HomePrivacy Policy
Legal Document Β· Last Updated 10 May 2026
Privacy PolicyYour data, your rights.
This policy explains what data FinovaOS collects, how we use it, and your rights as a user. We are committed to transparency and your privacy is taken seriously.
π
Section 01
Information We Collect
Account & Identity Data
When you register, we collect your name, email address, phone number, company name, and business type. This information is necessary to create and manage your account.
Financial & Business Data
All accounting records, invoices, ledger entries, inventory data, payroll records, and financial reports you enter into the platform are stored securely and are owned entirely by you.
Usage & Technical Data
We collect IP addresses, browser type, device identifiers, pages visited, and session timestamps to operate the platform, detect fraud, and improve performance. This data is never sold.
Communications
If you contact our support team, we retain those communications to provide assistance and improve our service quality.
βοΈ
Section 02
How We Use Your Information
Service Delivery
Your data is used solely to operate FinovaOS β to process transactions, generate reports, send notifications, and maintain your account.
Security & Fraud Prevention
We analyze usage patterns to detect unauthorized access, suspicious activity, and potential abuse of the platform.
Product Improvement
Aggregated, anonymized usage statistics help us understand how features are used and where to invest development effort. Individual records are never used for this purpose.
Legal Compliance
We may process your data when required to comply with applicable laws, court orders, or regulatory obligations.
π
Section 03
Data Sharing & Third Parties
We Never Sell Your Data
Your financial data, customer lists, and business records are never sold, licensed, or shared with advertisers or data brokers. Period.
Service Providers
We engage trusted infrastructure providers (cloud hosting, email delivery, payment processing) under strict data processing agreements. They may only process your data as directed by us.
Legal Requirements
We may disclose data if compelled by valid legal process, court order, or to protect the rights, property, or safety of our users and the platform.
Business Transfers
In the event of a merger or acquisition, your data may be transferred to the successor entity, which will be bound by this privacy policy.
π³
Section 04
Payment Processing
Third-Party Payment Providers
Payments on FinovaOS are processed through LemonSqueezy, a trusted third-party payment provider. FinovaOS does not store full card numbers, CVV codes, or other sensitive cardholder data on its own servers.
Card Data Security
All payment card data is handled directly by our payment processors under PCI-DSS compliant environments. We receive only a tokenized reference and last-4 digits for billing records. We have no access to your full card details at any time.
Bank & Wire Transfers
For customers who pay via bank transfer, we collect only the information required to verify and reconcile the payment. No banking credentials are stored by FinovaOS.
π
Section 05
Data Security
Encryption
All data in transit is protected by TLS 1.3. All data at rest is encrypted using AES-256. Encryption keys are stored separately from the data they protect.
Access Controls
We enforce role-based access controls internally. Only authorized personnel can access production systems, and all access is logged and audited.
Infrastructure
Our platform runs on enterprise-grade cloud infrastructure with redundant availability zones, daily automated backups, and 24/7 monitoring.
Incident Response
In the event of a data breach affecting your information, we will notify you within 72 hours of discovery, as required by applicable law.
π€
Section 06
AI & Automated Processing
AI Model Training
Customer business data is never used to train public or shared AI models. Your financial records, invoices, contacts, and operational data remain exclusively yours and are never fed into any externally shared machine learning pipeline.
AI-Powered Insights
AI-powered analytics, forecasts, and recommendations in FinovaOS are generated solely using your own workspace data, processed within your isolated environment. No cross-customer data comparison or blending occurs.
Automated Decisions
Where FinovaOS uses automated processing to generate suggestions (such as reorder recommendations or cash-flow forecasts), these are advisory only and do not constitute binding decisions. You retain full control over all business actions.
ποΈ
Section 07
Data Retention Policy
Active Accounts
We retain your data for as long as your account is active and as necessary to provide our services. Financial records may be retained for a longer period to comply with applicable tax and accounting regulations in your jurisdiction.
After Subscription Cancellation β 3-Phase Policy
When you cancel your subscription, a 90-day data retention window begins automatically. Phase 1 (Days 1β30): Your account is read-only. You can log in and export all your data. Phase 2 (Days 31β90): Your account is locked but data is preserved on our servers. You may reactivate at any time to restore access. Phase 3 (Day 90+): All business data is permanently and irreversibly deleted.
Email Reminders Before Deletion
We will send reminder emails to your registered address 14 days and 3 days before the 90-day permanent deletion deadline. It is your responsibility to ensure your email address is current and to export any data you wish to keep.
What Is Deleted at Day 90
Permanent deletion includes all invoices, purchase orders, ledger entries, inventory records, payroll data, employee records, contacts, bank reconciliation data, expense vouchers, reports, and any other business data you entered into the platform.
What We Retain After Deletion
After permanent deletion we retain only: (1) an anonymized audit log confirming the purge event, and (2) minimum billing records required by applicable financial regulations (plan name, payment amounts, dates). No personal business data is retained after day 90.
Explicit Deletion Request
You may request immediate deletion of your account and all associated data at any time by emailing [email protected]. We will process the request within 7 business days and send written confirmation. Immediate deletion waives any remaining read-only grace period.
Backups
System backup snapshots are retained for up to 30 days and are subject to the same security controls and deletion schedule as live data. Backup retention does not extend your data retention window after cancellation.
β
Section 08
Your Rights
Access & Portability
You may request a full export of your data at any time in standard formats (CSV, Excel, PDF). We will fulfill your request within 14 business days.
Correction
You may update or correct your personal information at any time through your account settings or by contacting our support team.
Deletion
You have the right to request deletion of your account and all associated personal data. We will confirm deletion in writing within 30 days.
Objection & Restriction
You may object to or request restriction of certain types of processing. Contact our privacy team to exercise these rights.
π’
Section 09
Workspace Isolation & Account Responsibility
Workspace Isolation
Each customer workspace operates within logically isolated environments designed to prevent unauthorized cross-account access between organizations. Business data belonging to one customer is never accessible to another customer under any circumstances.
Account Responsibility
Customers are responsible for maintaining the confidentiality of their login credentials and for all activities performed within their accounts. FinovaOS cannot be held responsible for losses resulting from unauthorized access caused by credential sharing, weak passwords, or failure to secure account access.
User Roles & Permissions
Account administrators are responsible for assigning appropriate roles and permissions to their team members. FinovaOS provides role-based access controls but does not audit how customers configure internal access within their own organization.
βοΈ
Section 11
Compliance, Legal Entity & Governing Law
International Compliance
While FinovaOS is not currently certified under GDPR, SOC 2, or ISO 27001, we follow industry-standard security and privacy practices designed to align with international compliance expectations. We are committed to progressively adopting formal certifications as the platform matures.
Legal Entity
FinovaOSβ’ is a product of Finova Forge. Finova Forge is the legal entity responsible for operating, maintaining, and delivering the FinovaOS platform and all associated services.
Governing Law
This Privacy Policy shall be governed by and interpreted in accordance with the laws applicable to the jurisdiction in which Finova Forge operates, unless otherwise required by the customer's local laws or regulations. Where conflicts arise between jurisdictions, the parties will act in good faith to resolve them.
Dispute Resolution
Any disputes relating to this privacy policy that cannot be resolved informally will be addressed through the legal processes applicable in Finova Forge's operating jurisdiction.
π
Section 12
Changes to This Policy
Notification
We will notify you of material changes to this privacy policy via email and in-app notification at least 14 days before the changes take effect.
Continued Use
Your continued use of FinovaOS after the effective date of any changes constitutes your acceptance of the updated policy.