Legal
Privacy policy
Last updated 1 July 2026
01Who we are
Finlecy provides reconciliation software to businesses. This policy explains what we do with personal data when you visit finlecy.com, when you contact us, and when your employer uses our platform.
Our postal address is C/ Hijuela de Lojo 75, 20491 Belauntza, Guipúzcoa, Spain. You can reach us at hello@finlecy.com or on +34 716 694 618.
For personal data relating to visitors to this site and to people who contact us, Finlecy is the data controller. For personal data contained in reconciliation data uploaded by a customer, the customer is the controller and Finlecy is a processor acting on their documented instructions.
02What we collect, and why
We try to collect as little as possible. Everything below is either given to us deliberately or is necessary to keep the service running.
- Contact details you send us — name, email address, company and anything you write in a message. We use these to reply and to keep a record of the conversation. Legal basis: legitimate interests in responding to an enquiry, or steps taken at your request before entering a contract.
- Account data for platform users — name, work email, role and authentication identifiers. Necessary to provide the service under our contract with your employer.
- Operational logs — IP address, timestamps, requests made and actions taken in the product. Retained for security, audit and troubleshooting. Legal basis: legitimate interests in operating a secure service, and our customers' need for an audit trail.
- Reconciliation data uploaded by customers. This is business transaction data. It may incidentally contain personal data such as a counterparty name in a payment narrative. We process it only on the customer's instructions.
03What we do not do
- We do not run advertising or marketing trackers on this website. There is no analytics script, no advertising pixel and no third-party cookie.
- We do not sell, rent or share personal data with anyone for their own marketing purposes.
- We do not use customer data to train machine-learning models — ours or anyone else's. There is no opt-out because there is nothing to opt out of.
- We do not build profiles of you or make decisions about you by automated means that produce legal or similarly significant effects.
04Cookies
This site sets no cookies and stores nothing in your browser. The interactive playground runs entirely in your browser and transmits nothing — data you type into it never leaves your device and is discarded when you close the tab.
The signed-in product uses a single strictly necessary cookie to maintain your session. It carries no tracking identifier and expires when your session ends.
05Where data is processed
All personal data is processed within the European Union, in a single region. We do not transfer personal data outside the EEA in the ordinary course of providing the service, including for support and diagnostics.
Where an Enterprise customer chooses a deployment in their own infrastructure, processing takes place wherever that infrastructure is located and the customer determines the arrangement.
06Sub-processors
We use a small number of sub-processors for hosting, email delivery and error monitoring. Every one is EU-resident and bound by a written processing agreement.
The current list is published and available on request. Customers receive at least thirty days' notice before any addition, with a right to object.
07How long we keep things
On request or at contract end we delete customer data verifiably within thirty days, including from backups, and issue a deletion certificate.
- Enquiry correspondence: three years from the last contact, then deleted.
- Account data: for the duration of the contract, then thirty days.
- Operational and audit logs: aligned to the customer's configured retention, since these records form part of the audit trail they rely on.
- Reconciliation data: as configured by the customer — ninety days, two years or seven years by plan — or until they ask us to delete it.
08Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, and to receive it in a portable format. You can also withdraw consent where we rely on it, although in most cases we do not.
To exercise any of these, write to hello@finlecy.com. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If your data reached us through a customer's use of the platform, we will direct you to that customer, since they determine how it is used. We will help them respond.
You may also complain to a supervisory authority. In Spain this is the Agencia Española de Protección de Datos. We would rather you raised it with us first, but that is your choice and not a precondition.
09Security
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access is role-based and logged. Finlecy staff hold no standing access to customer data; support access is time-bound, approved by a second engineer and visible in the customer's own access log.
Our security practices are described in more detail on the security page, including the parts where we are not yet certified.
10Changes
We will post any change here and update the date at the top. Where a change materially affects how we handle personal data, we will contact customers directly rather than relying on you to notice.