Security
Protecting your financial data
Financial data needs clear access rules and responsible processing. Explore how data is protected and how AI supports analysis. Before contracting, ask for documentation applicable to your service.
The measures behind data protection
Technical controls and operating procedures work together. Their scope is assessed for the contracted service and environment.
Your data rights
Access, export and deletion requests are handled through our contact channel. Scope depends on the request, your role and applicable obligations.
Client-scoped access
The application architecture uses user permissions and database access rules to separate client data.
Storage and processing
Website contact enquiries are stored in Cloudflare D1 in the EU. Application documentation identifies database storage in Frankfurt; AI processing uses separate providers and locations.
Audit records
Recorded activities help trace changes. Audit records have separate access and retention rules; coverage varies between processes.
Encryption and service access
The website uses HTTPS. Service keys are restricted to server infrastructure. Storage protection depends on the service and its configuration.
User roles
Access is managed through user roles and permissions. Application documentation describes access controls and two-factor authentication.
Providers and processing locations
The website and application have different data flows. An EU database location does not establish that email delivery, support or AI processing takes place exclusively in the EU.
Cloudflare · website
Hosting, abuse prevention and Cloudflare D1 storage for website enquiries. The database currently runs in the European EEUR region; a mandatory EU jurisdiction is not configured. Edge and security processing are separate from the database location.
Resend · website
Delivery of internal contact enquiry notifications to FynTwin, newsletter confirmations and offer-related messages. Delivery processing and subprocessors are not represented here as exclusively EU-based.
Plausible · public website
Public-page statistics when enabled. No first-party analytics cookies; private pages, tokens, query strings and form contents are excluded from events.
Supabase / AWS · application
Documented application storage, authentication and files in Frankfurt, EU. This is separate from the website contact-enquiry database.
OpenAI · AI analysis
AI responses generated from limited context. The latest reviewed documentation identifies US processing and a request for EU processing; approval of EU processing and ZDR has not been confirmed for this publication.
Cohere / Oracle Cloud · knowledge base
Cohere supports retrieval of professional material; its processing region is unconfirmed. The documented Oracle Cloud vector-index location is Frankfurt, EU.
Documentation records an accepted OpenAI DPA dated 28 August 2026. This does not establish that all provider contracts are executed or that EU AI processing is active. Request current processing terms and the subprocessor list for your specific relationship.
AI supports analysis; professional judgement remains yours
AI responses may be inaccurate or incomplete. Check conclusions, sources and the applicability of standards. Filtering reduces the transmission of structured identifiers; free text can still contain personal data. Setting store:false does not establish provider approval for ZDR.
Questions before contracting
Content reviewed: 27 September 2026.
Discuss your requirements
Request a demonstration and documentation for your security assessment before using the service.