FOLIO — PRIVACY NO LEDGER COPY · DATA RIGHTS · TRANSFERS

Privacy is architectural.

We hold no copy of your ledger.

FinHelm holds no copy of your ledger. Every ERP read is fetched live from your accounting system, used to compute the analysis in front of you, and discarded. What FinHelm stores is what you author inside FinHelm, your forecast history, and your account, billing, and audit records. Section V details retention.

Last updated XV May MMXXVI · Replaces March MMXXVI · v2.0

SECTION IScope of this Policy

This Privacy Policy applies to all FinHelm products and services, including FinHelm Clarity (our QuickBooks Online–connected SMB FP&A product), FinHelm Platform (our mid-market and enterprise FP&A product), the FinHelm MCP connector for AI clients, and marketing pages and demo tools at finhelm.ai. Where MCP connector–specific terms apply, they are noted in the relevant section.

SECTION IIWho we are

FinHelm Corp is a Tennessee C-Corporation, founded MMXXVI. Our principal place of business is in Tennessee, U.S.A. For data protection purposes, FinHelm Corp is the data controller for marketing and authentication data, and a data processor for ERP analysis data on behalf of our customers.

Contact: privacy@finhelm.ai.

SECTION IIIData we collect

FinHelm collects only what is necessary to operate the product and meet legal obligations.

FIG. III.a · The ledger boundary is structural. The ledger we never store, we cannot lose.

SECTION IVHow we use data

We use data only for the purposes listed below and only on the legal basis indicated.

Data category Purpose Legal basis
Email & password hashAccount creation, authentication, password resetContract
OAuth tokensRead-only access to connected ERP on user’s instructionContract
ERP transaction data (transient)Compute UES™, Monte Carlo, variance, runway, narrativesContract
Analysis outputsDisplay in AI client; Reflection Engine™ fidelity scoringContract
Audit metadataOperational integrity, security incident response, billingLegitimate interest
Sign-in metadataAccount security, fraud preventionLegitimate interest
Marketing email (opt-in only)Product updates and educational contentConsent

We do not sell, rent, or trade personal information. We do not use ERP data or analysis outputs to train third-party AI models. AI models accessed via our MCP connector are invoked ephemerally per request; outputs are returned and not pooled into a training set.

SECTION VData retention

Data category Retention period
Raw ERP transaction dataNot retained — transient memory only
OAuth tokens (active)Until you revoke access or close your account
OAuth tokens (revoked)Deleted within 24 hours of revocation
Content you author (budgets, drivers, scenarios)Until you delete it or close your account
Analysis outputs and forecast history13 months from generation, then deleted
Audit metadata13 months from event, then deleted
Account data (active)Until you close your account
Account data (closed)30 days, then deleted (legal-hold exceptions noted)
Marketing consent recordsUntil you withdraw consent, plus 24 months evidence

SECTION VIThird-party services & sub-processors

FinHelm contracts the sub-processors below to operate the product. The canonical list is mirrored on finhelm.ai/security/.

Sub-processor Purpose Region
Amazon Web ServicesCompute, storage, KMS, Cognito, networkingU.S. — us-east-1
Anthropic, PBCAI model invocation (ephemeral, per-request)U.S.
Stripe, Inc.Payments processing (when paid tiers enforced)U.S.
SentryApplication error monitoring (no ERP data sent)U.S.
PostmarkTransactional email (sign-in, password reset)U.S.
VercelFrontend hostingStandard web logs
PostHogProduct analyticsAnonymized usage events

FinHelm provides 30 days’ notice before adding a new sub-processor that processes customer ERP data. Subscribe to sub-processor change notifications at privacy@finhelm.ai.

SECTION VIIYour data rights

Depending on your jurisdiction, you have the following rights:

To exercise any of these rights, email privacy@finhelm.ai. We respond within 30 days.

SECTION VIIISecurity

FinHelm implements industry-standard technical and organizational measures:

Detailed security architecture is documented at finhelm.ai/security/.

SECTION IXChildren’s privacy

FinHelm is a B2B finance product and is not directed to individuals under 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it.

SECTION XInternational data transfers

FinHelm’s primary infrastructure is hosted in the U.S. (AWS us-east-1). For customers outside the U.S., this constitutes a cross-border transfer. Where required (for example, EEA and UK customers), we rely on Standard Contractual Clauses and equivalent transfer mechanisms. Contact privacy@finhelm.ai for the applicable transfer mechanism documentation.

SECTION XIChanges to this policy

We will notify customers of material changes by email and by updating the “Last updated” date at the top of this page at least 14 days before changes take effect. Non-material edits (typo fixes, link updates) take effect on publication. The previous version (March MMXXVI) is available on request.

FOLIO — INVITATION · DATA SUBJECT REQUESTS

Exercise your data rights.

Access, rectification, erasure, portability, objection, and consent withdrawal. We respond within 30 days.