Last updated: 15th July 2026
Finzu Ltd ("Finzu", "we", "us", "our") provides an accounting platform for UK small and medium-sized businesses. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it.
This policy applies to visitors to finzu.ai, users of our beta programme, and customers using the Finzu platform (together, the "Services"). It should be read alongside our Terms of Service and Cookie Policy.
Finzu is the data controller for personal data about you as a user of the Services — your account details, billing information, communications with us, and how you use the platform.
For the financial and accounting data you upload or connect on behalf of your business, Finzu acts as a data processor and your business remains the controller. We process that data on your instructions and in line with our data processing agreement.
The Finzu platform processes your business's financial data in order to deliver bookkeeping, reconciliation, and reporting. This includes:
This data may include personal data about your customers, suppliers, or employees where it appears in your financial records. We process it on your instructions, as your processor, and you remain responsible for having a lawful basis to share it with us.
We do not use your data to train AI models. Our AI providers process your data to return a result and do not retain it.
Finzu does not make decisions about you that produce legal or similarly significant effects based solely on automated processing, within the meaning of Article 22 of the UK GDPR.
Under UK GDPR, we rely on the following legal bases, depending on the activity:
We use the following service providers to deliver the Services. Each is bound by a data processing agreement.
We will update this list before adding a new sub-processor and, where required by our agreement with you, give you advance notice.
We also share information with:
Your application data — your account, ledger, transactions, and accounting records — is stored in the United Kingdom. Documents and files you upload are stored in the European Union, and AI processing takes place in the European Union.
Transfers from the UK to the EU are covered by the UK's finding of adequacy for the European Economic Area.
Two of our providers may process data outside the UK and EU. Stripe, which handles billing for your Finzu subscription, may transfer payment and billing data to the United States. Google, which we use for email and customer support correspondence, may process that correspondence in the United States. Neither has access to your business's financial records held in the platform. These transfers are covered by appropriate safeguards recognised under UK GDPR, including the UK International Data Transfer Addendum and the UK Extension to the EU–US Data Privacy Framework.
Your business's data. We retain your business's financial and accounting data for as long as your account is active. When your account ends, we return or delete it in line with our data processing agreement.
Our own records. We retain records we are required to keep as a business, such as invoices we issue to you and our own tax and accounting records, for at least six years, as required by UK tax law.
Beta programme data. Where a beta participant does not go on to become a customer, we retain their data for 12 months and then delete or anonymise it, unless a longer period is required by law. Where a beta account converts to a live account, the retention terms above apply.
Technical logs. Server and security logs, which include IP addresses, are retained for 90 days and then deleted.
Audit records. Records of changes made to your business's financial data within the platform form part of your accounting records and are retained for as long as your account is active, in line with the terms above.
Under UK GDPR, you have the right to:
To exercise any of these rights, contact us at privacy@finzu.ai. We will respond within one month. If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Where your business's financial data includes personal data about your own customers or staff, requests relating to that data should be directed to your business as the data controller. We will support you in responding, as set out in our data processing agreement.
We use cookies and similar technologies for essential site functionality and, where you consent, analytics. You can manage your preferences through the cookie banner or your browser settings. For details, see our Cookie Policy.
We may update this policy from time to time to reflect changes to our practices or for legal, operational, or regulatory reasons. We will post the updated version here with a revised "Last updated" date, and where changes are material, we will provide additional notice.