Notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
Privacy Policy
Last updated: 16 September 2026
This page explains which personal data we collect through www.clearfin.io and while providing our financial management services, why we collect it, how we protect it and what your rights are. The principle is simple: all data we collect about our customers is used exclusively to provide the service to that customer. We do not sell it, we do not share it with third parties for commercial purposes, and we do not use it to train public artificial intelligence models.
1. Data controller
The data controller is clearfin, VAT no. 04399891201, with registered office at Via Guglielmo Marconi 45, Bologna (Italy).
For any request concerning your personal data you can write to privacy@clearfin.io or by post to the address above.
2. What data we process
2.1 Browsing data
The systems that run the website collect, in their ordinary operation, some data whose transmission is implicit in the use of the Internet: IP address, browser and device type, operating system, pages visited, time of the request and its outcome. This data is used to operate the website, check that it works correctly and keep it secure. It is kept for the time strictly necessary and is not linked to identified persons, unless needed to establish liability in the event of cyber crimes.
2.2 Data you provide through the contact form
When you fill in the "Book the call" form you give us: first name, last name, email, phone number, company name and annual revenue bracket. We use this data only to get back to you about your request and to assess together whether our service can help you. The form sends the data to an automation system we operate, which forwards it to the team.
If you book a call through Calendly (external link), the data you enter is also processed by Calendly LLC under its privacy notice.
2.3 Data processed to provide the service to customers
If you become a customer, in order to deliver the financial management service we process the data needed to build and keep up to date the financial model of your company, including:
- Electronic invoices issued and received, retrieved from the Italian Revenue Agency's exchange system (SdI) through the read-only consultation mandate you grant us;
- Bank account transactions and balances, retrieved in read-only mode through providers authorised under the PSD2 directive, subject to your authorisation, which you can revoke at any time;
- Loan and leasing schedules, ERP data, spreadsheets and other documents you choose to share with us;
- Counterparty data (your company's customers and suppliers) contained in invoices and transactions: company name, VAT number, contact details, amounts and due dates;
- Communications exchanged with your finance director via WhatsApp, email, chat or dashboard, including the content of conversations;
- Dashboard user data: name, email, role, login credentials and usage logs.
This data may concern not only you but also your staff and the contact persons of your customers and suppliers. In those cases we process their data on your behalf and only to the extent required by the service (Art. 14 GDPR).
2.4 Cookies and third-party tools
The website uses the following tools, which may set cookies or similar technologies:
| Tool | Provider | Purpose | Type |
|---|---|---|---|
Language preference (clearfin_lang) | clearfin | Remembers the language you chose in your browser (localStorage). Never transmitted to anyone. | Technical |
| Google Ads (conversion tag) | Google Ireland Ltd. | Measures the effectiveness of advertising campaigns. Privacy notice | Marketing |
| Contentsquare | Contentsquare SAS | Analyses, in aggregate form, how the website is used in order to improve it. Privacy notice | Analytics |
| Microsoft Clarity | Microsoft Corporation | Records anonymised heatmaps and session replays. Privacy notice | Analytics |
| Google Fonts | Google Ireland Ltd. | Loads the website's fonts; your browser sends your IP address to Google. | Technical |
Technical cookies do not require consent. Analytics and marketing tools are activated only with your consent, which you can withdraw at any time; you can also block them in your browser settings or through the opt-out tools provided by each vendor.
3. Why we process data and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Respond to your contact request and assess whether to start working together | Form data (2.2) | Pre-contractual steps taken at your request (Art. 6.1.b GDPR) |
| Provide the financial management service to the customer: payment schedule, cash forecast, receivables collection, margin analysis, files for banks and shareholders, answers to your questions | Service data (2.3) | Performance of the contract (Art. 6.1.b GDPR); for third-party data, legitimate interest in performing the contract with the customer (Art. 6.1.f GDPR) |
| Comply with legal, tax, accounting and anti-money-laundering obligations | Contract and billing data | Legal obligation (Art. 6.1.c GDPR) |
| Operate the website and keep it secure | Browsing data (2.1) | Legitimate interest (Art. 6.1.f GDPR) |
| Analyse website usage and measure advertising campaigns | Analytics and marketing cookies (2.4) | Consent (Art. 6.1.a GDPR) |
| Establish, exercise or defend legal claims | All data as needed | Legitimate interest (Art. 6.1.f GDPR) |
Customer data serves the customer only. The information we acquire about a customer company (invoices, bank transactions, loans, ERP data, conversations) is used exclusively to provide the service to that company. In particular, it is:
- never sold or transferred to third parties;
- never used for marketing, commercial profiling or promotional communications, whether to the customer or to third parties;
- never used to train public AI models or models shared with other customers: AI tools work on the financial model of the individual company, which remains the customer's;
- never used for purposes other than those stated without informing you first and, where required, obtaining your consent.
4. Is providing data mandatory?
Providing data in the contact form is optional, but without it we cannot get back to you. For customers, access to invoices and bank accounts is necessary to build the financial model: without this data we are unable to provide the service. Access is always read-only and you can revoke it at any time, in which case the service can no longer be kept up to date.
5. How we process and protect data
Data is processed with IT tools and, to a residual extent, on paper, with technical and organisational measures appropriate to prevent unauthorised access, loss, destruction or disclosure. In particular:
- data is stored on servers located in the European Union;
- access to the SdI and to bank accounts is read-only: we cannot issue or modify invoices, nor initiate payments;
- a customer's data is accessible only to the team members working on that company, who are bound by confidentiality obligations;
- data is transmitted over encrypted connections and protected by authentication systems.
Some analysis activities are supported by artificial intelligence tools. Relevant answers and decisions are always reviewed and signed off by a member of the team: we do not make decisions based solely on automated processing that produce legal effects on the customer (Art. 22 GDPR).
6. Who we share data with
We do not disseminate your data. Within the limits needed for the stated purposes, the following parties may have access to it, appointed as data processors under Art. 28 GDPR or acting as independent controllers:
- Hosting and cloud infrastructure providers for the website, the dashboard and the automation systems;
- Accredited intermediaries with the Italian Revenue Agency for consulting electronic invoices on the SdI;
- Account information service providers (AISP) authorised under PSD2, for retrieving bank transactions;
- Communication service providers (email, messaging, WhatsApp Business by Meta Platforms Ireland Ltd.) for the channel you choose to use;
- AI model providers, under agreements that prohibit the use of data to train their models;
- Analytics and advertising vendors listed in section 2.4, only with consent;
- Consultants and professionals (accountants, lawyers) and public authorities, where required by law.
On your instruction, we may share data or documents with parties you designate, such as your accountant or your bank, for example when preparing a credit-line application.
An up-to-date list of data processors is available on request by writing to privacy@clearfin.io.
7. Transfers outside the European Union
Customer service data is stored in the European Union. Some vendors (in particular those for website analytics, advertising, messaging and artificial intelligence) may process data in countries outside the EU, including the United States. In such cases the transfer takes place on the basis of an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for companies that adhere to it) or of the standard contractual clauses approved by the Commission, supplemented where necessary by additional measures.
8. How long we keep data
- Contact form data: up to 12 months from the last contact, if no collaboration starts;
- Customer service data: for the duration of the contract. On termination, you revoke the SdI mandate and the PSD2 authorisation, we hand over the data collected in a readable format and delete the rest within 30 days, subject to the following;
- Contract, accounting and tax data: 10 years from the end of the relationship, as required by law (Art. 2220 Italian Civil Code);
- Browsing data: normally no longer than 12 months;
- Cookies: for the durations stated by each vendor, and in any case no longer than 24 months.
Data needed to establish, exercise or defend legal claims may be kept until the dispute is settled.
9. Your rights
At any time you can exercise the rights provided by Articles 15-22 GDPR:
- access: know whether we process your data and obtain a copy;
- rectification: correct inaccurate or incomplete data;
- erasure: have your data deleted, in the cases provided by law;
- restriction: ask that data be only stored and not further processed;
- portability: receive the data you provided in a structured, commonly used format;
- objection: object to processing based on legitimate interest;
- withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise your rights write to privacy@clearfin.io. We reply within one month of the request. If you believe that the processing infringes the law, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante) or with the supervisory authority of the Member State where you reside.
10. Minors
The website and the services are intended for businesses and professionals. We do not knowingly collect data from persons under 18 years of age.
11. Changes to this notice
We may update this notice to reflect regulatory developments or changes in our services. The version in force is always the one published on this page, with the last-updated date shown at the top. In the event of material changes affecting customers, we notify them directly.