regulatory agencies.
4. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR) and applicable EU data protection laws, we are required to have a valid legal basis for processing your personal data. We rely on the following legal bases depending on the specific processing activity:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into a contract. This includes processing to:
- Create and manage your Financial Suite account.
- Provide our SaaS platform and related services as specified in your subscription agreement.
- Process payments and manage your billing.
- Deliver customer support in relation to services you have purchased.
4.2 Consent (Article 6(1)(a) GDPR)
For certain processing activities, we rely on your freely given, specific, informed, and unambiguous consent. This includes:
- Sending you marketing and promotional communications.
- Placing non-essential cookies on your device (see our Cookie Policy).
- Processing special categories of data, where applicable.
Where consent is the legal basis, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
We may process your personal data where it is necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by your rights and freedoms. Our legitimate interests include:
- Improving and optimising our platform, AI models, and user experience.
- Ensuring network and information security, including preventing unauthorised access and cyber threats.
- Conducting business analytics and internal reporting.
- Preventing fraud and enforcing our legal rights.
- Communicating with existing customers about products and services similar to those previously purchased.
4.4 Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where necessary to comply with a legal obligation to which we are subject, including:
- Tax reporting and financial record-keeping requirements under U.S. federal and state law.
- Responding to binding requests from regulatory authorities and courts.
- Complying with anti-money laundering (AML) and know-your-customer (KYC) regulations where applicable to our financial software services.
For a comprehensive overview of your rights under the GDPR and how we fulfil our obligations as a data controller, please refer to our dedicated GDPR Compliance page.
5. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data to third parties for their marketing purposes. We share your personal data only in the following limited circumstances and with appropriate safeguards in place:
5.1 Service Providers and Processors
We engage trusted third-party service providers who process personal data on our behalf to help us operate and deliver our services. These providers are contractually bound to process your data only as instructed by us and in accordance with applicable data protection laws. Our key service providers include:
- Stripe (Payment Processing): We use Stripe to securely process all subscription payments and transactions. Stripe acts as an independent data controller for payment data. Please refer to Stripe's Privacy Policy for details on how they handle your payment information.
- Amazon Web Services (AWS) (Cloud Hosting and Infrastructure): Our platform, databases, and application infrastructure are hosted on AWS data centres. AWS processes data on our behalf under strict data processing agreements with appropriate security measures.
- Analytics Providers: We use analytics tools to understand how our website and platform are used. These tools may collect data such as pages visited, session duration, and interaction patterns. Data collected through analytics is used solely for improving our services and is processed in accordance with our Cookie Policy.
5.2 Business Transfers
In the event of a merger, acquisition, reorganisation, sale of assets, or bankruptcy, your personal data may be transferred as part of the transaction. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
5.3 Legal and Regulatory Disclosures
We may disclose your personal data if required to do so by law or in response to valid legal process, including:
- Court orders, subpoenas, or other legally binding requests.
- Requests from law enforcement or governmental authorities with proper jurisdiction.
- To protect the rights, safety, and property of Financial Suite, our users, or the public.
- To detect, prevent, or address fraud, security vulnerabilities, or technical issues.
5.4 With Your Consent
We may share your personal data with third parties when you have explicitly consented to such sharing, for example, when you choose to integrate your Financial Suite account with a third-party application or service.
6. International Data Transfers
Financial Suite is headquartered in the United States (Wilmington, Delaware) and primarily stores and processes personal data within the United States. When we process personal data of individuals in the European Economic Area (EEA), we comply with GDPR requirements for international data transfers.
6.1 Safeguards for International Transfers
When we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place to protect your data in compliance with the GDPR and applicable data protection laws. These safeguards include:
- EU-US Data Privacy Framework: Where applicable, we rely on the EU-US Data Privacy Framework for transfers to certified organisations in the United States.
- Standard Contractual Clauses (SCCs): We enter into EU Commission-approved Standard Contractual Clauses with data recipients outside the EEA to ensure an adequate level of data protection. These clauses impose contractual obligations on the data recipient to protect personal data and provide data subjects with enforceable rights and effective legal remedies.
- Adequacy Decisions: Where the European Commission has determined that a third country provides an adequate level of data protection, we may transfer data to recipients in that country without additional safeguards.
- Transfer Impact Assessments: For transfers relying on SCCs, we conduct transfer impact assessments to evaluate whether the legal framework of the destination country provides adequate protection for personal data and, where necessary, implement supplementary measures.
6.2 Specific Transfers
Our primary international data transfers include:
- AWS (United States): Application hosting and data storage infrastructure. Transfers are governed by Standard Contractual Clauses and AWS's compliance with the EU-US Data Privacy Framework.
- Stripe (United States): Payment processing. Stripe is certified under the EU-US Data Privacy Framework and employs Standard Contractual Clauses for data transfers.
You may request a copy of the specific safeguards applied to international transfers of your data by contacting us at privacy@financial-suite.ai.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal obligations, to resolve disputes, and to enforce our agreements. The specific retention periods depend on the type of data and the purpose of processing:
| Data Category | Retention Period | Justification |
|---|---|---|
| Account data | Duration of account plus 12 months after deletion request | Contract performance; transition period for data export |
| Financial and billing data | 7 years after the end of the financial year in which the transaction occurred | U.S. federal and state tax and accounting regulations |
| Communication records | 3 years from the date of the last communication | Customer support quality; dispute resolution |
| Usage and analytics data | 24 months from the date of collection | Platform improvement and analytics; legitimate interest |
| Marketing consent records | Duration of consent plus 3 years after withdrawal | Proof of consent under GDPR requirements |
| Server logs | 90 days | Security monitoring and incident investigation |
| Cookie data | As specified in our Cookie Policy | Varies by cookie type and purpose |
| Demo request form data | 12 months from submission if no account is created | Sales follow-up; legitimate interest |
When personal data is no longer required, we securely delete or anonymise it. Anonymised data that cannot be used to identify you may be retained indefinitely for statistical and analytical purposes.
8. Your Rights
Under the GDPR and applicable EU data protection laws, you have the following rights with respect to your personal data. We are committed to facilitating the exercise of these rights in a timely and transparent manner.
8.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether your personal data is being processed, and if so, to request access to that data along with information about the purposes of processing, the categories of data concerned, and the recipients to whom the data has been disclosed.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data. You can update much of your information directly through your account settings.
8.3 Right to Erasure (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, or when you withdraw your consent. Please note that this right is not absolute and may be subject to legal retention obligations.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request restriction of processing of your personal data in certain circumstances, for example, when you contest the accuracy of the data or when the processing is unlawful but you oppose erasure.
8.5 Right to Data Portability (Article 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance, where the processing is based on consent or contract and carried out by automated means.
8.6 Right to Object (Article 21 GDPR)
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. Where you object to processing for direct marketing, the processing will cease immediately.
8.7 Right Not to Be Subject to Automated Decision-Making (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. While our AI-powered tools assist in financial analysis, final decisions with legal or significant effects are not made solely by automated means.
8.8 Exercising Your Rights
To exercise any of the rights described above, please contact our privacy team at privacy@financial-suite.ai. We will respond to your request within 30 days as required by the GDPR. In exceptional circumstances where the complexity or volume of requests warrants it, we may extend this period by an additional 60 days, in which case we will notify you of the extension and the reasons for it.
We may need to verify your identity before processing your request to ensure the security of your personal data. Requests are free of charge unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
If you are unsatisfied with our response or believe that your data protection rights have been infringed, you have the right to lodge a complaint with a supervisory authority in your country of residence within the EEA.
For comprehensive details on your GDPR rights and how we comply with EU data protection regulations, please visit our GDPR Compliance page.
9. Security Measures
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction. Our security measures include:
9.1 Encryption
- In transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS). This ensures that your data cannot be intercepted during transmission.
- At rest: Personal data stored on our servers and databases is encrypted using AES-256 encryption. Encryption keys are managed through AWS Key Management Service (KMS) with strict access controls.
- Passwords: User passwords are hashed using industry-standard bcrypt algorithms and are never stored in plain text.
9.2 Access Controls
- Role-based access control (RBAC): Access to personal data within our organisation is restricted on a need-to-know basis. Only authorised personnel with specific roles can access particular types of data.
- Multi-factor authentication (MFA): We enforce multi-factor authentication for all internal systems and administrative access to production environments.
- Principle of least privilege: Employees are granted the minimum level of access necessary to perform their duties, and access permissions are regularly reviewed and updated.
9.3 Monitoring and Auditing
- Security audits: We conduct regular internal and external security audits and vulnerability assessments to identify and remediate potential security weaknesses.
- Penetration testing: Independent third-party penetration testing is performed periodically to evaluate the effectiveness of our security controls.
- Logging and monitoring: We maintain comprehensive audit logs of access to personal data and monitor our systems for suspicious activity around the clock.
- Incident response: We maintain a documented incident response plan and a dedicated security team to handle data breaches or security incidents promptly. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay, as required by the GDPR.
9.4 Organisational Measures
- Employee training: All employees and contractors receive regular data protection and information security training.
- Confidentiality agreements: All personnel with access to personal data are bound by contractual confidentiality obligations.
- Data protection by design and by default: We incorporate data protection principles into the design and development of our products and services from the outset.
While we implement robust security measures, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to continuously improving our security posture to protect your data.
10. Children's Privacy
Financial Suite is a professional business-to-business (B2B) financial analysis platform. Our services are not directed at, designed for, or intended to be used by individuals under the age of 16. We do not knowingly collect, solicit, or process personal data from children under 16 years of age.
If we become aware that we have inadvertently collected personal data from a child under 16, we will take immediate steps to delete that information from our systems. If you believe that we have collected data from a child under 16, please contact us immediately at privacy@financial-suite.ai so that we can take appropriate action.
Parents or guardians who believe their child may have provided personal data to Financial Suite are encouraged to contact us using the details provided in the Contact Us section below.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes to this policy, we will:
- Update the "Effective Date" at the top of this page.
- Post a prominent notice on our website informing you of the changes.
- Where required by law or where changes materially affect how we process your personal data, send you a direct notification by email to the address associated with your account.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data. Your continued use of our services after any changes become effective constitutes your acknowledgement of the revised policy.
Previous versions of this Privacy Policy are available upon request by contacting us at privacy@financial-suite.ai.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please do not hesitate to contact us:
Financial Suite -- Data Protection
Data Controller: Financial Suite, Inc.
Email: privacy@financial-suite.ai
Address: Wilmington, Delaware, United States
We aim to respond to all legitimate enquiries within 30 days. If your request is particularly complex or you have made multiple requests, it may take us longer, but we will notify you and keep you updated on the progress.
For issues specifically related to GDPR compliance, data subject access requests, or exercising your data protection rights, please visit our GDPR Compliance page or email us directly at privacy@financial-suite.ai.