Privacy Policy
Last Updated: 18 May 2026
1. Introduction
Fintech Solutions (“we”, “us”) operates ReceivableIQ. This Privacy Policy explains what personal data we collect, how we use it, and the rights you have.
We comply with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), the Kingdom of Saudi Arabia Personal Data Protection Law, the EU General Data Protection Regulation (GDPR) where applicable, and applicable Pakistan data protection law.
Contact: legal@receivable-iq.com.
2. Information We Collect
Account information
- Name, email address, organisation, country
- Password (encrypted at rest; we never see plain-text passwords)
- Subscription plan
Customer data
- Debtor company names, countries, industries
- Invoice amounts, invoice dates, payment status
- Aging data and credit limits
- Contact names at debtor organisations
Data excluded from AI processing
The following fields are never sent to AI providers:
- Email addresses and phone numbers
- Free-text notes
- Uploaded documents
- Personal identifiers beyond what is strictly necessary
Usage data
- Login timestamps
- Features used
- Browser type and IP address
- Error and diagnostic logs
AI audit data
- Feature used, AI model version, prompt hash (not prompt text), timestamp
3. How We Use Your Information
| Purpose | Legal basis |
|---|---|
| Providing the Service | Contract performance |
| Billing and payments | Contract performance |
| Security monitoring | Legitimate interest |
| Improving the platform | Legitimate interest |
| Legal compliance | Legal obligation |
| AI audit logging | Legitimate interest |
| Support requests | Contract performance |
We do not sell your data. We do not use your data to train AI models.
4. Data Sharing
We use the following sub-processors:
| Sub-processor | Purpose | Region | Safeguards |
|---|---|---|---|
| Supabase / AWS | Database | Japan | SOC 2 Type II |
| Vercel | Hosting | Global | SOC 2 Type II |
| Anthropic | AI processing | USA | No training on customer data |
| Railway | OSINT worker | USA | Infrastructure |
| OpenCorporates | Registry lookups | UK | Public data only |
| Cloudflare | Security / DNS | Global | SOC 2 Type II |
We will disclose data only where required by law. We do not sell your data to anyone.
5. Data Storage and Security
- Data is stored on AWS in Japan (
ap-northeast-1). - GCC data residency is available on request for enterprise customers.
- TLS 1.2+ in transit. AES-256 at rest.
- Row-level security enforces tenant isolation at the database level.
- We will notify affected customers within 72 hours of discovering a personal data breach.
- Security contact: legal@receivable-iq.com.
6. Data Retention
| Category | Retention |
|---|---|
| Account information | Subscription + 30 days |
| Customer data | Subscription + 30 days |
| AI reports | Subscription + 30 days |
| AI audit logs | 7 years |
| Usage logs | 12 months |
| Billing records | 7 years |
| OSINT cache | 7 days |
7. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion
- Request a portable copy
- Object to processing
If you are in the EU / UK (GDPR)
- Restrict processing
- Not be subject to fully automated decisions
- Lodge a complaint with your supervisory authority
If you are in the UAE (PDPL)
- Be informed about processing
- Access, correction, and destruction
If you are in Saudi Arabia (PDPL)
- Know what is collected, access, correct, destruct
Submit requests to legal@receivable-iq.com. We respond within 30 days.
8. AI Governance
- Administrators can disable AI features per organisation at any time.
- We do not make automated decisions about you. All AI output is advisory only.
- The AI model version is logged for every AI call.
- Historical reports remain unchanged when AI models are updated.
9. Changes to this Policy
We will give at least 14 days' notice by email before any material change. Continued use of the Service after the effective date constitutes acceptance.
10. Contact
Fintech Solutions
206-D, Sector D, DHA Phase 1, Lahore Cantonement, Pakistan
legal@receivable-iq.com
Effective Date: 18 May 2026