FOLIO — PRIVACY ZERO DATA CUSTODY · DATA RIGHTS · TRANSFERS

Privacy is custody.

Custody is architectural.

FinHelm processes financial data in real-time memory only. Raw ERP transactions, customer and vendor names, and account-level details are never written to FinHelm's databases. We retain analysis outputs and minimal audit metadata. We do not retain your ledger.

Last updated XV May MMXXVI · Replaces March MMXXVI · v2.0

SECTION IScope of this Policy

This Privacy Policy applies to all FinHelm products and services, including FinHelm Clarity (our QuickBooks Online–connected SMB FP&A product), FinHelm Platform (our mid-market and enterprise FP&A product), the FinHelm MCP connector for AI clients, and marketing pages and demo tools at finhelm.ai. Where MCP connector–specific terms apply, they are noted in the relevant section.

SECTION IIWho we are

FinHelm Corp is a Tennessee C-Corporation, founded MMXXVI. Our principal place of business is in Tennessee, U.S.A. For data protection purposes, FinHelm Corp is the data controller for marketing and authentication data, and a data processor for ERP analysis data on behalf of our customers.

Contact: privacy@finhelm.ai.

SECTION IIIData we collect

FinHelm collects only what is necessary to operate the product and meet legal obligations.

FIG. III.a · The custody doctrine is structural. Data we never have, we cannot lose.

SECTION IVHow we use data

We use data only for the purposes listed below and only on the legal basis indicated.

Data category Purpose Legal basis
Email & password hashAccount creation, authentication, password resetContract
OAuth tokensRead-only access to connected ERP on user’s instructionContract
ERP transaction data (transient)Compute UES™, Monte Carlo, variance, runway, narrativesContract
Analysis outputsDisplay in AI client; Reflection Engine™ fidelity scoringContract
Audit metadataOperational integrity, security incident response, billingLegitimate interest
Sign-in metadataAccount security, fraud preventionLegitimate interest
Marketing email (opt-in only)Product updates and educational contentConsent

We do not sell, rent, or trade personal information. We do not use ERP data or analysis outputs to train third-party AI models. AI models accessed via our MCP connector are invoked ephemerally per request; outputs are returned and not pooled into a training set.

SECTION VData retention

Data category Retention period
Raw ERP transaction dataNot retained — transient memory only
OAuth tokens (active)Until you revoke access or close your account
OAuth tokens (revoked)Deleted within 24 hours of revocation
Analysis outputs13 months from generation, then deleted
Audit metadata13 months from event, then deleted
Account data (active)Until you close your account
Account data (closed)30 days, then deleted (legal-hold exceptions noted)
Marketing consent recordsUntil you withdraw consent, plus 24 months evidence

SECTION VIThird-party services & sub-processors

FinHelm contracts the sub-processors below to operate the product. The canonical list is mirrored on finhelm.ai/security/.

Sub-processor Purpose Region
Amazon Web ServicesCompute, storage, KMS, Cognito, networkingU.S. — us-east-1
Anthropic, PBCAI model invocation (ephemeral, per-request)U.S.
Stripe, Inc.Payments processing (when paid tiers enforced)U.S.
SentryApplication error monitoring (no ERP data sent)U.S.
PostmarkTransactional email (sign-in, password reset)U.S.
VercelFrontend hostingStandard web logs
PostHogProduct analyticsAnonymized usage events

FinHelm provides 30 days’ notice before adding a new sub-processor that processes customer ERP data. Subscribe to sub-processor change notifications at privacy@finhelm.ai.

SECTION VIIYour data rights

Depending on your jurisdiction, you have the following rights:

To exercise any of these rights, email privacy@finhelm.ai. We respond within 30 days.

SECTION VIIISecurity

FinHelm implements industry-standard technical and organizational measures:

Detailed security architecture is documented at finhelm.ai/security/.

SECTION IXChildren’s privacy

FinHelm is a B2B finance product and is not directed to individuals under 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it.

SECTION XInternational data transfers

FinHelm’s primary infrastructure is hosted in the U.S. (AWS us-east-1). For customers outside the U.S., this constitutes a cross-border transfer. Where required (for example, EEA and UK customers), we rely on Standard Contractual Clauses and equivalent transfer mechanisms. Contact privacy@finhelm.ai for the applicable transfer mechanism documentation.

SECTION XIChanges to this policy

We will notify customers of material changes by email and by updating the “Last updated” date at the top of this page at least 14 days before changes take effect. Non-material edits (typo fixes, link updates) take effect on publication. The previous version (March MMXXVI) is available on request.

FOLIO — INVITATION · DATA SUBJECT REQUESTS

Exercise your data rights.

Access, rectification, erasure, portability, objection, and consent withdrawal. We respond within 30 days.