Legal documents
Privacy Policy
How Finora collects, uses and protects your personal data, and what rights you have under the GDPR.
Last revised: 06 August 2026
Company details have not been filled in yet. This document is published with “[TO BE FILLED IN]” markers and does not comply with Art. 4 of the Electronic Commerce Act until they are entered.
This policy explains how [TO BE FILLED IN] processes personal data when you use the Finora web application. It is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.
This English version is provided for convenience. In case of discrepancy, the Bulgarian version prevails.
1. Who is the data controller
The controller of your personal data is:
- [TO BE FILLED IN], UIC [TO BE FILLED IN]
- Address: [ADDRESS TO BE FILLED IN]
- Email for data protection matters: [TO BE FILLED IN]
- Phone: [TO BE FILLED IN]
- Data Protection Officer: not appointed, as our activity does not fall within Art. 37 GDPR. Please direct questions to the email above.
2. What data we process
2.1. Data you provide directly
- Registration data: name, email address, password (stored solely as an irreversible bcrypt hash — we cannot see or recover it).
- Account settings: base currency, time zone, notification preferences, budget mode.
- Financial data you enter or upload: transactions (date, amount, description, category, notes), the names and IBANs of your own accounts, CSV bank statements, savings goals and contributions, recurring expenses and payees.
- Correspondence: the content of enquiries and complaints you send us.
2.2. Data generated through use
- Technical data: IP address, browser and device type, date and time of requests — in standard server and hosting provider logs, for security and diagnostics.
- Access data: last login date, issued session tokens (stored as hashes).
- Audit log: records of who performed key actions in the account and when (for example bulk deletion), for traceability during incidents.
2.3. Data from third parties
- From Stripe: payment and subscription status, customer and subscription identifiers, the last 4 digits and the type of the card. We never receive or store full card details.
- Referral code, if you arrived via a partner link.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account, providing the application's features | Performance of a contract — Art. 6(1)(b) GDPR |
| Processing payments and subscriptions, issuing accounting documents | Performance of a contract — Art. 6(1)(b) and legal obligation — Art. 6(1)(c) GDPR |
| Transactional emails (registration confirmation, password reset, failed payment) | Performance of a contract — Art. 6(1)(b) GDPR |
| Budget alerts, summaries and other optional emails | Consent — Art. 6(1)(a) GDPR (withdrawable at any time in settings) |
| Monthly AI summaries (optional feature, disabled by default) | Consent — Art. 6(1)(a) GDPR |
| Security, abuse prevention, error diagnostics | Legitimate interest — Art. 6(1)(f) GDPR (protecting the Service and its users) |
| Retention of accounting and tax documentation | Legal obligation — Art. 6(1)(c) GDPR |
| Establishing, exercising or defending legal claims | Legitimate interest — Art. 6(1)(f) GDPR |
| Non-essential cookies and local storage | Consent — Art. 6(1)(a) GDPR and Art. 4b of the Bulgarian Electronic Communications Act |
4. Monthly AI summaries
Finora can generate a short written summary of your month. The feature is disabled by default and works only if switched on.
- The language model receives aggregated values only — category totals, transaction counts, ratios. Individual transactions, descriptions, counterparties, IBANs and names never leave our server.
- The processor is Anthropic PBC (USA). The data is not used to train models.
- If you do not want summaries, simply do not enable the feature, or switch it off in settings.
5. Who we share data with
We do not sell or rent personal data. We share it only with processors acting on our instructions under an Art. 28 GDPR agreement:
| Recipient | Purpose | Location |
|---|---|---|
| Stripe Payments Europe, Ltd. | Payment and subscription processing | Ireland (EU) / USA |
| Resend, Inc. | Sending transactional and notification emails | USA |
| Vercel Inc. | Application hosting and CDN | EU / USA |
| Supabase, Inc. | Database hosting (PostgreSQL) | EU (Frankfurt) |
| Anthropic PBC | Generating monthly AI summaries — only if the feature is enabled and only on aggregated totals, never individual transactions | USA |
Data may also be disclosed to competent authorities (tax administration, courts, investigating bodies) where this is required by law.
6. Transfers outside the EU/EEA
Some of our providers are established in the USA. For those transfers we apply appropriate safeguards under Chapter V GDPR:
- Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914);
- certification under the EU–U.S. Data Privacy Framework, where the provider participates in it;
- additional technical measures — encryption in transit and minimisation of the data transferred.
You may request a copy of the applicable safeguards at [TO BE FILLED IN].
7. Retention periods
| Data category | Period |
|---|---|
| Account and login data | Until the User deletes the account |
| Transactions, accounts, categories, goals | Until account deletion or until deleted by the User |
| Uploaded statement files and import records | Until the import or the account is deleted |
| Accounting and tax records of payments | 10 years from the beginning of the year following the year of issue (Art. 12 of the Bulgarian Accountancy Act) |
| Login (refresh) and password reset tokens | Until expiry or revocation |
| Audit log entries | Up to 12 months |
| Cookie consent records | Up to 12 months from the moment consent is given |
| Correspondence on enquiries and complaints | Up to 3 years after the case is closed (limitation period) |
Once the period expires the data is deleted or irreversibly anonymised. Backups are rotated on a schedule; deleted records disappear from them within 30 days.
8. Your rights
Under the GDPR you have the following rights, which you may exercise free of charge:
- Access (Art. 15) — to obtain a copy of the data we process about you.
- Rectification (Art. 16) — to correct inaccurate or incomplete data, including directly in the application.
- Erasure / “right to be forgotten” (Art. 17) — you can delete your account yourself from settings.
- Restriction of processing (Art. 18) — where accuracy or lawfulness is contested.
- Portability (Art. 20) — export of your data in a machine-readable format (CSV), available at any time from your account regardless of plan.
- Objection (Art. 21) — to processing based on legitimate interest.
- Withdrawal of consent (Art. 7(3)) — at any time, without affecting the lawfulness of processing before withdrawal.
- Complaint to a supervisory authority (Art. 77).
Requests are submitted to [TO BE FILLED IN]. We respond within one month, extendable by a further two months for complex requests, of which you will be informed. We may ask for additional information to verify your identity. A step-by-step description is available on the Your GDPR rights page.
Supervisory authority: Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, tel. +359 2 915 3518, email kzld@cpdp.bg, https://www.cpdp.bg.
9. Data security
We apply technical and organisational measures under Art. 32 GDPR appropriate to the risk:
- encryption of the connection (TLS/HTTPS) for all traffic;
- passwords stored solely as bcrypt hashes — irreversible and unreadable;
- access managed with signed tokens in httpOnly cookies, inaccessible to JavaScript, with refresh token rotation;
- strict per-user data separation at the database query level;
- restricted staff access on a need-to-know basis;
- regular backups and logs providing traceability of key actions.
In the event of a security breach likely to result in a high risk to your rights we will notify you without undue delay, and the supervisory authority within 72 hours, in accordance with Art. 33 and 34 GDPR.
10. Automated decision-making
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR.
Automatic categorisation, internal transfer detection and AI summaries are assistive suggestions that you can change or reject at any time. They do not lead to refusal of service, pricing decisions or any other decision with legal effect.
11. Children's data
The Service is intended for persons aged 18 and over. We do not knowingly collect data from anyone below that age. If we establish that an account has been created by a minor, we will delete it. If you are a parent or guardian and believe a child has provided data, please write to us at the email address above.
13. Data processed by add-ons (Finora Auto)
Finora Auto is a paid add-on for tracking a vehicle — fuel fill-ups, fuel consumption, service history and related costs. This section describes the specific data it processes, in addition to what is described above.
13.1. What data Finora Auto processes
- Licence plate and VIN, if you enter them — these are data linked to you as the vehicle's owner, and we treat them as personal data, not as ordinary technical specifications.
- Vehicle data: make, model, year, engine size and power, tank capacity.
- Odometer readings by date — mileage over time can reveal travel habits.
- Fuel fill-ups: date, time, amount paid, litres, and the fuel station if you enter it.
- Service history: workshop, date, mileage, work performed and amounts paid.
- Other vehicle costs: insurer, policy number, validity periods, fines and other payments you enter.
- Acquisition and sale: purchase date and price, sale date and price, if you record them.
13.2. Legal basis
We process this data on the basis of performance of a contract (Art. 6(1)(b) GDPR) — you activated the add-on and the data is necessary for it to work. We do not rely on legitimate interest for this category.
13.3. Retention period
Finora Auto data is kept for as long as your account exists — including if the add-on subscription expires or is cancelled. Expiry does not lead to deletion: access drops to read-only (see the Terms of Service, section 7), while the vehicles, fuel entries, services and costs you already entered remain visible and preserved, so you can renew at any time without losing history.
13.4. Your rights
The rights described in section 8 above apply in full to Finora Auto data as well. In particular: export remains available even with an expired subscription — the right to portability under Art. 20 GDPR does not depend on whether you are paying. Deleting your account also erases all add-on data.
13.5. Who we share this data with
Finora Auto does not add any new recipient beyond those listed in section 5. We do not scan or automatically process receipts or photos of them — that feature is not implemented. If it is ever launched, it will require a new row in the sub-processor table above and separate consent before it works.
14. Data processed by add-ons (Finora Home)
Finora Home is a paid add-on for tracking rental properties — expenses, rent, loans and yield analysis. This section describes the specific data it processes, in addition to what is described above.
14.1. What data Finora Home processes
- Property data: address, city, district, area, number of rooms, floor, year built, if you enter them.
- Loan data: lender, amount, interest rate, term and repayment schedule, including early repayments.
- Property expenses: category, amount, date and vendor, if you enter an invoice or vendor.
- Lease terms: rent amount, dates, deposit, indexation.
14.2. Legal basis
For your own data (property, loan, expenses) we process on the basis of performance of a contract (Art. 6(1)(b) GDPR) — you activated the add-on and the data is necessary for it to work.
For your tenant's data the roles are different: you are the data controller — you decide what to enter and why — while Finora acts only as a data processor under Art. 28 GDPR, on your instructions and solely so the feature works. That means you are responsible for informing your tenant that their data is entered into Finora (for example in the lease itself or a separate notice), as required by Art. 13/14 GDPR — Finora has no direct contact with your tenant and cannot fulfil this obligation on your behalf.
14.3. Retention period
Finora Home data, including tenant data, is kept for as long as your account exists — including if the add-on subscription expires or is cancelled. Expiry does not lead to deletion: access drops to read-only (see the Terms of Service, section 7), while the properties, loans, rent records and expenses you already entered remain visible and preserved, so you can renew at any time without losing history.
14.4. Your rights — and your tenant's rights
The rights described in section 8 above apply in full to your own data in Finora Home. In particular: export remains available even with an expired subscription — the right to portability under Art. 20 GDPR does not depend on whether you are paying. Deleting your account also erases all add-on data, including any tenant data you entered.
If one of your tenants asks to access, correct or delete their data, they should contact you — you are the controller of that data, not Finora. If you need technical assistance to fulfil such a request (for example, partial deletion of one tenant's data), contact us through section 8.
14.5. Who we share this data with
Finora Home does not add any new recipient beyond those listed in section 5 — tenant data is hosted on the same infrastructure and is not passed to any third party outside it.
15. Changes to this policy
We may update this policy following changes in the law, in the service or in the providers we use. For material changes we will notify you by email or via an in-app message at least 14 days in advance. The date of last revision is shown at the top of this document.
You can save this document as a PDF using your browser's print function.