Back to site

Legal documents

Privacy Policy

How Finora collects, uses and protects your personal data, and what rights you have under the GDPR.

Last revised: 06 August 2026

Company details have not been filled in yet. This document is published with “[TO BE FILLED IN]” markers and does not comply with Art. 4 of the Electronic Commerce Act until they are entered.

This policy explains how [TO BE FILLED IN] processes personal data when you use the Finora web application. It is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.

In short: we process only the data we need for the application to work. We do not sell data. We show no ads. We do not track users across other websites. Your financial records are never used for advertising profiles.

This English version is provided for convenience. In case of discrepancy, the Bulgarian version prevails.

1. Who is the data controller

The controller of your personal data is:

  • [TO BE FILLED IN], UIC [TO BE FILLED IN]
  • Address: [ADDRESS TO BE FILLED IN]
  • Email for data protection matters: [TO BE FILLED IN]
  • Phone: [TO BE FILLED IN]
  • Data Protection Officer: not appointed, as our activity does not fall within Art. 37 GDPR. Please direct questions to the email above.

2. What data we process

2.1. Data you provide directly

  • Registration data: name, email address, password (stored solely as an irreversible bcrypt hash — we cannot see or recover it).
  • Account settings: base currency, time zone, notification preferences, budget mode.
  • Financial data you enter or upload: transactions (date, amount, description, category, notes), the names and IBANs of your own accounts, CSV bank statements, savings goals and contributions, recurring expenses and payees.
  • Correspondence: the content of enquiries and complaints you send us.

2.2. Data generated through use

  • Technical data: IP address, browser and device type, date and time of requests — in standard server and hosting provider logs, for security and diagnostics.
  • Access data: last login date, issued session tokens (stored as hashes).
  • Audit log: records of who performed key actions in the account and when (for example bulk deletion), for traceability during incidents.

2.3. Data from third parties

  • From Stripe: payment and subscription status, customer and subscription identifiers, the last 4 digits and the type of the card. We never receive or store full card details.
  • Referral code, if you arrived via a partner link.
Financial records are not a “special category of data” under Art. 9 GDPR, but we treat them with heightened care because they reveal sensitive habits. If you yourself enter health data, political opinions or another special category into a description or note, you do so at your own discretion and on the basis of your explicit consent under Art. 9(2)(a) GDPR — we recommend avoiding this.

3. Purposes and legal bases

PurposeLegal basis
Creating and maintaining your account, providing the application's featuresPerformance of a contract — Art. 6(1)(b) GDPR
Processing payments and subscriptions, issuing accounting documentsPerformance of a contract — Art. 6(1)(b) and legal obligation — Art. 6(1)(c) GDPR
Transactional emails (registration confirmation, password reset, failed payment)Performance of a contract — Art. 6(1)(b) GDPR
Budget alerts, summaries and other optional emailsConsent — Art. 6(1)(a) GDPR (withdrawable at any time in settings)
Monthly AI summaries (optional feature, disabled by default)Consent — Art. 6(1)(a) GDPR
Security, abuse prevention, error diagnosticsLegitimate interest — Art. 6(1)(f) GDPR (protecting the Service and its users)
Retention of accounting and tax documentationLegal obligation — Art. 6(1)(c) GDPR
Establishing, exercising or defending legal claimsLegitimate interest — Art. 6(1)(f) GDPR
Non-essential cookies and local storageConsent — Art. 6(1)(a) GDPR and Art. 4b of the Bulgarian Electronic Communications Act

4. Monthly AI summaries

Finora can generate a short written summary of your month. The feature is disabled by default and works only if switched on.

  • The language model receives aggregated values only — category totals, transaction counts, ratios. Individual transactions, descriptions, counterparties, IBANs and names never leave our server.
  • The processor is Anthropic PBC (USA). The data is not used to train models.
  • If you do not want summaries, simply do not enable the feature, or switch it off in settings.

5. Who we share data with

We do not sell or rent personal data. We share it only with processors acting on our instructions under an Art. 28 GDPR agreement:

RecipientPurposeLocation
Stripe Payments Europe, Ltd.Payment and subscription processingIreland (EU) / USA
Resend, Inc.Sending transactional and notification emailsUSA
Vercel Inc.Application hosting and CDNEU / USA
Supabase, Inc.Database hosting (PostgreSQL)EU (Frankfurt)
Anthropic PBCGenerating monthly AI summaries — only if the feature is enabled and only on aggregated totals, never individual transactionsUSA

Data may also be disclosed to competent authorities (tax administration, courts, investigating bodies) where this is required by law.

6. Transfers outside the EU/EEA

Some of our providers are established in the USA. For those transfers we apply appropriate safeguards under Chapter V GDPR:

  • Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914);
  • certification under the EU–U.S. Data Privacy Framework, where the provider participates in it;
  • additional technical measures — encryption in transit and minimisation of the data transferred.

You may request a copy of the applicable safeguards at [TO BE FILLED IN].

7. Retention periods

Data categoryPeriod
Account and login dataUntil the User deletes the account
Transactions, accounts, categories, goalsUntil account deletion or until deleted by the User
Uploaded statement files and import recordsUntil the import or the account is deleted
Accounting and tax records of payments10 years from the beginning of the year following the year of issue (Art. 12 of the Bulgarian Accountancy Act)
Login (refresh) and password reset tokensUntil expiry or revocation
Audit log entriesUp to 12 months
Cookie consent recordsUp to 12 months from the moment consent is given
Correspondence on enquiries and complaintsUp to 3 years after the case is closed (limitation period)

Once the period expires the data is deleted or irreversibly anonymised. Backups are rotated on a schedule; deleted records disappear from them within 30 days.

8. Your rights

Under the GDPR you have the following rights, which you may exercise free of charge:

  • Access (Art. 15) — to obtain a copy of the data we process about you.
  • Rectification (Art. 16) — to correct inaccurate or incomplete data, including directly in the application.
  • Erasure / “right to be forgotten” (Art. 17) — you can delete your account yourself from settings.
  • Restriction of processing (Art. 18) — where accuracy or lawfulness is contested.
  • Portability (Art. 20) — export of your data in a machine-readable format (CSV), available at any time from your account regardless of plan.
  • Objection (Art. 21) — to processing based on legitimate interest.
  • Withdrawal of consent (Art. 7(3)) — at any time, without affecting the lawfulness of processing before withdrawal.
  • Complaint to a supervisory authority (Art. 77).

Requests are submitted to [TO BE FILLED IN]. We respond within one month, extendable by a further two months for complex requests, of which you will be informed. We may ask for additional information to verify your identity. A step-by-step description is available on the Your GDPR rights page.

Supervisory authority: Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, tel. +359 2 915 3518, email kzld@cpdp.bg, https://www.cpdp.bg.

9. Data security

We apply technical and organisational measures under Art. 32 GDPR appropriate to the risk:

  • encryption of the connection (TLS/HTTPS) for all traffic;
  • passwords stored solely as bcrypt hashes — irreversible and unreadable;
  • access managed with signed tokens in httpOnly cookies, inaccessible to JavaScript, with refresh token rotation;
  • strict per-user data separation at the database query level;
  • restricted staff access on a need-to-know basis;
  • regular backups and logs providing traceability of key actions.

In the event of a security breach likely to result in a high risk to your rights we will notify you without undue delay, and the supervisory authority within 72 hours, in accordance with Art. 33 and 34 GDPR.

10. Automated decision-making

We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR.

Automatic categorisation, internal transfer detection and AI summaries are assistive suggestions that you can change or reject at any time. They do not lead to refusal of service, pricing decisions or any other decision with legal effect.

11. Children's data

The Service is intended for persons aged 18 and over. We do not knowingly collect data from anyone below that age. If we establish that an account has been created by a minor, we will delete it. If you are a parent or guardian and believe a child has provided data, please write to us at the email address above.

12. Cookies

We use a minimal set of cookies and local storage. The full list, purposes and durations are described in the Cookie Policy. You can change your consent for the optional categories at any time via the “Cookie settings” link in the site footer.

13. Data processed by add-ons (Finora Auto)

Finora Auto is a paid add-on for tracking a vehicle — fuel fill-ups, fuel consumption, service history and related costs. This section describes the specific data it processes, in addition to what is described above.

13.1. What data Finora Auto processes

  • Licence plate and VIN, if you enter them — these are data linked to you as the vehicle's owner, and we treat them as personal data, not as ordinary technical specifications.
  • Vehicle data: make, model, year, engine size and power, tank capacity.
  • Odometer readings by date — mileage over time can reveal travel habits.
  • Fuel fill-ups: date, time, amount paid, litres, and the fuel station if you enter it.
  • Service history: workshop, date, mileage, work performed and amounts paid.
  • Other vehicle costs: insurer, policy number, validity periods, fines and other payments you enter.
  • Acquisition and sale: purchase date and price, sale date and price, if you record them.

13.2. Legal basis

We process this data on the basis of performance of a contract (Art. 6(1)(b) GDPR) — you activated the add-on and the data is necessary for it to work. We do not rely on legitimate interest for this category.

13.3. Retention period

Finora Auto data is kept for as long as your account exists — including if the add-on subscription expires or is cancelled. Expiry does not lead to deletion: access drops to read-only (see the Terms of Service, section 7), while the vehicles, fuel entries, services and costs you already entered remain visible and preserved, so you can renew at any time without losing history.

13.4. Your rights

The rights described in section 8 above apply in full to Finora Auto data as well. In particular: export remains available even with an expired subscription — the right to portability under Art. 20 GDPR does not depend on whether you are paying. Deleting your account also erases all add-on data.

13.5. Who we share this data with

Finora Auto does not add any new recipient beyond those listed in section 5. We do not scan or automatically process receipts or photos of them — that feature is not implemented. If it is ever launched, it will require a new row in the sub-processor table above and separate consent before it works.

14. Data processed by add-ons (Finora Home)

Finora Home is a paid add-on for tracking rental properties — expenses, rent, loans and yield analysis. This section describes the specific data it processes, in addition to what is described above.

14.1. What data Finora Home processes

  • Property data: address, city, district, area, number of rooms, floor, year built, if you enter them.
  • Loan data: lender, amount, interest rate, term and repayment schedule, including early repayments.
  • Property expenses: category, amount, date and vendor, if you enter an invoice or vendor.
  • Lease terms: rent amount, dates, deposit, indexation.
Your tenant's name and contact details (phone, email), if you enter them, are personal data of a THIRD PARTY — not yours. We process them on your behalf and on your instructions, not at our own discretion — see 14.2 below for what exactly this means for you.

14.2. Legal basis

For your own data (property, loan, expenses) we process on the basis of performance of a contract (Art. 6(1)(b) GDPR) — you activated the add-on and the data is necessary for it to work.

For your tenant's data the roles are different: you are the data controller — you decide what to enter and why — while Finora acts only as a data processor under Art. 28 GDPR, on your instructions and solely so the feature works. That means you are responsible for informing your tenant that their data is entered into Finora (for example in the lease itself or a separate notice), as required by Art. 13/14 GDPR — Finora has no direct contact with your tenant and cannot fulfil this obligation on your behalf.

14.3. Retention period

Finora Home data, including tenant data, is kept for as long as your account exists — including if the add-on subscription expires or is cancelled. Expiry does not lead to deletion: access drops to read-only (see the Terms of Service, section 7), while the properties, loans, rent records and expenses you already entered remain visible and preserved, so you can renew at any time without losing history.

14.4. Your rights — and your tenant's rights

The rights described in section 8 above apply in full to your own data in Finora Home. In particular: export remains available even with an expired subscription — the right to portability under Art. 20 GDPR does not depend on whether you are paying. Deleting your account also erases all add-on data, including any tenant data you entered.

If one of your tenants asks to access, correct or delete their data, they should contact you — you are the controller of that data, not Finora. If you need technical assistance to fulfil such a request (for example, partial deletion of one tenant's data), contact us through section 8.

14.5. Who we share this data with

Finora Home does not add any new recipient beyond those listed in section 5 — tenant data is hosted on the same infrastructure and is not passed to any third party outside it.

15. Changes to this policy

We may update this policy following changes in the law, in the service or in the providers we use. For material changes we will notify you by email or via an in-app message at least 14 days in advance. The date of last revision is shown at the top of this document.

You can save this document as a PDF using your browser's print function.