AI Finance Team
All legal documents

Privacy Notice

Version: 2026-08-privacy-v1 · Effective from: 23 Aug 2026

Download (Markdown)Save a copy of this document.

Controller: the MVP company Kft., registered seat 2162 Őrbottyán, Táncsics Mihály utca 50., Hungary, company registration number 13-09-223340, tax number 32113644-2-13, trading as AI Finance Team.

Contact: privacy@aifinance.team

1. The two roles we play, read this first

a) Your firm's clients' bookkeeping data: we are a processor. If you are an accounting firm using AIFT, or a client company whose accountant uses AIFT, the invoices, bank transactions and documents processed in AIFT are controlled by the accounting firm (or its client company), not by AIFT. We process that data strictly under our Data Processing Agreement. If you are an employee, customer or supplier of a company whose bookkeeping runs through AIFT and you want to exercise your data-subject rights, contact that company or its accounting firm. We support them in responding, but the decision is theirs. The rest of this notice covers only the data for which AIFT itself is the controller.

a2) If your accountant invited you into AIFT (client companies). You have your own AIFT account, so this notice applies to you directly for the data in section (b): your name, email, language, role and security logs. Your company's bookkeeping data is a different matter: your accounting firm decides how it is used, and requests about it go to them (see section 6). The billing rows in section 2 do not apply to you, because client companies are not billed by AIFT. The terms covering your access are the Client Access Terms.

b) Account, billing, website and service data: we are the controller. Described below.

2. What we collect as controller, why, and on what legal basis

DataPurposeLegal basis (Art. 6)Retention
Account data: name, email, password hash, language preference, role membershipsProviding login and workspace access(1)(b) contractAccount lifetime plus 30 days
Authentication and security logs, including bot-protection checksAccount security, abuse prevention(1)(f) legitimate interest12 months
Feedback you submit through the in-app feedback button: your message, plus your name, email, firm and workspace name, the page you were on and your languageAnswering you and improving the service(1)(f) legitimate interest24 months
Records of acceptance of our terms (who accepted which version, when, in which language)Proving the contract was concluded; defending claims(1)(b) contract; (1)(f) legitimate interestDuration of the contract plus the limitation period
Billing data: firm name, billing address, VAT number, subscription and invoice records (card data is entered at and held by Stripe, never by us)Billing and statutory accounting duties(1)(b) contract; (1)(c) legal obligation8 years (Hungarian Accounting Act)
Usage records: per-workspace document counts, feature usage, AI cost metrics; the per-document billing evidence behind each closed monthBilling (usage-based plans), capacity planning, invoice disputes(1)(b) contract; (1)(c) legal obligationBilling records and evidence 8 years; operational metrics 24 months
Support and email correspondence with usAnswering you(1)(b) / (1)(f)24 months

3. Invitation and notification emails

We send transactional email only (invitations, sign-in and security emails, workspace notifications, message nudges), from an EU sending region. We do not use open or click tracking, and we send no marketing email without separate consent.

4. Cookies and the security check

The app sets only strictly necessary cookies: the authentication session and a locale (language) cookie.

On our sign-in, sign-up, password-reset and password-change pages we run Cloudflare Turnstile, a bot-protection check that prevents automated attacks on accounts. It receives your IP address and browser signals in order to distinguish humans from bots; it does not track you across sites and does not build a profile. This is a strictly necessary security measure, so it does not require consent.

Because the app uses only essential cookies and this security check, no consent banner is shown there.

Our marketing website at aifinance.team is different. It uses analytics (Google Tag Manager and Google Analytics) and therefore asks for your consent through a cookie banner before any non-essential cookie is set. The Cookie and Website Notice, an annex to this one, sets out exactly what that site places, what loads before you choose, and how to change your mind.

Before you log in, we may read your browser language and your request's country signal (from the hosting provider's request header) to choose a display language; this is processed transiently and not stored.

5. Where data lives, and who helps us process it

All databases and file storage: EU (AWS Frankfurt); application compute: Frankfurt. A small number of sub-processors help us provide the service; the current list, locations and safeguards are published on our sub-processor register. Where a sub-processor processes data outside the EEA (for example semantic-search embeddings, payment processing, the bot-protection check, or the internal notification we receive when you send feedback), the transfer is protected by Standard Contractual Clauses. Where AI document processing runs is a setting on each workspace, and the EU option (AWS Bedrock, Frankfurt) is the default for new workspaces; a workspace set to the US option, or a step whose model is not yet available in the EU, runs on Anthropic's first-party API in the US under Standard Contractual Clauses. On the EU option the Bedrock service does not store the prompts or results and does not share them with the model provider; our own processing logs keep prompt and response copies in Frankfurt for 14 or 90 days, then delete them automatically.

6. Your rights

Access, rectification, erasure, restriction, portability and objection (Art. 15-21). Write to privacy@aifinance.team; we respond within one month (Art. 12(3)). You may complain to your supervisory authority; in Hungary this is NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság, naih.hu), or your local authority elsewhere. For your firm's clients' bookkeeping data, see §1(a): the request goes to the controller, meaning the accounting firm or its client company.

7. Security in one paragraph

Tenant isolation enforced in the database itself (row-level security), encryption in transit and at rest, credentials in a write-only encrypted vault, private document storage with short-lived signed links, role-based access enforced server-side, bot protection on authentication pages, audit logging, and automatic purge of AI request logs (14/90 days). Ask us at privacy@aifinance.team if you need more detail for a vendor assessment.

8. Changes

We announce material changes in the app and by email at least 14 days before they take effect. Prior versions are available on request.