Legal
Privacy Notice
SFDR AI is the data controller for personal data processed through SFDR AI. This notice explains what we collect, why, and what rights you have.
Last updated: 11 August 2026
1. Controller and contact
SFDR AI, trading as SFDR AI, decides how and why your personal data is processed and is therefore the controller. For any privacy question or request, contact max.martikainen2@gmail.com.
2. What we collect and why
- Account data — name, email address and Google account identifier used to sign in. Purpose: creating and securing your account. Legal basis: performance of our contract with you.
- Service content — portfolios, holdings, uploaded CSV files, company and fund names, document URLs and questions you ask about documents. Purpose: providing the reporting service. Legal basis: contract.
- Usage and billing records — credit consumption, job and scan history, timestamps. Purpose: metering, invoicing accuracy and support. Legal basis: contract and legal obligation.
- Technical data — IP address, device and browser information, log and error data. Purpose: security, fraud and abuse prevention, and keeping the service reliable. Legal basis: legitimate interests.
- Support messages — the content of emails you send us. Purpose: answering you. Legal basis: legitimate interests.
- Marketing emails — only if you opt in. Legal basis: consent, withdrawable at any time.
We do not use your uploaded portfolio content to train our own models. Prompts and document extracts are sent to our AI providers only to produce your results.
3. Who we share data with
- Service providers — cloud hosting and database, authentication, AI model providers, web search and document retrieval providers, and market-data providers, acting on our instructions.
- Paddle, our Merchant of Record, for the sale of the product, subscription management, payments, tax compliance and invoicing. Paddle handles payment data under its own privacy notice.
- Professional advisers — legal and accounting, where necessary.
- Authorities — where we are required to disclose by law.
We do not sell personal data.
4. International transfers
Some providers process data outside the EEA/UK. Where that happens we rely on an adequacy decision or on Standard Contractual Clauses together with appropriate technical safeguards.
5. Retention
Account and portfolio data is kept while your account is active and for up to 12 months after closure, so you can reactivate; billing and tax records are kept for the period required by law (typically 6–7 years); technical logs are kept for up to 12 months. After that, data is deleted or anonymised.
6. Your rights
You have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent where processing is based on consent. Email max.martikainen2@gmail.com and we will respond within one month. You may also complain to your local data protection supervisory authority.
7. Security
We apply appropriate technical and organisational measures, including encryption in transit, access controls, row-level authorisation on stored data and least privilege for administrative access. No system is perfectly secure, but we work to protect your data and to notify you where required if something goes wrong.
8. Cookies and local storage
We use strictly necessary cookies and browser storage to keep you signed in, to remember your theme preference and to resume long-running scans. These are required for the service to work. If we later add analytics or marketing cookies, we will ask for your consent first and provide a way to change your preferences. You can also clear cookies in your browser settings.
9. Changes
We may update this notice; the current version is always published here with the date it was last updated.
