Privacy notice
Who is responsible
CEL TECHNOLOGIES LTD, registered in England and Wales, operates Finbar. Contact inquiries@finbar.com or our registered address about privacy. This notice covers our marketing websites, enquiries, accounts, web app and related services.
We determine processing for account administration, billing, security and enquiries. For information processed on a business customer's instructions, the DPA describes our processor role. Contact that business about information it controls; we can route requests.
Information and purposes
| Information | Why we use it | Lawful basis for our controller activities |
|---|---|---|
| Name, email, login identifiers and account preferences | Authenticate users, administer accounts and provide requested services | Contract with an individual customer; legitimate interests in administering business customer accounts |
| Demo enquiries and correspondence | Respond to requests and provide support | Legitimate interests in responding to enquiries and supporting customers; contract where applicable |
| Subscription, transaction and billing identifiers | Manage payments, entitlements and accounting | Contract, legitimate interests in administering business accounts, and legal obligations for required records |
| Uploaded files, workbooks, workspace content, prompts, chat messages and tool results | Store and retrieve work, answer questions and perform requested AI tasks | Contract or legitimate interests where we act as controller; customer instructions where we act as processor |
| Request, error, device/network and usage records | Operate, secure, troubleshoot and meter the service | Legitimate interests in service reliability, abuse prevention and accurate billing |
| Optional embedded-form storage and any separately requested marketing preferences | Provide the optional form or communicate as requested | Consent where required |
| Basic website traffic statistics: homepage addresses, visits, source categories, country and connection information | Understand and improve the website | Legitimate interests in improving the website; you can opt out in Cookie settings |
| Optional marketing-website analytics and session replay: browser identifiers, page URLs, referrers, device/network information, interactions and page reconstructions | Understand acquisition, website use and usability | Consent |
Required account and payment information must be supplied for paid service; optional enquiries and permissions can be declined.
Marketing choices
Promotional emails require separate opt-in. Unsubscribe through the email link or inquiries@finbar.com. Signup, purchase, terms acceptance and demo-form use or consent do not opt you into marketing.
Necessary service, billing and security messages may continue after unsubscribing, but will not be used to bypass your marketing choice.
AI processing and recipients
Relevant prompts, document excerpts, attachments and tool results may go to an AI provider to fulfil requests. Finbar stores chat and tool-result data server-side to operate conversations.
The provider register identifies our infrastructure, authentication, payment, enquiry and AI services, their roles and locations. Processing may involve retention, logging and authorised support or security access.
Exa web-search queries may include prompts or other customer content, separately from documents sent for AI processing.
Optional Google sign-in supplies your name, email and account identifier—not your password. The Excel add-in also requests Google fonts independently of sign-in. The register explains these flows and links Google's privacy information.
We may also disclose information where required by law, to protect legal rights, or in a business transfer subject to appropriate safeguards. Business workspace administrators may have access consistent with the customer's arrangements.
Product improvement and model training
Our business terms and consumer terms permit product improvement using usage data and voluntary feedback, and model development, training or enhancement using customer content and usage data, including for third-party components. Model-training use requires prior aggregation and commercially reasonable, industry-standard de-identification efforts. Usage data may be disclosed to others only in aggregated form that does not identify customers or users.
These contractual permissions are not data-protection consent or a lawful basis by themselves. Before starting a new use of personal information for these purposes, we will provide purpose-specific privacy information, identify an appropriate lawful basis and obtain consent where required. Aggregated or de-identified information may still be personal information. Applicable objection, consent-withdrawal and deletion rights remain; see below. Processor instructions, confidentiality, retention and staff-access restrictions still apply.
Staff access to customer content
Authorised staff may access customer content only as needed for support, troubleshooting, security or legal obligations, subject to customer instructions. Staff and contractors with access are bound by written confidentiality obligations.
International processing
Processing may occur outside the UK or EEA, including the United States. The provider register describes locations and global processing; resource locations do not guarantee all processing stays in that country.
For AWS hosting, Microsoft Azure and Microsoft 365, and Stripe billing, we use the data-protection arrangements incorporated into those providers' standard service terms:
| Provider | Transfer arrangements |
|---|---|
| AWS | The AWS Data Processing Addendum and UK GDPR Addendum incorporate EU standard contractual clauses and the UK Addendum for the transfers to which those clauses apply under the terms. |
| Microsoft Azure and Microsoft 365 | Microsoft's Products and Services Data Protection Addendum applies the EU standard contractual clauses implemented by Microsoft to transfers out of the UK and EEA, with the UK Addendum for UK transfers. |
| Stripe | Stripe's Data Transfers Addendum provides for the Data Privacy Framework, including its UK extension, for covered US transfers, with EU standard contractual clauses and the UK Addendum as the alternative mechanisms under those terms. |
The clauses impose contractual safeguards; the Data Privacy Framework covers participating US organisations, not every recipient or country. Coverage depends on the transfer and provider terms. Contact us for information about applicable safeguards, including a copy where required.
Retention
We retain information for the purposes and periods below, subject to shorter retention or earlier deletion where applicable.
| Information | Retention target |
|---|---|
| Customer content requested for deletion after the service ends | Within 60 days of the request under the business terms or consumer terms, subject to earlier legal or binding instruction requirements and the residual-backup handling below |
| Other valid personal-data deletion requests | Within the applicable legal requirements; the end-of-service contractual period does not extend statutory deadlines or delay binding processor instructions |
| Residual backups of deleted content | Until overwritten or deleted through the applicable backup cycle, only where permitted by law and the data processing annex; protected and beyond ordinary use pending deletion, with deletion reapplied on restoration |
| Ordinary operational logs | Up to 90 days from the event or record creation |
| Support records | Up to 24 months after resolution |
| Inactive sales enquiries | Up to 12 months after last contact |
| Active account and workspace content | As needed to provide the active service, subject to deletion requests and applicable end-of-service obligations |
| Accounting, invoices and transaction records | Six years from the end of the last company financial year to which they relate, or longer where legally required |
| Minimal contract and subscription evidence | During the relevant contract and normally six years after it ends |
| Marketing consent evidence | While we rely on that consent, then normally up to six years after we last relied on it, only where continued retention is justified |
| Marketing suppression records | Only the identifier and preference needed to prevent renewed contact, for as long as that remains necessary |
| Privacy-request and security-incident working files | Up to 24 months after closure, with earlier removal of unnecessary sensitive evidence |
| Minimal privacy/security outcome or decision records | Where justified for accountability or legal claims, up to six years after closure |
Unpaid accounts are reviewed after 12 months without meaningful account or service activity. Closure requires at least 30 days' email warning and an opportunity to retain the account through renewed activity. Active paid accounts, necessary active-workspace participation and others' content are excluded. Earlier deletion requests and end-of-service obligations prevail, as explained in the business terms or consumer terms.
Contract and consent evidence includes only necessary identifiers, timestamps, wording and relevant notices or transactions—not whole accounts, documents or chats. Retaining evidence or opt-out records does not authorise marketing after withdrawal.
Limited legal/security holds may require different periods. We minimise records, document justification and review necessity, deleting when no longer needed unless longer retention is mandatory. Neither these targets nor controller-side evidence purposes override statutory deadlines, customer instructions or DPA deletion obligations.
Account deletion is not necessarily immediate erasure of object versions, backups or provider copies; the retention/deletion rules above apply. See privacy requests.
Your right to object
Under UK and EU data protection law, you can object to processing based on our legitimate interests on grounds relating to your particular situation. We must stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
You can object at any time to direct marketing, including related profiling, without giving a reason. We will stop that use. Unsubscribe in a marketing email or contact inquiries@finbar.com; see privacy requests for other contact instructions.
Your other choices and rights
Depending on applicable law and circumstances, you can request access, correction, erasure, restriction or portability of your information. Where we rely on consent, you can withdraw it without affecting earlier lawful processing. Use privacy requests; you do not need an active account.
You can complain to the UK Information Commissioner's Office or another competent data protection authority. You can contact us first, but do not have to do so.
Website analytics and cookies
We use Amplitude for basic traffic statistics to understand and improve this website. These count homepage visits by page address, source and country, without analytics cookies or recognising you across visits. Page addresses exclude query strings and fragments. Our hosting provider, AWS, estimates country from your IP address. Basic statistics are on by default; you can opt out in Cookie settings or choose Reject non-essential. Amplitude receives connection information, including your IP address.
With your consent, we also use detailed analytics and session replay. Detailed analytics collects browser identifiers, page addresses, referring websites, device information and interactions. Session replay records page content and interactions during consenting visits, with form inputs masked by default.
Change your choices at any time using Cookie settings in the footer. Turning off a feature stops further collection; it does not delete information already sent. These choices are separate from the enquiry form and marketing emails.
This analytics applies to the public website, not the Finbar app or Excel add-in. See our cookie policy for storage details and our service providers page for processing locations.
Changes to this notice
We will publish an updated version when this notice changes and provide additional notice when appropriate.