This Privacy Notice explains how Fintant Inc., a Delaware corporation with a principal office at 73-12 35th Avenue, Suite A45, Jackson Heights, NY 11372 (“Fintant,” “we,” “us,” or “our”), handles personal information through its public website, prospect and scheduling workflows, invitation-only accounting-firm portal, operations systems, communications, and related services.
Questions and privacy requests may be sent to privacy@fintant.ai.
1. Scope
This Notice applies to:
website visitors; prospects and business contacts; users invited by accounting firms; Fintant personnel and support users when they use the platform; individuals who contact support, privacy, accessibility, or security; and personal information Fintant handles for its own service administration, security, legal, and business purposes.
Accounting firms may submit financial records and other information about their end clients. For that Client Financial Data, the accounting firm generally determines the purpose and instructions, and Fintant generally acts as its processor, service provider, or subprocessor. The accounting firm’s privacy notice and the signed Master Services Agreement and Data Processing and Security Addendum govern that processing in addition to this Notice.
This Notice does not apply to a third-party site or service that operates under its own privacy notice.
2. Our privacy roles
Fintant acts in different roles depending on the activity.
When Fintant determines the purpose
Fintant is generally a controller or business for:
website and prospect inquiries; scheduling and business-development administration; portal identity, invitations, sessions, role administration, and policy acceptance; service security, misuse prevention, audit, support, and incident response; vendor governance, legal claims, insurance, and compliance; business contacts, billing contacts, and marketing choices; and de-identified operational information that Fintant is contractually permitted to create and that cannot reasonably identify an individual.
When the accounting firm determines the purpose
Fintant generally acts as a processor, service provider, or subprocessor for Client Financial Data submitted under a Client Agreement. Fintant processes that data only on documented client instructions and for approved service purposes, subject to security, confidentiality, retention, and legal obligations.
If you are an end client, employee, customer, vendor, or other individual whose information appears in records submitted by an accounting firm, direct your request first to that firm. Fintant will support the firm’s verified request and will forward a request when appropriate.
3. Personal information we handle
The categories depend on how you interact with us.
Prospect and business-contact information
name, work email, telephone number, firm, role, location, and time zone; firm size, client range, workflows, tools, operating model, reviewer, volume, bottleneck, desired result, timing, and inquiry context; consent to contact and optional marketing choice; meeting, appointment, calendar, organizer, and scheduling status; and source, correspondence, proposal, and relationship history.
Public forms are not intended for client or end-client names, financial records, tax identifiers, account numbers, credentials, payment-card data, financial statements, or source documents.
Account, organization, and identity information
name, email, organization, role, status, time zone, and membership; invitation delivery address, claim mode, acceptance, expiry, revocation, and replacement state; identity-provider user, organization, membership, session, and authentication references; verified-email, invitation, authentication-code, recovery, session, and recent-authentication state; active sessions, device or browser information, IP address, user agent, and login timestamps; and Terms and Privacy Notice version, acceptance or acknowledgement time, and related evidence.
Fintant does not need to retain identity-provider access or refresh tokens after the local session bridge is created when the approved identity workflow does not require them.
Firm, end-client entity, and work information
client-firm legal or display name, contacts, operating regions, readiness, policies, approved workflows, and service configuration; end-client entity name or code, jurisdiction, fiscal-year information, status, and firm reference; work type, period, scope, account or source coverage, deadlines, assignments, checklist, status, blockers, next actions, and changes; client-visible questions, answers, attachments, and disposition; Fintant internal notes, which are restricted from client-facing paths; deliverables, package manifests, exception summaries, quality assurance, release, client-firm decision, and approval records; and notifications, audit history, support elevation, exports, retention holds, and deletion requests.
Client Financial Data
Depending on the approved work, Client Financial Data may include:
bank and credit-card statements and transaction data; invoices, receipts, cheque images, deposit records, remittance records, and merchant reports; customer, vendor, payee, employee, and contact information contained in source records; accounting-system exports, ledgers, journals, chart-of-accounts references, payroll or tax-related records when specifically approved, and prior workpapers; file names, document categories, source identifiers, metadata, size, type, content hashes, scan results, and versions; extracted fields, normalized transactions, coding or mapping suggestions, confidence, model or workflow version, source references, control results, exceptions, corrections, and human approvals; and completed workpapers, reconciliation summaries, exception lists, and deliverables.
Financial records may contain sensitive personal information, such as financial account information, government identifiers, tax information, credentials, payroll data, or precise transaction details. Fintant limits this processing to the approved Client Agreement, Work Authorization, personnel, systems, providers, countries, and purpose.
Technical, security, and provider information
request and correlation identifiers, timestamps, route, and result state; IP address, user agent, session, authentication method, and access evidence; provider event identifiers, delivery state, safe failure code, webhook verification, and replay state; file-security provider, content hash, signature or engine version, and safe result; job status, retries, lease, worker heartbeat, operational alert, and evidence reference; privacy-safe analytics events, consent class, safe actor or object references, and allow-listed attributes; and deletion state for active data, object storage, providers, de-identification, and backup purge.
We do not intentionally place raw financial-file content, internal notes, provider secrets, reusable file URLs, credentials, or message bodies in analytics or ordinary audit records.
4. Sources of information
We receive personal information:
directly from you; from the accounting firm or organization that invites you or submits work; from authorized firm administrators and Fintant personnel; from an end client or source system when the client firm has authorized the transfer; from approved identity, email, scheduling, meeting, storage, scanning, monitoring, analytics, AI or model, and infrastructure providers; from your browser, device, and use of the service; and from public or business sources used for ordinary business development, where permitted.
5. Why we use personal information
We use personal information to:
respond to inquiries and evaluate prospective engagements; schedule meetings and administer business relationships; provision and protect invitation-only accounts; verify identity, enforce the configured authentication method, manage sessions, and prevent unauthorized access; create and manage client organizations, memberships, end-client entity records, and work; receive, validate, scan, store, version, process, and deliver authorized files and work products; perform scoped accounting-production work and provide source-linked workpapers, controls, and exceptions; support Fintant quality assurance and separate accounting-firm approval; communicate safe service, invitation, security, and workflow notifications; provide support and controlled, time-limited support access; maintain audit, security, provider, retention, deletion, and operational evidence; investigate misuse, enforce agreements, protect rights, and respond to incidents; comply with law, court orders, insurance, tax, and regulatory obligations; manage providers, subprocessors, contractors, and business continuity; improve workflows using permitted de-identified or aggregated information; and send marketing communications only where permitted and consistent with your choices.
Where a law requires a legal basis, Fintant relies as appropriate on performance of a contract, steps requested before contract, legitimate interests, legal obligations, protection of rights and security, or consent. Consent is used only when the law requires it and may be withdrawn without affecting prior lawful processing.
6. Client Financial Data and accounting-firm instructions
The accounting firm remains responsible for:
its end-client relationship and privacy notice; the authority, consent, contractual permission, and lawful basis needed to give Fintant the data; defining the approved purpose, scope, accounts, entities, periods, providers, processing countries, and reviewer; obtaining any required taxpayer consent before U.S. tax-return information is disclosed for offshore processing; accounting policies, material judgments, final review, approval, posting, filing, payment, and end-client communication; and responding to individuals’ requests as controller or business.
Fintant:
processes Client Financial Data only for documented instructions and approved purposes; does not sell it, share it for cross-context behavioral advertising, or use it to solicit the accounting firm’s end clients; does not use it to train a public or general-purpose model; restricts it to approved personnel, systems, countries, and subprocessors; maintains source, exception, review, and approval boundaries; supports verified privacy requests and incident assessment; and returns, deletes, de-identifies, or preserves it according to the Client Agreement, organization policy, legal holds, and approved retention schedule.
If an instruction appears unlawful, unauthorized, insecure, or outside scope, Fintant may pause the processing and ask the accounting firm to resolve it.
7. AI-assisted processing
Fintant may use approved commercial AI, optical character recognition, extraction, or automation services for an approved client workflow only after the provider, contract, data region, retention mode, security controls, and client authorization have passed Fintant’s release process.
When approved:
data is minimized to what the workflow needs; consumer or personal AI accounts are prohibited; provider use for general model training is prohibited unless the accounting firm expressly authorizes a different arrangement and law permits it; persistent storage features are disabled or separately approved; the provider and processing countries appear in the Subprocessor Register; model or workflow version and processing events are recorded where applicable; deterministic checks, source references, visible exceptions, and human review remain required; and an AI-assisted output does not authorize posting, filing, payment, or external communication.
The public website and test environment must not be understood as approval to process live Client Financial Data through an AI system.
8. How we disclose personal information
We disclose personal information only as needed for the purposes described above, including to:
the accounting firm and its authorized users; authorized Fintant personnel and contractors with a need to know; approved identity, email, scheduling, meeting, infrastructure, hosting, storage, scanning, monitoring, analytics, AI or model, security, support, and professional-service providers; insurers, auditors, accountants, lawyers, and advisers subject to appropriate duties; a buyer, investor, lender, successor, or transaction adviser in a financing, merger, reorganization, sale, or diligence process, subject to confidentiality and applicable law; law enforcement, regulators, courts, or other parties when required by law or necessary to protect rights and security; and another party with your direction or valid authorization.
Service providers may process only the information needed for their role and must be governed by appropriate contract and security obligations.
Fintant does not sell personal information. Fintant does not share personal information for cross-context behavioral advertising. Fintant does not use sensitive personal information to infer characteristics unrelated to providing and protecting the service.
9. Subprocessors and service providers
Before live-data launch, Fintant will maintain a Subprocessor Register identifying each approved provider’s legal entity, purpose, relevant data, processing countries or regions, transfer mechanism where applicable, and change date. The current register will be made available to client firms and through privacy@fintant.ai.
The provider categories may include:
managed identity, authentication, invitations, organization membership, and session controls; transactional email; scheduling and meeting creation; infrastructure and hosting; private object storage and backups; malware or content scanning; monitoring and incident response; product analytics, if approved; AI, OCR, or model processing, if approved; and professional and security advisers.
A provider used in development, test, or evaluation is not automatically approved for production or Client Financial Data. As of this draft date, Fintant has not approved any production subprocessor to receive live Client Financial Data. The Subprocessor Register distinguishes approved production subprocessors from systems under review.
For current prospect, website, account-administration, and security purposes, not live Client Financial Data, the operating inventory includes GoDaddy for the email tenant, Cloudflare for authoritative DNS, Outlook as a manual email client, LinkedIn for professional-source research and manually sent messages, Notion for the canonical outreach contact and suppression registers, Acuity for the intended scheduling path, WorkOS AuthKit for the implemented managed identity path, and Resend for website authentication and one-time-code email. The exact accounts, contracting entities, regions, terms, retention, access, and production approvals remain subject to the applicable provider and release evidence. Microsoft 365 is not Fintant’s user-confirmed email tenant. Cronofy is not used. A Google Workspace or Gmail account for Acuity and Google Meet is only being considered and is not selected, connected, or approved. Mailchimp and HubSpot are future-only. An n8n Notion integration identity and LinkedIn engagement-layer schema footprint exist, but direct bot access, credentials and active workflow/runtime are not verified, and n8n is not approved for outreach sending or automation.
10. Cross-border processing
Fintant is a U.S. company serving accounting firms in the United States and Canada and may use approved personnel in Bangladesh. Personal information may therefore be processed in the United States, Canada, Bangladesh, and other countries where approved providers operate, but only after the applicable country, provider, contract, access, and client-authorization gates have been satisfied.
Privacy and government-access laws differ by country. Fintant uses contractual, organizational, and technical measures intended to protect transferred data, including:
client-approved processing countries and provider restrictions; confidentiality and data-protection duties; least-privilege, named-account access; approved systems and managed security controls; provider data-processing terms and transfer mechanisms where required; monitoring, incident, return, and deletion duties; and client notice and objection procedures for material subprocessor changes.
Canadian organizations remain accountable for personal information transferred for processing and use contractual or other means to require a comparable level of protection. If European or United Kingdom transfer law applies, the applicable Client Agreement must include an approved transfer mechanism and any required assessment or supplementary measure.
11. Retention and deletion
Fintant keeps personal information only for as long as needed for the purposes described in this Notice, the Client Agreement, documented organization policy, security, legal, insurance, dispute, tax, professional, or regulatory obligations.
Retention is determined by category:
Prospect and scheduling data: while an inquiry or business relationship is active and for a documented follow-up period; then deleted or de-identified unless a legal or dispute reason requires retention. Marketing choices: until you opt out or the purpose ends, with limited suppression information retained to respect the choice. Account and organization data: while the account or client relationship is active and for the period needed for security, contract, support, legal, and audit records after closure. Client Financial Data and source files: for the period in the Client Agreement and organization policy, subject to scope completion, return or deletion instructions, legal holds, and required evidence. Deliverables, decisions, and approval records: for the contracted recordkeeping period and any period required to establish the work performed, versions, exceptions, and firm decision. Audit, security, and incident records: for the approved security or legal schedule; governed audit records may be restricted, preserved, superseded, or de-identified in a way that maintains required history and integrity. Provider records: according to the provider contract and approved schedule. Backups: protected from ordinary use and removed through a separately tracked backup-purge cycle.
A deletion request is reviewed against identity, scope, client instructions, legal holds, dependencies, security, contract, and other permitted exceptions. Fintant records active-store, object-store, provider, de-identification, and backup-purge state separately where applicable.
Fintant intends to begin verified deletion work promptly and to complete eligible active-system deletion within 30 days where operationally feasible. This is not a promise that every record or protected backup will be erased within 30 days. Fintant will respond within the timeline required by applicable law and will explain a denial, extension, restriction, or retained category where required.
12. Security
Fintant uses or is implementing administrative, technical, and physical measures designed for the sensitivity of accounting and financial information. Depending on the approved production environment, these include:
invitation-only access and verified identity; configured identity-provider authentication, session controls, and recent-authentication checks; tenant and role authorization enforced by the server; least-privilege support access and session revocation; transport encryption and encryption at rest in approved production systems; private storage, time-limited download authorization, file-type controls, content hashes, scanning, quarantine, and versioned replacement where those production controls are approved and active; cross-site request forgery protection, security headers, rate limits, bounded inputs, and strict validation; governed audit history, provider-event verification, safe logging, monitoring, and operational alerts where those production controls are approved and active; legal holds, governed deletion, backup-purge tracking, and incident response; provider due diligence, contractual safeguards, and access review; and human review before accounting-firm approval or external financial action.
Not every control is active in development or test. Private production object storage, production malware scanning, managed production identity, production monitoring, production backups, and other provider controls remain release gates until implementation and approval are evidenced. Fintant does not claim an independent certification unless it has been completed and is current. No system is completely secure, and this Notice is not a guarantee against every incident.
Report a suspected security issue to security@fintant.ai. Do not include Client Financial Data or credentials in ordinary email.
13. Your choices and privacy rights
Depending on your location and applicable law, you may have rights to:
know or access personal information; correct inaccurate information; delete eligible information; restrict or object to processing; receive portable information; withdraw consent where processing relies on consent; opt out of marketing; opt out of sale, sharing, or targeted advertising where applicable; limit certain uses of sensitive personal information where applicable; appeal a denied request where applicable; and complain to a privacy regulator.
Submit a request to privacy@fintant.ai. Fintant may need to verify identity and authority. Verification information is used only for the request. Authorized agents may be required to provide proof of authority.
We will not discriminate against you for exercising a privacy right. A request may be limited or denied when law permits, including when Fintant cannot verify it, the request concerns data Fintant processes only for a client firm, retention is legally required, security or legal claims require the record, or the request is manifestly unfounded or excessive.
For Client Financial Data, the accounting firm is usually responsible for the substantive response. Fintant will forward or assist rather than disclose data outside the firm’s authority.
14. Regional information
Canada
Canadian privacy law may provide rights of access and correction and require appropriate purpose, consent, safeguards, openness, accountability, and limits on use, disclosure, and retention. Fintant will support the client firm’s obligations for transferred information and respond to requests for information Fintant controls.
You may contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator if you are not satisfied with a response.
California and other U.S. states
If a U.S. state privacy law applies to Fintant and your information, the rights in Section 13 apply as provided by that law. Fintant does not sell personal information or share it for cross-context behavioral advertising.
Client Financial Data is generally processed for the accounting firm as a service provider or processor. The accounting firm is generally responsible for responding to end-client requests. Some financial information or regulated entities may also be subject to statutory exemptions that must be evaluated during founder legal/compliance review, with qualified licensed-counsel review obtained when the Founder Legal Review and Escalation Policy identifies a trigger.
California’s statutory damages of up to USD $750 per consumer per incident concern a limited private right of action for specified security breaches; they are not a penalty automatically imposed for every privacy-policy issue.
European Economic Area and United Kingdom
This section applies only where European or United Kingdom data-protection law applies to Fintant’s processing. In addition to the rights in Section 13, you may complain to the competent supervisory authority.
Fintant and the client firm will identify the controller, processor, legal basis, transfer mechanism, retention criteria, and required contact or representative in the applicable Client Agreement or supplemental notice. Mere accessibility of the website does not by itself determine territorial scope. Fintant will not publish a European or United Kingdom representative or Data Protection Officer claim unless founder legal/compliance review establishes the requirement, qualified licensed-counsel review is obtained when the Founder Legal Review and Escalation Policy identifies a trigger, and the appointment actually exists.
15. Cookies and similar technologies
The service uses essential cookies and browser storage for authenticated sessions, authorization state, cross-site request forgery protection, and reliable operation. Disabling essential storage may prevent portal access.
Optional analytics, advertising, or marketing technologies will remain disabled until approved and implemented with legally required notice and choice. The current service does not require third-party advertising cookies. The Cookie Notice contains the current first-party inventory, purposes, and durations.
If Fintant later uses technology subject to opt-out signals such as Global Privacy Control, it will implement and describe the required signal handling before activation.
16. Marketing communications
Prospect and operational contact are separate from optional marketing. You may opt out of marketing at any time by using the message instructions or contacting privacy@fintant.ai.
Fintant may still send non-marketing messages needed for an account, invitation, security event, service status, legal notice, or active business relationship.
17. Children
The website and portal are intended for business users who are at least 18 years old. Fintant does not knowingly offer the service to children or knowingly collect children’s personal information through the service. Contact privacy@fintant.ai if you believe a child submitted information.
18. Changes to this Notice
Fintant may update this Notice when its services, providers, laws, or practices change. The Notice will identify its effective date and prior material versions will be archived.
Material changes will receive notice appropriate to their effect. A Privacy Notice update is not treated as consent when the law requires a separate affirmative choice.
19. Contact
Privacy requests and questions: privacy@fintant.ai General support: support@fintant.ai Security reports: security@fintant.ai Accessibility support: support@fintant.ai, with “Accessibility” in the subject line Mail: Fintant Inc., 73-12 35th Avenue, Suite A45, Jackson Heights, NY 11372