Privacy Policy
Last updated: 2026-10-01
1. Controller and contact
The controller is PLACEHOLDER — legal entity name (e.g. UAB Finki), PLACEHOLDER — street, city, postcode, Lithuania, Lithuania. No DPO is appointed; privacy enquiries go to contact@tryfinki.com.
2. Data we collect
- Authentication data, including email and securely handled credentials.
- Portfolio data and brokerage data synced through SnapTrade, including positions, transactions and account names. This is financial data.
- Uploaded documents and extracted content.
- Support and bug-report content.
- Security and technical logs, including IP address, user agent and timestamps.
- Optional analytics data and marketing preferences.
3. Purposes and legal bases
- Contract, Art. 6(1)(b): account operation, calculations and brokerage sync.
- Legitimate interests, Art. 6(1)(f): security, abuse prevention, error monitoring and aggregate product improvement. We balance these limited uses against your privacy and minimise the data involved.
- Consent, Art. 6(1)(a): optional analytics and marketing email; you may withdraw at any time.
- Legal obligation, Art. 6(1)(c): accounting records.
4. Sharing
We use the processors listed on our Subprocessors page. We do not monetize personal data or share it for third-party marketing.
5. International transfers
Some processors operate outside the EEA. Depending on the provider and service, safeguards may include Standard Contractual Clauses and/or the EU-US Data Privacy Framework. Provider-specific mechanisms still requiring verification are marked on the Subprocessors page. Copies of applicable safeguards are available on request.
6. AI and automated processing
Document parsing is AI-assisted. Portfolio analytics and optimisation are deterministic calculations based on your inputs and do not make a decision with legal or similarly significant effect under Art. 22. Portfolio data is not used to train AI models.
7. Retention
- Account and portfolio data: while active, then a 30-day recovery period after a deletion request before permanent deletion.
- Uploaded documents: while needed for extraction and account use, then deleted with account data.
- Analytics: according to the configured PostHog retention period and until consent is withdrawn.
- Security logs: up to 12 months unless needed to investigate an incident.
- Accounting records: for the statutory retention period.
8. Security
We use encryption in transit and at rest, least-privilege access and Supabase row-level security so users can read only their own rows. Where required, we notify the supervisory authority of a personal-data breach within 72 hours.
9. Your rights
You may request access, rectification, erasure, restriction, portability, object to processing, withdraw consent, and exercise the right not to be subject to solely automated decisions. Email contact@tryfinki.com; we normally respond within one month.
10. Complaints
You may complain to the State Data Protection Inspectorate (VDAI), L. Sapiegos g. 17, 10312 Vilnius, ada@ada.lt, vdai.lrv.lt, or your local supervisory authority.
11. Children
The service is not intended for anyone under 18 and we do not knowingly collect their data.
12. Cookies and local storage
Necessary storage supports authentication and consent records. Analytics storage is optional. See the Cookie Policy.
13. Changes
Material changes will be announced by email and/or in-app. The version date appears above.
14. Contact
contact@tryfinki.com