Legal

Privacy policy

Last updated: 13 September 2026

Data we collect

Company profile, business contact details, software stack, invoice workflow metadata, readiness answers, provider-request details, order and payment status, and basic product analytics.

Data we do not request

Do not submit invoice files, customer-level transaction data, bank details, tax returns, identity documents, personal IDs or payment-card details. Card data is handled by the payment provider.

How we use data

To calculate and save the requested readiness result, send requested emails, process report orders, fulfil provider matching, operate the manual review queue, secure the service and understand funnel performance.

Retention

Unpaid assessments and provider requests are retained for up to 12 months. Paid order records are retained for up to 7 years where reasonably required for accounting, dispute and legal obligations. Analytics may be retained in aggregated form. We may delete data sooner when no longer needed.

Deletion requests

Email privacy@finwaypoint.com from the relevant business email to request access or deletion. Some paid-order information may need to be retained for legal or accounting obligations.

Processors and transfers

We may use hosting, database, email and payment processors. They process limited data needed to provide their service under their own security and contractual controls.

Security and changes

We use access controls, signed payment webhooks and data minimisation. No system is risk-free. Material policy changes will be dated on this page.