Privacy Policy
This policy states what personal data Trade Finance AI collects when you use TradeFinanceAI, why it is collected, how long it is kept and what you can require us to do with it. It describes the system as it is actually built — the retention periods below are read from the platform's live retention register, not transcribed from it.
01Who is responsible for your data
The data controller is Trade Finance AI. Questions about this policy, or any request concerning your personal data, should be sent to privacy@tradefinanceai.com.
02What we collect
Data you give us
- Account details — your name, email address and password. The password is never stored: only a scrypt hash of it, which cannot be reversed into the original.
- Profile and company details — telephone number, address, company name, registration and tax identifiers, where you choose to provide them.
- Billing details — your plan, billing cycle and invoice history. We never see or store your card number. Payment card data is handled entirely by PayPal; we receive only a transaction reference, an amount and a status.
- The content you submit to the AI — your questions, and the text of any document you upload for examination.
Data the platform records automatically
- Security telemetry — for each sign-in and each session: the IP address, the country and city derived from it, the browser, the operating system and the device type. This is what makes the Active Sessions and Sign-in Activity screens in your account possible, and what lets us tell you when your account is accessed from somewhere new.
- Audit records — the security-sensitive actions taken on your account, by you or by our staff, with who did it, when, and from where.
- Usage telemetry — the number of AI questions asked, tokens consumed and documents examined, used for quota enforcement and cost governance.
03Why we are allowed to process it
- Performance of a contract — providing the service you subscribed to: your account, the AI features, billing and invoicing.
- Legal obligation — issued invoices and receipts, and the financial audit trail, which tax and accounting law requires us to keep for a fixed period regardless of your wishes.
- Legitimate interest — securing accounts against unauthorised access, preventing abuse, and keeping the platform reliable. Where we rely on this basis we have considered your interests and kept the data to the minimum the purpose requires.
- Consent — optional analytics and product marketing only. These are off unless you turn them on, and turning them off later is a single toggle in Settings that takes effect immediately.
04Your documents and your AI conversations
05Who else processes your data
We use a small number of processors, each for one clearly bounded purpose:
| Processor | Purpose | What it receives |
|---|---|---|
| Netlify | Application hosting, database and file storage | All platform data, at rest in the region of the hosted database |
| Anthropic | The AI model that answers your questions | The question and document text you submit for analysis |
| PayPal | Subscription payments | Your email, the amount and the plan. Card data goes to PayPal directly and never through us |
| Resend | Transactional email delivery | Your email address and the content of the message sent to you |
We do not sell personal data, and we do not disclose it to advertisers or data brokers.
06How long we keep it
Each class of data has a stated period and a stated basis. The table below is generated from the platform's retention register at the moment you loaded this page, so it cannot fall out of step with what the system actually does. The full register, including the classes that are automatically purged on a schedule, is set out in the Data Retention Policy.
| Data class | What it holds | Retained | Basis | Purge |
|---|---|---|---|---|
| invoices | Issued invoices and receipts | 10 years | Legal obligation — tax and accounting (10 years) | On request |
| audit logs | Administrative and security audit trail | 7 years | Legal obligation — financial recordkeeping (7 years) | On request |
| backup runs | Backup and restore-test evidence | 3 years | Legitimate interest — disaster recovery evidence | Automatic |
| ai usage events | AI usage telemetry (tokens, cost, latency) | 2 years | Legitimate interest — service governance | Automatic |
| email deliveries | Transactional email delivery tracking | 2 years | Legal obligation — proof of notice | On request |
| security events | Detected security events and alerts | 2 years | Legitimate interest — security monitoring | Automatic |
| login history | Authentication attempts, successful and failed | 1 year | Legitimate interest — account security | Automatic |
| webhook deliveries | Payment and email provider webhook deliveries | 6 months | Legal obligation — payment reconciliation | Automatic |
When you close your account, data held under consent or legitimate interest is deleted. Issued invoices and the financial audit trail are retained for their statutory period because we are required to keep them — we cannot delete those on request, and we say so plainly rather than promising otherwise.
07How it is protected
- In transit — HTTPS is enforced for a year at a time, including subdomains, and the platform is declared for browser preloading, so even a first visit is never made in plaintext.
- At rest — the more sensitive fields you give us (telephone, address, company and tax identifiers, and invoice metadata) are additionally encrypted at the application layer with AES-256-GCM under a key held outside the database, so a copy of the database alone does not reveal them.
- Access — your session cookie is
httpOnly, so no script can read it; every state-changing request must also carry a signed token bound to your specific session; and every document download uses a short-lived signed link rather than a guessable file path. - Staff access — our own staff hold role-based permissions, administrator accounts are required to use multi-factor authentication, and every administrative action is written to an audit log that records who, when and from where.
08Your rights
You can exercise all of the following yourself, from Settings → Privacy and your data:
- Access and portability — download a machine-readable export of your account, profile, subscriptions, invoices, payments, consents and usage.
- Erasure — request deletion of your account. We respond within 30 days. Records we are legally required to retain are listed above and are kept; everything else is removed.
- Rectification — correct your profile details at any time.
- Withdraw consent — turn off analytics or marketing whenever you like, without affecting your access to the service.
- Object and restrict — write to privacy@tradefinanceai.com and we will respond within the same 30-day period.
- Complain — you may complain to your national data protection authority. Doing so does not require you to contact us first.
09Children
TradeFinanceAI is a professional tool sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 18.
10Changes to this policy
Every version of this policy carries a version number, shown at the top of this page. Your acceptance is recorded against that number, so it is always possible to establish which text you were shown. When a change materially affects your rights we will ask you to accept the new version before you continue.