Privacy notice
Draft. The legal entity that operates FluxionIQ, and its contact details, will be named here before launch. Until then this page describes, accurately, what the software does with data, but it is not yet a complete notice under Article 13 GDPR.
Who is responsible
Operator (controller for account data; processor for the documents customers upload): to be confirmed before launch.
What we process
| Data | Why | Kept |
|---|---|---|
| Your name, email address, a hash of your password, sign-in sessions (IP address and browser identifier) | To give you an account and keep it secure | While the account exists; sessions expire after 7 days |
| Documents you upload, the data read from them, your corrections and decisions | To provide the service to your organisation | Until your organisation deletes them or erases the organisation |
| Bank statement lines you import | To match payments to documents | As above |
| Audit log of actions (who did what, when) | So your organisation can prove what happened | As above |
| Server logs (errors, request identifiers) | To run and fix the service | Rotated by the server's log policy |
There are no analytics, advertising or tracking cookies. The only cookie is the sign-in session cookie.
Where it is processed, and by whom
| Provider | Role | Location |
|---|---|---|
| Alibaba Cloud | Hosting: the server, the database and its backups | Frankfurt, Germany (region eu-central-1) |
| Mistral AI (France) | Reading uploaded documents with its OCR / Document AI and language models | Mistral's European API endpoint (api.mistral.ai). Mistral states: "By default, your data is hosted in the European Union." |
| Resend | Sending account emails (password reset, invitations) | Resend's European sending region (Ireland). Receives the recipient address and the email text only. |
What Mistral says about the documents it reads
- Location: by default, data sent to Mistral's API is hosted in the European Union. Mistral also states that, depending on the features used, data may be temporarily transferred outside the EU to the sub-processors listed in its Trust Center, under safeguards complying with Article 46 GDPR. FluxionIQ uses only Mistral's European endpoint, never its US endpoint, and the service refuses to start if configured otherwise.
- Retention: Mistral keeps API inputs and outputs for as long as needed to produce the answer and then for 30 rolling days to monitor abuse, unless zero data retention has been granted for the account. FluxionIQ has not yet been granted zero data retention; this page will say so when it has.
- Training: Mistral's terms allow API customers to opt out of their inputs and outputs being used to improve Mistral's models. This page will confirm when that opt-out is in place for FluxionIQ's account; until then, assume it is not.
There is no hosting in the Gulf (GCC) region at present, and FluxionIQ makes no GCC data-residency claim.
Backups
The database is backed up nightly to the same server. Backups are kept for 14 days and then deleted automatically, so data you erase remains in backups for up to 14 days.
Your rights
You can ask for access to, correction of, or deletion of your personal data, and you may complain to a data protection authority. An organisation's owner can erase all of the organisation's data in Settings at any time. Contact details for requests will be published here before launch.