At Finzo Solutions FZE, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Finzo ERP platform ("Service"). By using the Service, you agree to the practices described in this policy.
1. Data Controller
The data controller for the Service is:
2. Data We Collect
We collect the following categories of data:
| Category | Examples | Purpose |
|---|
| Account Information | Name, email, phone, company name | Account creation & support |
| Business Data | Invoices, bills, payments, employee records | Service delivery |
| Usage Data | Pages visited, features used, login timestamps | Service improvement |
| Device Data | Browser type, IP address, device type | Security & troubleshooting |
3. How We Use Your Data
We use your data to:
- Provide the Service — Process your financial data, generate reports, manage your business operations.
- Maintain security — Detect fraud, prevent unauthorized access, enforce our Terms.
- Communicate — Send transactional emails (invoices, receipts, alerts), respond to support requests.
- Improve the Service — Analyze aggregate usage patterns to improve features and performance.
- Billing — Process subscription payments and manage your account.
- Legal compliance — Meet our obligations under UAE law, including VAT reporting and tax compliance.
We do not sell your personal data to third parties. We do not use your business data for advertising purposes.
4. Data Storage & Security
Your data is stored securely using industry-standard practices:
- Infrastructure — Hosted on Supabase (backed by AWS), with servers in the Middle East region.
- Encryption — All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Access control — Row-Level Security (RLS) ensures that each tenant's data is isolated and inaccessible to other tenants.
- Authentication — Industry-standard authentication with secure password hashing (bcrypt).
- Audit logging — All significant actions (create, edit, delete) are logged with timestamps and user identification.
- Backups — Automated daily backups with point-in-time recovery.
5. Data Sharing
We share your data only with the following categories of third-party service providers ("Sub-processors"), and only to the extent necessary to provide the Service:
| Provider | Purpose | Data Shared |
|---|
| Supabase | Database & authentication | All service data |
| Stripe | Payment processing | Billing information only |
| Vercel | Application hosting | Request metadata (IP, headers) |
We may also disclose data when required by law, court order, or to protect our rights and safety.
6. Data Retention
- Active accounts — Data is retained for the duration of your subscription.
- After cancellation — Your data is retained for 90 days to allow for reactivation or export, after which it is permanently and irreversibly deleted.
- Legal holds — Data subject to legal requirements (e.g., VAT records) may be retained for the legally mandated period (typically 5 years under UAE law).
- Backups — Deleted data may persist in encrypted backups for up to 30 additional days before being purged.
7. Your Rights
You have the following rights regarding your personal data:
- Access — Request a copy of the personal data we hold about you.
- Rectification — Request correction of inaccurate or incomplete data.
- Deletion — Request deletion of your personal data (subject to legal retention requirements).
- Export — Download your business data in standard formats (CSV, Excel, PDF) at any time through the platform.
- Restriction — Request restriction of processing in certain circumstances.
- Objection — Object to processing of your data for specific purposes.
To exercise any of these rights, contact us at privacy@finzomea.com. We will respond within 30 days.
8. Cookies & Tracking
We use only essential cookies required for the Service to function:
- Session cookie — Maintains your authentication state. Expires when you log out or after 7 days of inactivity.
- Preferences — Stores your UI preferences (theme, sidebar state). Local storage only, not transmitted to servers.
We do not use:
- Third-party tracking cookies
- Advertising pixels or retargeting
- Analytics services that track individual users
9. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will take steps to delete it.
10. International Transfers
Your data is primarily stored in the Middle East region. In the event that data is transferred to other regions (e.g., for backup or CDN purposes), we ensure appropriate safeguards are in place, including encryption and contractual obligations with our sub-processors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will update the "Last updated" date at the top of this page.
- We will notify you via email or an in-app notification.
- You will be asked to re-accept the updated policy before continuing to use the Service.
If you have questions about this Privacy Policy or how we handle your data: