This policy explains how Finflo collects, uses, stores, and protects your personal information when you use our document processing service.
Last updated: February 2026
Finflo ("we", "our", or "us") operates the Finflo document processing platform available at app.finflo.au (the "Service"). This Privacy Policy describes how we collect, use, and share information about you when you use our Service.
By using Finflo, you agree to the collection and use of information in accordance with this policy.
When you use our Service, we automatically collect certain information:
The documents you upload may contain personal information about third parties (such as customer data, employee records, or financial information). You are responsible for ensuring you have the right to upload such documents and that doing so complies with applicable privacy laws.
We use the information we collect to:
We share your information only in the following circumstances:
We use trusted third-party service providers to operate our Service. These providers only have access to the information necessary to perform their specific functions and are contractually obligated to protect your data.
| Provider | Purpose | Data Shared |
|---|---|---|
| Northflank | Application hosting, database & cache (Australia) | All application data |
| Google Cloud | File storage (Australia) & AI processing | Uploaded documents, extracted data |
| Cloudflare | DNS, DDoS protection & Web Application Firewall | Network traffic metadata, IP addresses |
| Sentry | Error monitoring & performance tracking | Error logs, performance data (no document content) |
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency), including to:
If your information needs to be shared for any other reasons, we will reach out for your explicit consent before complying with the request.
We take the security of your data seriously and implement appropriate technical and organisational measures to protect it.
For more details about our security practices, please see our Security page.
We take the protection of your data seriously and follow industry-standard practices to safeguard it. All core infrastructure is hosted in Australia for data sovereignty compliance. While no online service can guarantee absolute security, we are committed to transparency and will promptly notify affected users if a security incident were ever to occur.
We follow a data minimisation approach, retaining your information only for as long as necessary to provide our Service. Document data is subject to automated deletion to reduce the window of exposure for sensitive information.
| Data Type | Retention Period |
|---|---|
| Uploaded PDF documents | Automatically deleted every 7 days |
| Extraction output files | Automatically deleted every 7 days |
| Extraction JSON data | Automatically deleted every 7 days |
| Account information | Until you delete your account |
| Templates | Until you delete them or your account |
| Deletion audit logs | Retained for compliance purposes |
| Server logs | 30 days |
| Database backups | 7 days (rolling) |
A scheduled background process runs every 7 days to permanently delete uploaded PDF files, extraction output files from cloud storage, and extraction JSON data from our database. An audit log of all deletion events is maintained for compliance and accountability. This approach follows the data minimisation principle recommended by the Australian Privacy Act and GDPR.
When you delete data or your account, we will remove your information from our active systems. Some information may persist in backups for a limited period before being permanently deleted.
Depending on your location, you may have certain rights regarding your personal information. We are committed to honouring these rights for all users.
You can request a copy of the personal information we hold about you.
You can request that we correct any inaccurate or incomplete personal information.
Document data is automatically deleted every 7 days. You can also manually delete templates and extraction data at any time. To delete your entire account and all associated data, contact us at finflo-support@finflo.au.
You can export your extraction results to Excel format directly from the application. For a complete export of all your data, contact us.
You can opt out of marketing communications at any time by clicking the unsubscribe link in any email or by contacting us.
If you believe we have not handled your information correctly, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or your local data protection authority.
To exercise any of these rights, please contact us at privacy@finflo.au. We will respond to your request within 30 days. We may need to verify your identity before processing certain requests.
Finflo is based in Australia. All core infrastructure — including application servers, databases, caches, and file storage — is hosted in Australian data centres to ensure data residency compliance.
Some ancillary services (such as Cloudflare for network edge protection and Sentry for error monitoring) may process limited metadata outside of Australia. No document content or extracted data is stored outside Australian infrastructure.
If you are accessing our Service from outside Australia, please be aware that your information may be transferred to, stored, and processed in Australia, which may have different data protection laws than your country of residence.
When we transfer data internationally, we rely on:
Finflo is not intended for use by children under the age of 18. We do not knowingly collect personal information from children under 18.
If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible. If you believe we may have information from or about a child under 18, please contact us at privacy@finflo.au.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make changes:
Your continued use of the Service after any changes indicates your acceptance of the updated policy.
If you have questions about this Privacy Policy, your data, or your rights, please contact us: