Privacy Policy

Last updated: 21 August 2026

This policy explains what personal data we process, why, and how we protect it. Controller: PROACTIVE SHIPPING S.R.L., VAT no. RO49176949, Trade Registry no. J2023022378407, registered office at Str. Ion Țuculescu no. 42, Bl. P3, Sc. C, 3rd floor, Ap. 47, District 3, Bucharest, Romania. Contact: contact@finur.io.

1. Data we process

  • Account data: name, email, password (encrypted), optional phone, billing details.
  • Content you upload: accounting documents, data of the companies and employees in your portfolio, messages to the agent.
  • Technical data: IP address, browser type, access and audit logs.
  • Communication data: messages sent via the contact form or email.

3. Sub-processors

We use infrastructure and service providers that process data on our behalf under data processing agreements (DPAs):

  • Supabase (database and authentication, EU hosting)
  • Anthropic (language model for document and conversation processing)
  • OpenAI (image extraction and automatic classification)
  • Vercel (website and web app hosting)
  • Railway (backend services hosting)
  • Paddle (payment processing, merchant of record)
  • Resend (transactional email delivery)
  • Meta Platforms (WhatsApp Business API, for communicating with your clients)
  • Cloudflare (DNS, CDN and anti-abuse protection, processes IP addresses)
  • Sentry (error and performance monitoring, EU region, no sensitive local data attached)
  • LangSmith, by LangChain (traces of model calls, used for response quality and cost; EU instance)

4. We do not sell your data

We do not sell your personal data and we do not use it for third parties' marketing purposes. The sub-processors above process it exclusively to provide the Finur service, under the data processing agreements (DPAs) signed with each of them.

The AI model providers we use (Anthropic, OpenAI) have an explicit contractual guarantee, under their commercial API terms, that they do not train their models on data sent through the API; your documents never become training material. Data is kept temporarily (a few days) solely for abuse prevention, then automatically deleted by the provider.

5. International transfers

Data is stored in the European Union. Some sub-processors (Anthropic, OpenAI, Meta) may process data outside the EU; in those cases transfers rely on the Standard Contractual Clauses approved by the European Commission or the EU-US Data Privacy Framework.

6. How long we keep data

Account data: for the duration of the contract and up to 30 days after closure (the window to cancel the deletion request), after which it is deleted in cascade from all systems: database, file storage and search index.

Our own billing documents: 10 years, as required by tax law. Technical logs: up to 12 months.

7. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to lodge a complaint with the Romanian supervisory authority ANSPDCP (dataprotection.ro). Full details on the GDPR page. You can write to us at contact@finur.io.

8. Security

Data is encrypted in transit and at rest, isolated per firm at database level, and access is protected by two-factor authentication. Internal access to production data is restricted and logged.