Finlai

Last updated: July 2026

Privacy Policy

Version 2.0. Scope: Spain.

1. Introduction and data controller

For FINLAI SOFTWARE FISCAL, S.L. (hereinafter, “Finlai”, “we” or the “Controller”), the protection of your personal data is a priority, especially given the economic, tax and financial nature of the information we process. This Privacy Policy (hereinafter, the “Policy”) describes how we collect, use, retain and protect your personal data when you use our web platform and application for financial, document, tax and invoicing management (hereinafter, the “Platform”), in compliance with Regulation (EU) 2016/679 (“GDPR”) and Ley Orgánica 3/2018, of 5 December (Spanish Data Protection Act, “LOPDGDD”).

Accessing, registering on and using the Platform implies acceptance of the practices described in this Policy. We recommend that you read it carefully to understand how we process your personal information.

  • Identity: FINLAI SOFTWARE FISCAL, S.L.
  • Registered office: C/ Serrano Anguita 13, Hub Barceló, 28004, Madrid.
  • Tax ID (NIF): B88869128.
  • Privacy e-mail: privacy@finlai.es

2. Definitions

TermDefinition
ClientNatural or legal person who contracts the Platform to manage their own tax, accounting and invoicing activity.
UserNatural person who accesses the Platform on behalf of the Client (account holder, authorised employee or collaborator).
Client's Third PartiesCustomers, suppliers, advisors, employees or invoice recipients whose data the Client incorporates into the Platform.
PlatformFinlai's website and web application, including its financial, document, tax, invoicing and, where applicable, payroll management functionalities.
Personal DataAny information relating to an identified or identifiable natural person, within the meaning of art. 4(1) GDPR.

3. Principles applicable to processing

Finlai processes personal data in accordance with the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability, set out in art. 5 GDPR. In particular, given the economic and tax nature of much of the data processed, Finlai applies a reinforced minimisation standard, limiting internal access to the information strictly necessary for each purpose.

4. Who should read this Policy and whose data do we process?

This Policy applies to the personal data of: (i) the User who registers on and uses the Platform; (ii) the Client's contact persons where the Client is a legal person; (iii) the Client's employees, where the payroll management service is contracted; and (iv) the Client's third parties whose data the Client incorporates into the Platform for the provision of the service (customers, suppliers, advisors or invoice recipients).

With respect to data of the Client's third parties, it is the Client who determines the purposes and means of the initial processing and who therefore holds the position of data controller vis-à-vis those persons, with Finlai acting as data processor under the terms of clause 8 of this Policy.

5. What personal data do we process, for what purposes and on what legal basis?

Below we detail the categories of data we process, the purposes for which we use them and the legal basis that entitles us to do so:

Purpose of ProcessingPersonal Data ProcessedLegal Basis for Processing
Creation and management of the account, authentication and workspace.Identification and contact data (first name, surname, e-mail address, telephone number), access credentials and workspace data (business name, economic activity).Performance of a contract and pre-contractual measures (art. 6(1)(b) GDPR).
Provision of the financial, document, tax and invoicing management services.Tax data (tax ID (NIF), tax address, economic activity, IAE heading), documents, invoices, income, expenses, taxes, withholdings, data of the Client's customers and suppliers, products and services.Performance of a contract (art. 6(1)(b) GDPR), compliance with legal obligations (art. 6(1)(c) GDPR) and, with respect to third-party data incorporated by the Client, processing on behalf of the controller pursuant to art. 28 GDPR.
Provision of the human tax advisory service, where contracted.Tax and accounting data and documentation provided by the Client that is necessary to provide the advisory service.Performance of a contract (art. 6(1)(b) GDPR).
Connection to bank accounts and aggregation of transactions.Identification data of the account holder and bank transactions (amounts, descriptions, dates, bank), obtained through bank aggregation providers authorised under PSD2.Performance of a contract and the Client's specific consent for the connection of each bank account (art. 6(1)(a) and 6(1)(b) GDPR).
Obtaining the power of representation before the Spanish Tax Agency and downloading tax data for the provision of the advisory service.Data obtained through the powers of representation granted by the Client before the AEAT (among others, the GENERALNOT, GENERALDATPE, GENERALLEY58 and PAGOAPODECC procedures): Tax Data, Census Data, the tax returns filed by the Client in the last four (4) years and their electronic notifications.Performance of a contract and compliance with legal obligations, on the basis of the power of representation granted by the Client (art. 6(1)(b) and 6(1)(c) GDPR).
Processing of documents through OCR and Artificial Intelligence (reading of invoices, classification of expenses, deduction suggestions, alerts and drafts).Data included in the documents and files uploaded by the Client (invoices, receipts, bank statements) and results generated by the OCR/AI systems.Performance of a contract and legitimate interest in improving the security, quality and reliability of the service (art. 6(1)(b) and 6(1)(f) GDPR).
Issuance of invoices, management of collections and compliance with the Verifactu regulations.Identification and tax data of the issuer and the recipient of the invoice, line items, amounts, taxes, withholdings and invoicing records required by the Verifactu regulations.Performance of a contract and compliance with legal, commercial and tax obligations (art. 6(1)(b) and 6(1)(c) GDPR).
Management of payments, subscriptions and non-payments.Billing and payment data, managed through an external payment provider, Stripe.Performance of a contract (art. 6(1)(b) GDPR).
Payroll management (payslips and Social Security) for Clients with employees (Premium and Empresas plans).Identification data, Social Security affiliation data and employment and remuneration data of the Client's employees.Performance of a contract and compliance with legal obligations in employment and Social Security matters (art. 6(1)(b) and 6(1)(c) GDPR).
Handling of support, incidents, enquiries and commercial or demo requests.Identification and contact data, and the content of the enquiry or incident raised.Consent, pre-contractual measures, performance of the contract or legitimate interest (art. 6(1)(a), 6(1)(b) and 6(1)(f) GDPR).
Sending of operational, legal, technical, security and billing communications.Identification and contact data.Performance of the contract and compliance with a legal obligation (art. 6(1)(b) and 6(1)(c) GDPR).
Sending of the newsletter, product news and commercial communications.Identification and contact data (e-mail address).Explicit consent or legitimate interest in offering similar services to existing Clients, with a simple and free unsubscribe option in every communication (art. 6(1)(a) and 6(1)(f) GDPR; art. 21 of Ley 34/2002 (Spanish E-Commerce Act, “LSSI-CE”)).
Security, fraud prevention, technical logs and abuse detection.Technical logs, browsing data and platform usage data.Legitimate interest and legal compliance, where applicable (art. 6(1)(f) and 6(1)(c) GDPR).
Management of job applications, if Finlai receives CVs or job applications.Data included in the CV and the application.Consent and pre-contractual measures (art. 6(1)(a) and 6(1)(b) GDPR).

6. Origin of the data

The personal data we process comes from:

  • The data subject themselves, through the registration form, the uploading of documents or contact with support.
  • The Client, when they incorporate data of their own customers, suppliers, advisors or employees into the Platform.
  • Bank aggregation providers, when the Client expressly authorises the connection of their accounts.
  • Public sources or official registers, where necessary to verify tax or identification data within the scope of the contracted advisory service.
  • The Agencia Estatal de Administración Tributaria (AEAT), through the powers of representation that the Client grants us for their representation.

7. For how long will we retain your data?

We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Once it is no longer necessary, we will delete it or, where there is a legal obligation or potential liability, block it in accordance with art. 32 LOPDGDD, keeping it available exclusively to judges, courts, the Public Prosecutor's Office or the competent Public Administrations during the applicable limitation period, after which it will be permanently deleted.

  • Account data: will be retained for as long as you keep your account active. After deregistration, it will be blocked for six (6) years if necessary to address contractual or legal liabilities.
  • Data of the financial, document, tax and invoicing management service: will be retained for the duration of the service. After cancellation, it will be deleted, anonymised or blocked for six (6) years where it forms part of contractual, tax, accounting or claims-defence documentation, in accordance with the Código de Comercio (Spanish Commercial Code) and tax regulations (arts. 66 et seq. of the Ley General Tributaria, Spanish General Tax Act, “LGT”).
  • OCR/AI results: will be retained for the duration of the service, according to the period applicable to the documents or transactions with which they are associated.
  • Billing, collections, payments and tax data: will be retained for six (6) years due to commercial and tax obligations, unless a longer legal period applies or liabilities are pending.
  • Support, incident and enquiry data: once the request has been resolved, it will be blocked for one (1) year, unless it results in a contract or a claim.
  • Data for commercial communications: will be processed until consent is withdrawn or you object to the processing, with a minimal suppression list being retained to prevent further unwanted communications.
  • Technical and security logs: will generally be retained for up to twelve (12) months, unless there is an ongoing investigation, a legal obligation or a claim.
  • Job application data: will be retained during the selection process and, after its closure, for one (1) year, unless you object or request deletion.

8. Recipients and data transfers

8.1 With whom do we share personal data?

At Finlai, our Clients' privacy is fundamental. We do not sell, rent or disclose your personal data to third parties for marketing purposes without your explicit consent. However, for the proper provision of our services, your data may be shared with the following categories of recipients, all of them subject to a data processing agreement pursuant to art. 28 GDPR when acting as processors:

  • Cloud hosting, database and storage providers, preferably located in the European Economic Area (EEA).
  • OCR and Artificial Intelligence provider(s) for the automatic reading and classification of documents.
  • External payment provider, for the management of subscriptions, collections and non-payments.
  • Providers of electronic invoicing and of the technical systems necessary for compliance with the Verifactu regulations.
  • Tax, legal, accounting and financial advisors and other professional collaborators necessary to provide the contracted advisory service.
  • Other technical support, communications and analytics providers.

Finlai maintains an up-to-date register of data processors and sub-processors, which may be provided to any Client who requests it, in compliance with the duty of transparency towards the data controllers on whose behalf third-party data is processed.

8.2 Third-party data provided by the Client (data processing agreement)

When you use the Platform, you may incorporate personal data of your own customers, suppliers, advisors, employees or invoice recipients. In these cases, you are the controller of that data and you must have a sufficient legal basis to incorporate it into Finlai, as well as inform the data subjects where applicable. Finlai acts as data processor, processing such data solely in accordance with your documented instructions, for the provision of the contracted service, and applying the security and confidentiality measures required by art. 28 GDPR.

8.3 The Client's current advisor and other independent controllers

When you expressly request or authorise it, we may communicate your data to your current advisor or other third parties you designate, to facilitate the management of the change of advisory firm or other purposes you authorise. Likewise, we may share data with banks (with respect to the account aggregation services) and with external tax or legal advisors, all of them acting as independent controllers of their own processing.

8.4 Public authorities

We will communicate data to the Agencia Estatal de Administración Tributaria (AEAT), the Tesorería General de la Seguridad Social, courts, tribunals, law enforcement bodies or competent public administrations where there is a legal obligation or for the fulfilment of the contracted tax, employment or invoicing obligations, including, where applicable, the submission of invoicing records required by the Verifactu regulations.

8.5 International transfers

Finlai prioritises the processing of personal data within the European Economic Area (EEA). If, exceptionally, an international transfer of data to a third country or international organisation were necessary, for example due to the location of a technology provider, it will only be carried out where one of the safeguards provided for in arts. 44 to 49 GDPR applies: an adequacy decision of the European Commission, the Standard Contractual Clauses (SCCs) or another valid transfer mechanism, accompanied, where necessary, by supplementary measures. You can request a copy of the safeguards applied by contacting us at privacy@finlai.es.

9. Automated decisions, profiling and Artificial Intelligence

The Platform uses Artificial Intelligence and OCR systems for the following purposes:

  • Automatic reading of invoices, receipts and documents provided by the Client.
  • Classification of income, expenses and fiscal transactions.
  • Generation of deduction suggestions, tax alerts and drafts of invoices or tax returns.

These processing operations constitute a limited form of profiling aimed at classifying the Client's economic information, but they do not give rise, unless expressly indicated otherwise, to decisions based solely on automated processing that produce legal effects or similarly significantly affect you, within the meaning of art. 22 GDPR. The readings, classifications, suggestions and drafts generated by these systems are indicative and supportive in nature, and must be reviewed and validated by the Client or, where applicable, by the advisory team, before being used, confirmed or transmitted to third parties or to the tax authorities.

Should fully automated decisions with legal effects be implemented in the future, this will be expressly communicated, together with the logic applied and the data subject's right to request human intervention, express their point of view and contest the decision.

10. How do you exercise your data protection rights?

You have the right to:

  • Access: to know which of your data we process.
  • Rectification: to request the correction of inaccurate data.
  • Erasure (“right to be forgotten”): to request the deletion of your data when, among other reasons, it is no longer necessary for the purposes for which it was collected.
  • Objection: to object to the processing of your data, especially processing based on our legitimate interest.
  • Restriction of processing: to request that we temporarily suspend the processing of your data in certain circumstances.
  • Portability: to receive your data in a structured, commonly used and machine-readable format, and to transmit it to another controller.
  • Not to be subject to automated individual decisions: not to be subject to a decision based solely on automated processing that produces legal effects concerning you, where applicable.
  • To withdraw the consent given at any time, without affecting the lawfulness of the processing carried out prior to its withdrawal.

You can exercise these rights free of charge by sending a request by e-mail to privacy@finlai.es, stating your identity, the right you are exercising and the data concerned. In order to process your request, we may ask you to prove your identity if there are reasonable doubts about it. Finlai will respond within a maximum of one (1) month from receipt of the request, extendable by two (2) additional months in complex cases, in which case the data subject will be informed within the first month.

If you consider that your rights have not been properly addressed, you have the right to lodge a complaint with the Agencia Española de Protección de Datos (Spanish Data Protection Agency) (C/ Jorge Juan, 6, 28001, Madrid; www.aepd.es), without prejudice to first contacting Finlai to resolve any issue.

11. Information security

We have adopted the technical and organisational measures necessary to guarantee the security of your personal data and prevent its alteration, loss, unauthorised processing or access, taking into account the state of the art, the nature of the data processed, including tax and financial information that is especially sensitive for the Client, and the risks to which it is exposed. Among others, we apply the following measures:

  • Encryption of data in transit (TLS) and, where appropriate, at rest.
  • Role-based access control and least-privilege principle for authorised personnel.
  • Regular backups and business continuity plans.
  • Logging and management of security incidents, with a procedure for notifying personal data breaches to the supervisory authority within 72 hours, and to the affected data subjects where there is a high risk to their rights and freedoms, in accordance with arts. 33 and 34 GDPR.
  • Periodic review of technology providers and assessment of their security level.
  • Contractual confidentiality of staff and collaborators with access to personal data.

12. Do we use cookies or tracking technologies?

Our website and Platform may use first-party and third-party cookies, as well as other tracking technologies, classified into:

  • Technical or necessary cookies: essential for the functioning and security of the session; they do not require consent.
  • Analytics cookies: to analyse the use of the Platform and generate internal statistics, on the basis of the user's consent.
  • Personalisation cookies: to adapt the user experience to their preferences.

You can manage and configure your cookie preferences from the settings panel on our website (CMP), or from your browser settings, and you can withdraw your consent at any time as easily as it was given. Non-technical cookies will be retained for the period indicated in the settings panel, and in no case beyond 24 months without renewal of consent. For more information, see our Cookie Policy available on the website and on the Platform.

13. Do we process data of minors?

Finlai's services are aimed exclusively at adults with the legal capacity to enter into contracts, acting on their own behalf or on behalf of a business, company or professional activity. Finlai does not knowingly collect data from minors. If it is detected that a minor has provided data, it will be deleted immediately, without prejudice to any additional measures that may be applicable.

14. Changes to the data controller

If the data controller, its contact details or the legal form under which the service is provided were to change, for example in the context of a corporate transaction, the affected data subjects will be informed where required under the applicable regulations, and this Policy will be updated accordingly.

15. Amendments to the Privacy Policy

We reserve the right to amend this Policy to adapt it to future legislative, case-law, technical or functional developments. In the event of significant changes, we will inform you through the Platform or by a communication to your e-mail address before they enter into force.

16. Governing law, jurisdiction and contact

This Policy is governed by Spanish and European data protection legislation. For any dispute, the parties submit to the jurisdiction of the Courts and Tribunals of Madrid, expressly waiving any other jurisdiction, without prejudice to the non-waivable rights that users hold in their capacity as consumers. For any enquiry related to this Policy, you can write to us at privacy@finlai.es.