Trust & Security
We will never sell your data. Never.
Last updated: 2026-07-18
You’re handing us the numbers that run your business — invoices, bank accounts, customer PANs, GST returns. This page is our commitment on what we do with them, in plain English. The formal version lives in our Privacy Policy and DPDP disclosure — this is the summary you can screenshot and send to your CA.
The promise
- We will never sell your data — not to competitors, not to marketers, not to data brokers. If we ever change this, you’ll be notified 30 days in advance and given the option to delete everything first.
- We will never look at your data without a reason — every staff access is audited, emails the workspace owner, and shows a persistent banner while active.
- If we’re breached, you’ll hear from us within 72 hours — the DPDP Act mandate is the floor; we aim for the same day.
Where your data lives
- Primary database + files: Supabase (Mumbai, ap-south-1). Postgres with encryption at rest (AES-256), daily point-in-time backup with 7-day recovery window.
- Application: Vercel, served from the bom1 (Mumbai) region. TLS 1.2+ everywhere, HSTS with a 2-year max-age.
- No data leaves India for the two systems above. Auxiliary services (Resend for email, Meta for WhatsApp, Sentry for error monitoring) may process transient payloads outside India — listed in full on our DPDP disclosure.
Who can see your data
- Only members of your workspace, scoped by Postgres Row-Level Security. Every query — from the app, from our API, from an admin panel — is filtered at the database. A member of Org A physically cannot see Org B’s data, even by manipulating requests.
- Your CA if you invited them via the CA portal, and only for the sections you granted access to. You can revoke any time.
- FinNilai staff only when troubleshooting your explicit support request. Staff access requires a typed reason, is fully audited, notifies you by email, and expires automatically. You can disable staff support access entirely in Settings → Compliance.
What we do with your data
- Store it, serve it back to you, run the accounting logic on it.
- Send transactional emails you asked for (reminders, statements).
- Aggregate anonymised operational metrics (total invoices generated across the platform, average WAC computation time) for capacity planning. Nothing is per-customer identifiable.
- Comply with lawful government orders when legally required — we’ll notify you first if the order permits it.
That’s the full list. If you can think of something else we might be doing, email privacy@finnilai.com and we’ll answer.
Your rights, one click away
- Export everything — Settings → Privacy & data → Request data export. You get a JSON dump of every row, emailed within a few minutes.
- Delete everything — Same page → Request workspace deletion. 30-day cooling-off, then hard delete. Cancel any time inside the window.
- Signed Data Processing Agreement — download at /dpa for your compliance records.
Report a security issue
Found a vulnerability? Please tell us before you tell anyone else. Email security@finnilai.com. We respond within 24 hours, patch within a target window based on severity, and won’t pursue you for good-faith research. Full policy at /security (mirrored at .well-known/security.txt).
On the roadmap
We’re a bootstrap-stage team investing security spend where the risk is highest first: mandatory 2FA, row-level isolation at the database, audited staff access, encrypted backups. Independent audits — SOC 2, external penetration tests, formal ISO 27001 — come when we’re serving the size of business that needs them. If your procurement team needs the current status on any of these, email security@finnilai.com and we’ll answer straight.
Contact
Grievance officer: privacy@finnilai.com. Security team: security@finnilai.com. General: contact@finnilai.com.