Privacy Policy

Last updated: 7 September 2026

Draft — not yet reviewed by counsel. Highlighted fields must be completed before publishing. Every factual claim below has been written to match what the product actually does today; if the product changes, this must change with it.

1. Who we are

[LEGAL ENTITY NAME] (“HFI AI”, “we”) operates gethfi.com. For customer account data we are the controller. For the financial data you upload or connect, we act as a processor on your instructions.

Contact: [PRIVACY EMAIL]. [If you have EU/UK users, name a representative under GDPR Art. 27 and say whether a Data Protection Officer is required.]

2. What we collect

Account data

  • email address, hashed password, organisation name, industry, role;
  • API tokens you create (stored as a hash, shown to you once);
  • audit records of significant actions — sign-in, report generation, approvals, integration changes, password changes — with the acting user and IP address.

Financial data

  • transactions you upload by CSV: date, description, category, type, amount;
  • transactions retrieved from connectors you authorise (banking, accounting, payments), on a read-only basis;
  • a cash balance figure you enter;
  • reports, forecasts, scenarios and AI-generated narrative derived from the above.

Technical data

  • IP address and request metadata in server logs;
  • [LIST ANY ANALYTICS, ERROR TRACKING OR SESSION-REPLAY TOOL. If none is installed, say “we run no third-party analytics” — that is a genuine selling point for a privacy-first product, but only if true.]

We do not ask for and do not want government identifiers, payment card numbers, or health data. Do not upload them.

3. Why we process it, and on what basis

  • To provide the service — computing metrics, generating reports and analysis. Basis: performance of our contract with you.
  • To secure the service — authentication, audit logging, abuse prevention. Basis: legitimate interests.
  • To support you — responding to requests. Basis: contract and legitimate interests.
  • To meet legal obligations — tax, accounting, lawful requests. Basis: legal obligation.

4. Automated analysis and the model provider

This section describes something customers frequently do not expect, so it is stated plainly.

To generate written analysis, insights and report narrative, we send extracts of your financial data — aggregates such as burn rate, runway, cash balance, category totals and monthly summaries, and in some features individual transaction descriptions and amounts — to a third-party large language model provider over their API.

The provider currently used is [MODEL PROVIDER LEGAL NAME], processing in [PROCESSING REGION]. [You must name the provider here. Describing it generically as “AI” is fine in marketing copy, but a privacy notice has to identify the recipient of the data or at minimum the category and location, and a DPA requires the sub-processor to be named.]

[CONFIRM AND STATE: whether the provider retains prompts, for how long, and whether they are used to train models. Obtain this in writing from the provider and reflect their actual terms here.]

If you connect a demo or sample connector, the data sent is synthetic rather than yours.

5. Who else we share data with

  • Hosting[HOSTING PROVIDER AND REGION], which stores the database and application servers.
  • Model provider — as described in section 4.
  • Connectors you authorise — data flows from them to us; we do not send your financial data back to them.
  • Payment processing[PAYMENT PROCESSOR, if any]. We do not store card numbers.
  • Legal — where required by law or to protect rights and safety.
  • Business transfer — a buyer or successor, subject to this policy.

We do not sell personal information and do not share it for cross-context behavioural advertising.

6. Security

What is in place today:

  • TLS on all connections to the service;
  • passwords stored using bcrypt; API tokens stored as SHA-256 hashes;
  • role-based access control, and data scoped to your workspace;
  • audit logging of significant actions;
  • the database is not exposed to the public internet.

Do not claim encryption at rest until it is true. The production disk is currently unencrypted, and the pricing page FAQ says otherwise. Fix the infrastructure or fix the claim — a security statement that is not accurate is worse than no statement.

No system is perfectly secure. [STATE YOUR BREACH NOTIFICATION COMMITMENT — GDPR requires notifying a supervisory authority within 72 hours; many US state laws have their own deadlines.]

7. How long we keep it

  • Customer Data: for as long as your account is active.
  • After account closure: deleted or de-identified within [RETENTION PERIOD], except where we must keep records by law.
  • Audit logs: [AUDIT RETENTION]. The Settings screen offers 1, 3 and 7 year options; make sure the stated period matches what is actually enforced.
  • Backups: [BACKUP RETENTION AND WHETHER DELETION PROPAGATES TO BACKUPS].

8. Your rights

Depending on where you live you may have rights to access, correct, delete, port or restrict processing of your personal data, to object to processing based on legitimate interests, and to complain to a supervisory authority.

Exercise them at [PRIVACY EMAIL]. We respond within [RESPONSE SLA] and will not discriminate against you for exercising a right.

Where we act as processor for financial data you connected, we will refer a request to the customer who controls that workspace.

9. International transfers

Your data may be processed in countries other than your own, including by the model provider. [IDENTIFY THE COUNTRIES AND THE TRANSFER MECHANISM — Standard Contractual Clauses, UK Addendum, or an adequacy decision. This is the item most likely to be challenged for an AI product processing EU financial data.]

10. Children

The service is not directed at children and we do not knowingly collect their data.

11. Cookies

We use cookies necessary to keep you signed in. [If no analytics or advertising cookies are set, say so — and then you do not need a consent banner in most jurisdictions. Confirm before asserting it.]

12. Changes

We will post changes here and update the date above. For material changes we will give notice by email or in the product.