Privacy Policy
This Privacy Policy describes how Finsider handles personal information in connection with its websites, communications, account access, financial-screening tools, software workspaces, research content, and professional-service relationships. It distinguishes information collected for our own business purposes from records processed on an organization's instructions. References to Finsider, we, us, or our mean the Finsider service provider identified in your applicable order form or engagement agreement.
1. Scope and relationship to customer agreements
This notice applies to visitors, prospective customers, business contacts, account users, and individuals communicating with Finsider. An organization's financial records may contain personal information about employees, customers, suppliers, shareholders, or other individuals. Where we process those records on that organization's behalf, the applicable services agreement, data-processing terms, and documented instructions determine our role and permitted processing. This notice does not replace those terms or authorize a use of customer records beyond them.
An organization using our services is responsible for identifying a lawful basis to provide information, issuing required notices, and handling requests for records it controls. If your information was uploaded by a customer, contact that organization first. We may refer a request to the relevant customer rather than disclose, change, or delete information contrary to its lawful instructions.
2. Information you provide
Depending on the interaction, information may include your name, business email address, company, role, contact details, inquiry content, product interests, meeting details, support requests, and correspondence. Account administration may involve authentication identifiers, organization membership, assigned permissions, account settings, and records of access or security events. Do not include passwords, complete payment-card details, government identifiers, or unrelated sensitive information in general contact forms.
Where an engagement or product permits uploads, source materials may include financial statements, ledgers, accounting exports, bank records, invoices, payroll records, contracts, transaction descriptions, and supporting documents. These materials may reveal personal, financial, or commercially confidential information. Customers should limit uploads to materials necessary for the agreed purpose and ensure they are authorized to provide them.
3. Technical information and cookies
Web infrastructure may process IP addresses, browser and device characteristics, requested pages, timestamps, referring pages, connection information, and diagnostic or security events. Authentication and session technologies may be necessary to recognize a signed-in user, protect an account, and maintain service functionality. Cookies or similar storage can also support preferences and other enabled features.
The technologies present depend on the page, deployment, and services enabled. Where optional technologies require consent, they should not be treated as necessary merely because they are useful. Use an available cookie control or browser setting to manage storage. Blocking essential authentication storage may prevent sign-in or other functionality. This policy does not state that every page uses analytics or advertising technologies.
4. Purposes of processing
We use information as appropriate to respond to requests; arrange and administer services; authenticate users; provision organizations and permissions; process authorized records; prepare requested analyses and deliverables; support collaboration and review; investigate faults; prevent abuse; protect confidentiality; maintain relevant business records; and satisfy applicable obligations. Communications may concern requested services, account administration, security, support, or marketing where permitted.
We seek to limit personal information to what is reasonably needed for the purpose. A new, materially different use may require an updated notice, additional consent, or other authorization. Publication of a revised policy alone does not override a contractual confidentiality restriction or supply consent where consent is legally required.
5. Financial analysis, AI agents, and professional review
Selected workflows may use AI models or agents to organize records, propose mappings, identify possible adjustments, summarize evidence, draft questions, or support analysis. Inputs, outputs, and relevant context may be processed by the providers and infrastructure configured for that service. The processing location, retention settings, and permitted uses must be evaluated for the applicable deployment and agreement; they are not identical across every product.
Automated outputs may be incomplete or incorrect and may contain information derived from confidential source records. Treat them with the same access restrictions appropriate to the underlying materials. Addback screening is not an audit or assurance opinion. Professional review and any CPA sign-off depend on the agreed engagement. An automated finding must not be treated as a final determination about an individual without the appropriate verification and legal basis.
This notice does not grant an unrestricted right to use confidential customer records for general-purpose model training. Any such use must have an applicable authorization and comply with contractual and legal restrictions. Customers should obtain product-specific processing and provider information before submitting sensitive data rather than infer a universal no-retention or no-training configuration from general website descriptions.
6. Minimization, anonymization, and derived records
Data minimization, removal of unnecessary identifiers, pseudonymization, or anonymization may be used where appropriate to a workflow. Pseudonymized information can remain personal information if it can reasonably be linked back to a person. Removing names alone does not necessarily anonymize a financial dataset. Source-lineage features may deliberately retain identifiers, hashes, citations, or links needed for authorized review.
Anonymization must be assessed in context, including the possibility of reidentification through other records. We do not represent that every uploaded file, processing step, output, or log is anonymous. Aggregated or deidentified information remains subject to any applicable restrictions, and information that is still reasonably identifiable must continue to be handled accordingly.
7. Service providers and authorized recipients
Information may be made available to personnel, contractors, and service providers with a relevant operational need, including providers of hosting, authentication, communications, support, storage, security, and enabled AI processing. Clerk is used for supported account authentication; supported website communications may use Resend. The complete provider set depends on the product and configuration. Provider access is not a statement that every provider receives every category of information.
Within a customer organization, administrators and authorized collaborators may access information according to their roles and the service's permission model. Information may also be disclosed to professional advisers, in response to a binding legal requirement, to protect legal rights or service security where permitted, or in connection with a corporate transaction subject to appropriate restrictions. We do not authorize a recipient to disregard applicable confidentiality or purpose limitations.
8. International processing and sovereignty requirements
A service provider, support function, or infrastructure component may operate outside your province, state, or country. Cross-border processing can make information subject to the laws and lawful access requirements of another jurisdiction. A general statement about data sovereignty is not a guarantee of processing exclusively in a particular location.
If your organization requires a specified region, restrictions on remote access, a particular transfer mechanism, or other residency controls, those requirements must be assessed and documented before onboarding. Applicable agreements should identify the approved scope and safeguards. Do not upload restricted data on the assumption that an unconfirmed residency requirement has already been met.
9. Retention, deletion, and backups
Retention depends on the category of information, service configuration, engagement instructions, operational needs, security requirements, and applicable legal or professional obligations. Source uploads, derived reports, reviewer decisions, authentication records, support communications, and security logs may have different lifecycles. A product's successful-run cleanup does not imply identical handling for failed runs, interrupted processing, backups, or separately retained outputs.
Deletion from an active interface may not immediately remove every copy from backups, recovery systems, or legally required records. Retained copies should remain subject to applicable controls until their authorized lifecycle ends. Customers should confirm retention and export requirements before ending an engagement or deleting a workspace. We do not promise a universal deletion period for all products in this notice.
10. Security and confidentiality
Security depends on a combination of technical, organizational, contractual, and user controls appropriate to the service. Relevant measures may include authentication, scoped permissions, access restriction, encryption supported by infrastructure, monitoring, secure operational practices, and review processes. Customers remain responsible for appropriate user provisioning, endpoint security, account protection, and the lawful selection of material they upload.
No internet transmission or information system can be guaranteed completely secure. Ask for current security documentation applicable to the exact service and deployment under review. This notice does not itself certify a product, extend an audit's scope, or promise a particular certification level. If a security incident creates notification duties, notifications will be handled under applicable law and relevant contractual terms.
11. Your choices and privacy requests
Subject to applicable law and our role, you may be entitled to request access to personal information, correction of inaccuracies, deletion, restriction of certain processing, information about processing, or withdrawal of consent. Some jurisdictions also provide objection, portability, appeal, or other rights. These rights are not identical everywhere and may be subject to lawful exceptions, including confidentiality owed to others and required record retention.
Submit a privacy request through the Finsider contact channel used for your engagement or the contact form available on this website, clearly identifying it as a privacy request. Provide enough context to locate the relevant records without sending unnecessary sensitive information. We may need proportionate identity or authority verification. If we act on another organization's instructions, we may assist that organization with the request instead of independently deciding it.
12. Communications preferences
You may ask us to stop optional promotional communications through an available unsubscribe mechanism or by contacting us. A marketing opt-out does not ordinarily stop necessary account, security, transaction, support, or engagement communications. Withdrawing consent may affect a service that genuinely depends on the withdrawn processing; it does not automatically invalidate processing lawfully completed beforehand.
13. Children and third-party services
Finsider's financial diligence offerings are intended for business and professional use, not services directed to children. Do not create an account or submit information on behalf of a child without an appropriate legal basis and service authorization. If you believe information has been submitted improperly, contact us so the circumstances can be assessed.
External websites, integrations, and services operate under their own terms and privacy notices. A link, published paper, or integration listing does not mean Finsider controls another provider's practices. Review those terms before independently disclosing information to that provider.
14. Changes, questions, and complaints
We may revise this notice to reflect changes in services, processing, or legal requirements. The published revision date identifies the version; where required, material changes will require additional notice or consent. An updated notice does not retrospectively erase a contractual commitment. Keep a copy of the version relevant to your relationship if needed.
Raise questions or complaints through your established Finsider contact channel and describe the concern and requested resolution. Applicable law may permit a complaint to a privacy regulator in addition to contacting us. This notice does not limit rights or remedies that cannot lawfully be limited.