MazeCFO

Legal

Privacy policy

What we collect, why, how long we keep it, and what you can require of us.

Draft pending legal review. This document describes how the platform actually operates, but it has not been reviewed by qualified counsel and is not yet a binding agreement. It must not be relied upon until this notice is removed.

1Two kinds of data

Account data is what we collect to run the service: your email address, a hash of your password, session records with IP address and browser identifier, and audit entries recording actions taken in your workspace.

Customer data is what you upload: ledgers, statements, documents, and anything derived from them. We are a processor for this data. You determine what it contains and why.

2What we collect and why

Email address — to identify your account and send verification, reset, and notification messages. Password hash — to authenticate you; the password itself is never stored. IP address and browser identifier — to show you your active sessions, to rate-limit sign-in attempts, and to record security events. Usage records — to meter plan limits and AI spend.

We do not use tracking or advertising cookies, and we do not sell personal data.

3AI processing

When you ask the assistant a question, the question and the specific excerpts retrieved to answer it are sent to our AI provider. Only the excerpts relevant to that question are sent — not your database, and never another customer's data.

Your financial data is not used to train models.

4Where data is held

Application data is stored in the deployment region for your account. Backups are encrypted before leaving the host and stored with a separate provider. Sub-processors are limited to hosting, the AI provider, email delivery, and payment processing; the current list is available on request.

5Retention

Customer data is retained while your account is active and for a defined window after termination so you can export it. Audit logs are retained for the configured period, which may exceed the customer-data window because they are the record of who did what.

Backups age out on their own schedule. A deletion request is applied to live data immediately and recorded, so that if a backup is ever restored the deletion is re-applied rather than the data reappearing.

6Your rights

Where GDPR or comparable law applies, you may request access, correction, erasure, restriction, portability, or object to processing. Export is available directly in the product; other requests go through the contact page and are answered within one month.

Where we act as a processor for customer data, requests from your end users should be directed to you as controller, and we will assist.

7Security

Tenant data is isolated by database-enforced row-level security. Passwords are hashed with Argon2id. Session and reset tokens are stored only as hashes. Sensitive fields, including integration credentials, are encrypted at rest. Details are on the security page, which also states plainly what we do not claim.

8Breach notification

If a breach affects your personal data, we will notify you without undue delay with what we know, what we are doing, and what you should do.

9Changes and contact

Material changes will be notified before they take effect. Questions or requests: contact us.