Privacy Policy

Last updated · 22 Jul 2026

Find.report Privacy Policy

Privacy Policy

Last updated 2026-07-02

This Privacy Policy explains how Find.report collects, uses, discloses, stores and protects Personal Data when you visit our website, create an account, use our dashboards, upload transactions, connect financial accounts, use AI summaries, receive reports, contact support, subscribe to paid Plans or otherwise interact with the Service.

Where we decide why and how Personal Data is processed, we are the controller. Where we process Personal Data in Customer Data on behalf of a business customer, we usually act as processor and the customer is the controller. Our Terms & Conditions include a Data Processing Addendum for processor activities.

Contents
  1. Privacy summary
  2. Scope
  3. Personal Data we collect
  4. Sources of Personal Data
  5. How we use Personal Data
  6. Lawful bases
  7. AI processing
  8. Automated decision-making
  9. Aggregated data and benchmarks
  10. Sharing and disclosure
  11. International transfers
  12. Retention
  13. Security
  14. Your rights
  15. Cookies and analytics
  16. Marketing communications
  17. Children
  18. Changes
  19. Contact and complaints

1. Privacy summary

Find.report helps business users analyse financial activity, expenses, cash flow, market exposure, benchmarks and AI-generated business insights. To provide the Service, we process business account information, user information, uploaded financial files, connected account data, prompts, AI Outputs, usage logs, billing records and support messages.

We do not sell your identifiable financial data. We use Customer Data to provide, secure, support and improve the Service. We may use aggregated or de-identified data for benchmarks and product analytics where it does not reasonably identify a customer or individual.

AI Outputs are generated to assist users, but users remain responsible for reviewing them. The Service is not intended to make solely automated decisions with legal or similarly significant effects about individuals.

2. Scope

This Policy applies to Personal Data processed through the Find.report website, app, dashboards, account management, uploads, connected accounts, AI features, reports, emails, support channels, analytics and related services.

This Policy does not apply to third-party websites, banks, payment providers, accounting tools, AI providers, market data providers or other third-party services that have their own privacy policies, except where they process Personal Data for us as our service provider.

3. Personal Data we collect

3.1 Account and user data

  • name, email address, phone number, role, job title, company name and workspace membership;
  • login credentials, authentication identifiers, session information and security settings;
  • user preferences, notification settings, language, region, currency and dashboard configuration;
  • Admin User actions, invitations, role changes and permission settings.

3.2 Company and business data

  • company name, industry, country, business size, website, registration details and business profile;
  • billing contact, tax information, invoice details, subscription Plan and payment status;
  • business categories, financial goals, market watchlists, selected benchmarks and reporting preferences.

3.3 Financial and transaction data

When you upload, enter, import or connect financial data, we may process:

  • transaction dates, amounts, currencies, descriptions, balances, account names, account identifiers, categories and metadata;
  • vendor, supplier, customer, payee, payer, merchant, employee-expense or counterparty names;
  • invoices, receipts, spreadsheets, statements, CSV files, ledger files and uploaded documents;
  • bank account data or payment account data retrieved through open-banking or account-information integrations, where enabled;
  • expense categories, recurring charges, subscriptions, cash-flow indicators, anomalies, benchmarks and derived metrics.

Financial records may contain Personal Data about employees, contractors, customers, suppliers, sole traders and other individuals. Business customers are responsible for ensuring they have a lawful basis to upload or connect such data.

3.4 AI inputs and outputs

  • prompts, queries, instructions, uploaded context and user-selected data used to generate AI Outputs;
  • AI-generated summaries, classifications, risk briefings, recommendations, report drafts and explanations;
  • feedback, thumbs-up/down signals, corrections, category edits and quality-review information.

3.5 Usage, device and technical data

  • IP address, approximate location, device type, browser, operating system, user agent and identifiers;
  • pages viewed, features used, clicks, timestamps, session events, error logs and performance data;
  • security logs, access logs, audit logs, fraud-prevention signals and diagnostic data;
  • cookie identifiers and similar technology data, as described below.

3.6 Support, feedback and communications

  • support requests, chat messages, emails, call notes, attachments and admin responses;
  • survey responses, product feedback, feature requests, testimonials and communication preferences;
  • records of legal, privacy, billing, security or compliance correspondence.

3.7 Billing and payment data

We may collect invoice details, billing address, VAT or tax details, subscription status and payment metadata. Payment-card details are normally processed by payment providers. We do not store full card numbers.

3.8 Data we ask you not to provide

The Service is not designed to process medical records, biometric data, children’s data, criminal-offence data, national identifiers, full payment-card numbers, passwords, highly sensitive personal data or special-category data unless expressly supported and agreed in writing. Please do not upload such data unless necessary, lawful and agreed.

4. Sources of Personal Data

We may collect Personal Data from:

  • you directly when you create an account, configure dashboards, upload files, contact us or use the Service;
  • your employer, client, company or workspace Admin User when they invite you or manage access;
  • connected banks, payment accounts, accounting tools, cloud storage tools or integration providers that you authorise;
  • payment processors, fraud-prevention tools, authentication providers, analytics tools and support systems;
  • public and commercial market data, business data, news, exchange-rate and financial information providers;
  • cookies and similar technologies when you visit our website or use the Service.

5. How we use Personal Data

We use Personal Data to:

  • create, authenticate, secure and manage accounts;
  • provide dashboards, ledgers, uploads, transaction views, classifications, metrics, health scores, benchmarks and reports;
  • connect, refresh and display data from authorised financial accounts and integrations;
  • generate AI summaries, risk briefings, recommendations, explanations, category suggestions, market views and report drafts;
  • administer Plans, subscriptions, billing, invoices, renewals, cancellations and payment status;
  • provide customer support, troubleshooting, training, documentation and service communications;
  • monitor performance, debug errors, improve features, test models and develop new functionality;
  • protect the Service, prevent fraud, detect misuse, investigate security events and enforce terms;
  • send product updates, legal notices, security notices and administrative messages;
  • send marketing communications where permitted and manage opt-outs;
  • produce aggregated or de-identified benchmarks, analytics and platform statistics;
  • comply with law, regulatory obligations, tax rules, accounting requirements, court orders and lawful requests;
  • exercise, establish or defend legal rights.

6. Lawful bases

Where UK GDPR or EEA GDPR applies, we rely on the following lawful bases:

PurposeLawful basis
Creating accounts, providing the Service, processing uploads, generating reports, administering subscriptions and responding to support requests.Performance of a contract or steps before entering into a contract; legitimate interests in providing a business service.
Processing Customer Data on behalf of business customers.Processor activity on Customer’s instructions. Customer determines its own lawful basis.
Security monitoring, fraud prevention, abuse prevention, access logs and service integrity.Legitimate interests in protecting the Service, users and customers; legal obligation where applicable.
Billing, accounting, tax, legal notices and statutory recordkeeping.Performance of a contract; legal obligation; legitimate interests in managing our business.
AI summaries, classifications, metrics, benchmarks and product improvement.Performance of a contract; legitimate interests in improving and providing the Service; consent where required.
Cookies and analytics.Consent where required by e-privacy rules; legitimate interests for strictly necessary security and service cookies.
Marketing communications.Consent where required; legitimate interests for permitted business-to-business communications; compliance with opt-out rules.
Legal claims, compliance, investigations and corporate transactions.Legal obligation; legitimate interests in protecting rights, complying with law and operating our business.

7. AI processing

Find.report may use AI and machine-learning features to classify transactions, detect patterns, generate business summaries, explain changes, draft reports, assess financial-health indicators, produce risk briefings and provide market or benchmark commentary.

AI processing may involve sending minimised inputs to AI service providers or operating models in our own or third-party infrastructure. Inputs may include selected transactions, categories, summaries, prompts, dashboard context or other data required to provide the requested feature.

As a policy, we do not sell identifiable Customer financial data and do not intentionally use identifiable Customer financial data to train public AI foundation models. We may use aggregated or de-identified data, user feedback, error reports, evaluation datasets and synthetic data to test, monitor, improve and develop the Service.

We use reasonable controls designed to minimise unnecessary disclosure to AI providers, protect confidentiality and assess AI-related risks. However, AI Outputs may be inaccurate, incomplete, outdated or unsuitable. Users must review AI Outputs before relying on them.

8. Automated decision-making and profiling

The Service may create scores, categories, forecasts, benchmarks, anomaly indicators or AI Outputs. These are intended to assist human users and are not intended to make solely automated decisions that produce legal or similarly significant effects about individuals.

You must not use the Service as the sole basis for employment, lending, credit, insurance, eligibility, legal, disciplinary, medical, housing or similarly significant decisions about individuals. If you use exported data or outputs in a regulated or high-impact decision process, you are responsible for providing required notices, human review, appeal mechanisms and legal compliance.

9. Aggregated data, de-identified data and benchmarks

We may create aggregated or de-identified data that does not reasonably identify a customer or individual. We may use this data for:

  • industry benchmarks and all-company benchmark views;
  • product analytics and feature performance;
  • security and reliability trends;
  • market, category and expense trend analysis;
  • model evaluation and service improvement;
  • public or commercial statistics where customers and individuals are not reasonably identifiable.

We take steps designed to reduce the risk of re-identification before using aggregated or de-identified data for external benchmarking.

10. Sharing and disclosure

We may share Personal Data with:

  • Service providers and subprocessors for hosting, storage, authentication, analytics, payments, open banking, AI inference, email, support, monitoring, security, fraud prevention and infrastructure;
  • Customer admins and workspace users according to workspace settings, roles and permissions;
  • Integration providers where you connect banks, accounting systems, payment accounts, cloud tools or APIs;
  • Payment providers to process subscriptions, invoices, taxes, refunds and fraud checks;
  • Professional advisers such as lawyers, accountants, auditors, insurers and consultants;
  • Authorities, regulators and courts where required by law or necessary to protect rights, safety, security or lawful interests;
  • Corporate transaction parties in connection with a merger, acquisition, investment, financing, reorganisation, insolvency, sale of assets or due diligence, subject to appropriate safeguards;
  • Others with your instruction or consent.

We do not sell identifiable Customer financial data. We do not disclose Customer-identifiable benchmark data publicly unless authorised or required by law.

11. International transfers

We may process Personal Data in the United Kingdom, European Economic Area, United States and other countries where we or our service providers operate. Where applicable law requires a transfer mechanism for international transfers, we use appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, EU Standard Contractual Clauses or equivalent lawful mechanisms.

12. Retention

We retain Personal Data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining security, complying with legal obligations, resolving disputes, enforcing agreements and maintaining business records.

Data categoryTypical retention approach
Account and workspace dataFor the life of the account, then for a reasonable period for deletion, backup, legal, security and dispute purposes.
Uploaded financial data and connected account dataWhile the workspace is active or as configured by Customer, then deleted or anonymised after termination subject to backup cycles and legal obligations.
Billing, invoice and tax recordsUsually retained for up to 7 years or longer if required by law, tax, accounting or dispute obligations.
Security, audit and access logsRetained for a period appropriate to security, fraud prevention, compliance and incident investigation needs.
Support communicationsRetained for support history, quality, training, legal and dispute-resolution purposes.
Marketing dataUntil you unsubscribe, object or the data is no longer needed. Suppression lists may be retained to honour opt-outs.
Aggregated or de-identified dataMay be retained indefinitely where it does not reasonably identify a customer or individual.
BackupsDeleted on backup rotation cycles, unless retained longer for security, continuity, legal hold or disaster recovery.

Actual retention periods may vary based on Plan, configuration, legal requirements, security events, disputes, backups and technical constraints.

13. Security

We use technical and organisational measures designed to protect Personal Data. These may include encrypted transmission, access controls, role-based permissions, least-privilege internal access, logging, monitoring, backup processes, vulnerability management, provider due diligence, confidentiality obligations and incident-response procedures.

No system is completely secure. You are responsible for protecting your credentials, devices, access permissions, exports and account settings. Notify us promptly at hi@find.agency if you suspect unauthorised access or a security issue.

14. Your rights

Depending on your location and the role we play, you may have rights to:

  • request access to your Personal Data;
  • request correction of inaccurate or incomplete Personal Data;
  • request deletion of Personal Data;
  • request restriction of processing;
  • object to processing based on legitimate interests or direct marketing;
  • request data portability;
  • withdraw consent where processing is based on consent;
  • complain to a supervisory authority.

Where we process Personal Data on behalf of a business customer, we may refer your request to that customer or act on the customer’s instructions. To exercise rights, contact hi@find.agency. We may need to verify your identity and request information to locate your data.

If you are in the United Kingdom, you may complain to the Information Commissioner’s Office. We encourage you to contact us first so we can try to resolve the concern.

15. Cookies and analytics

We use cookies and similar technologies to operate the website and Service, authenticate users, maintain sessions, remember preferences, improve performance, understand usage and protect against fraud or abuse.

Cookie categoryPurposeConsent approach
Strictly necessaryAuthentication, security, session management, load balancing, fraud prevention and core service functionality.Usually used without consent where necessary to provide the requested service.
PreferencesRemember settings such as language, region, dashboard preferences and display options.Consent or settings-based controls where required.
AnalyticsUnderstand usage, errors, performance and feature adoption.Consent where required by e-privacy rules.
MarketingMeasure campaigns, personalise communications or support advertising.Consent where required.

You can manage cookies through browser settings and, where provided, our cookie banner or preference centre. Blocking some cookies may affect the Service.

16. Marketing communications

We may send business updates, product announcements, newsletters, offers or event information where permitted by law. You can opt out of marketing emails using the unsubscribe link or by contacting us. We may still send transactional, legal, billing, security and service-related messages.

17. Children

Find.report is intended for business users and is not directed to children under 16. We do not knowingly collect children’s Personal Data. If you believe a child has provided Personal Data, contact us so we can take appropriate steps.

18. Additional regional privacy information

Users in some regions may have additional privacy rights under local law. Where applicable, we will honour those rights. This may include rights to know, access, correct, delete, restrict, object, opt out of certain disclosures, appeal a decision or lodge a complaint. We do not discriminate against users for exercising privacy rights.

If a regional supplement is required for your market, we may publish or provide a separate addendum.

19. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified by email, in-app notice, website notice or another reasonable method. The updated Policy will apply from the date stated unless otherwise required by law.

20. Contact and complaints

Privacy contact: hi@find.agency

Security contact: hi@find.agency

Legal contact: hi@find.agency

Appendix: Business customer data protection notes

If you are a business customer, you are responsible for providing appropriate privacy information to individuals whose Personal Data you upload, import or connect to Find.report. This may include employees, customers, suppliers, sole traders, vendors and counterparties appearing in financial records or transaction descriptions.

You should avoid uploading unnecessary Personal Data, special-category data, criminal-offence data, children’s data, full card numbers, passwords or unrelated sensitive information. You should configure user permissions carefully, review exports and maintain your own retention practices.