This Privacy Policy explains how Finerlise collects, uses and protects personal data, and the rights you have. It should be read together with our Terms & Conditions. Capitalised terms not defined here have the meaning given in the Terms.
1.Who we are and when this policy applies
Finerlise is operated by [FULL LEGAL NAME], an individual domiciled in [CITY], Indonesia (“we”, “us”, “our”). For the personal data of Users and website visitors described in this policy, we are the data controller.
We process personal data in accordance with Indonesia’s Law No. 27 of 2022 on Personal Data Protection (“UU PDP”) and, where it applies to you, the EU General Data Protection Regulation (“GDPR”).
This policy applies to:
- Users: anyone who creates an Account, joins a Workspace or buys a Subscription Plan;
- Visitors: anyone who browses our website or contacts us;
- Respondents: anyone who views or fills in a Form. For Respondents, most processing is done on behalf of the Form owner, as explained in Article 2.
2.If you filled in a form
Forms are created and published by our customers, not by us. The person or organisation that sent you a Form is the data controller of your answers and decides why and how they are used. We act as their data processor and handle your data only on their instructions, under the Data Processing Terms in Annex 1.
When you open or fill in a Form, we process on the Form owner’s behalf:
- your answers, uploaded files and any partial drafts saved while you fill it in;
- visit information: browser and device type, the referring website and campaign (UTM) parameters, the approximate country and city derived from your IP address, and timing of pages viewed;
- a session cookie (
pf_session) that keeps your visit and draft together and prevents duplicate submissions; - if the Form requires it, your email address or the identity of your Finerlise account.
We do not store your raw IP address with your visit. To prevent abuse, we keep a one-way hash (HMAC) of your session and network address for short rate-limit windows.
To ask about, correct or delete your answers, please contact the Form owner. Their privacy notice governs your data. If you contact us instead, we will forward your request to them where we can identify them.
We also process limited technical data from Form pages for our own purposes as a controller, namely security, abuse prevention and error diagnostics (Article 4). Optional analytics apply only if you have accepted cookies on our website (Article 6).
3.Personal data we collect about Users and Visitors
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password hash, profile picture, two-factor settings, sign-in method | You, or Google / our sign-in provider when you use single sign-on |
| Onboarding & preferences | Role, use case and how you found us (optional), appearance, regional and notification settings | You |
| Workspace & collaboration data | Workspace membership and role, invitations you send or receive, Forms and Themes you create or edit | You and other Members of your Workspace |
| Billing data | Plan, billing email, country, subscription status, invoices. Card details are held only by Polar. | You and our payment provider, Polar |
| AI Feature data | Your prompts, the Form or Responses included as context, and the Output | You, when you use AI Features |
| Integration data | Connected Google or Notion account email and granted scopes, the spreadsheets or databases you choose as destinations, webhook URLs, API key metadata | You, and Google or Notion when you connect Google Sheets or Notion |
| Usage & device data | Pages and features used, clicks, errors, browser, device, approximate location, and IP address | Automatically, via our servers, analytics and error tools |
| Communications | Support emails, feedback, waitlist sign-ups, sales enquiries | You |
| Legal acceptance records | Which version of the Terms and this policy you accepted, when, and your browser | Automatically, when you agree |
You are not obliged to give us personal data, but without account data we cannot provide the Service to you.
4.How we use personal data and our legal bases
| Purpose | Legal basis |
|---|---|
| Creating and operating your Account and Workspaces, and providing the Service | Performance of our contract with you (the Terms) |
| Processing payments, invoicing and managing Subscription Plans | Performance of contract; legal obligation (tax and accounting) |
| Sending service emails: verification, invitations, billing, security and policy changes | Performance of contract |
| Providing AI Features | Performance of contract |
| Keeping the Service secure, preventing fraud, spam and abuse, and enforcing our Terms | Legitimate interests |
| Diagnosing errors and improving performance (including masked session replays, with consent) | Legitimate interests; consent for replays |
| Understanding how the product is used, using cookie-based analytics | Consent (cookie banner) |
| Measuring usage with cookieless, aggregated analytics | Legitimate interests |
| Sending occasional product updates and tips | Legitimate interests; you can opt out at any time |
| Recording your acceptance of the Terms and this policy | Legal obligation; legitimate interests |
| Complying with law and responding to lawful requests | Legal obligation |
We may create de-identified or aggregated data from the information we collect to operate and improve the Service. Such data does not identify you or any Respondent.
We do not sell personal data, use it for third-party advertising, or make decisions producing legal or similarly significant effects about you based solely on automated processing.
5.AI Features
When you use AI Features, your prompt and the relevant context (for example the current Form, or the Responses selected for analysis) are sent to OpenRouter, which routes the request to the provider of the selected AI model (such as OpenAI, Google or another host of an open-weight model).
We configure OpenRouter to use only providers that do not store prompts or train models on them. No Response data is sent to a model unless an AI Feature you use needs it to produce the result you asked for.
To debug and improve AI Features, AI requests and results may be recorded in our AI observability tools (Langfuse and PostHog) and are kept only as long as needed for that purpose.
8.International data transfers
Our main database is hosted in Singapore, and some of our providers process data in other countries, including the United States, the European Union and Japan. When personal data is transferred outside Indonesia or your country, we take the measures required by applicable law, such as relying on countries with an adequate level of protection, contractual safeguards (including standard contractual clauses where available), or your consent.
9.Retention
We keep personal data for as long as needed for the purposes described in this policy: while your Account is active, and afterwards for as long as necessary to comply with legal obligations (such as tax and accounting records), resolve disputes, prevent abuse and enforce our agreements.
After your Account is deleted, your Content is deleted as described in Article 19 of the Terms. Residual copies in backups are removed on their normal rotation cycle. Respondent data is kept for as long as the Form owner keeps it in their Workspace.
10.Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, hashed passwords and IP addresses, role-based access control within Workspaces, and restricted administrative access.
No system is completely secure, and Finerlise is currently in beta (see Clause 3.4 of the Terms). If a personal data breach affects you, we will notify you and, where required, the competent authority without undue delay and in accordance with applicable law.
11.Your rights
Depending on the law that applies to you, you have the right to:
- be informed about how your data is processed and obtain access to a copy of it;
- correct inaccurate or incomplete data (much of it you can edit directly in your settings);
- request deletion, or end processing, of your data;
- restrict or object to processing based on our legitimate interests, including direct marketing;
- receive your data in a structured, commonly used format and have it transferred to another controller;
- withdraw consent at any time, without affecting processing that took place before;
- object to decisions based solely on automated processing.
To exercise your rights, email [email protected] from the address linked to your Account. We may need to verify your identity before acting on a request, and will respond within the time required by law. Some data may be kept where we are legally required to.
If you are not satisfied with our response, you may lodge a complaint with the Indonesian personal data protection authority or, if you are in the European Economic Area or the United Kingdom, with your local data protection supervisory authority.
12.Emails from us
We send service emails that are necessary to operate your Account; you cannot opt out of these while your Account is active. We may also occasionally send product updates and tips. Every such email contains an unsubscribe link, and you can also opt out by emailing [email protected].
13.Children
The Service is not directed at children. Account holders must be at least 13 years old, and users under the age of majority need the consent of a parent or guardian (see Clause 4.1 of the Terms). If we learn that we collected a child’s data without valid consent, we will delete it. Form owners are responsible for obtaining any consent required to collect data from children through their Forms.
14.Changes to this policy
We may update this policy. For material changes, we will notify you by email or in the Service at least 14 days in advance and ask you to review and accept the new version when you next use Finerlise. The version number and date at the top of this page show when it was last changed.
15.Contact
Finerlise is operated by [FULL LEGAL NAME], [CITY], Indonesia. For any question about this policy or your personal data, contact [email protected].
Annex 1.Data Processing Terms
These Data Processing Terms (the “DPA”) form part of the Terms and apply when we process personal data on behalf of a customer (“you”), in particular Respondent data collected through your Forms.
Roles and instructions. You are the controller and we are your processor. We process personal data only on your documented instructions, which consist of the Terms, your configuration of the Service (including integrations and AI Features you use) and any further written instructions we agree to, unless the law requires otherwise, in which case we will inform you unless legally prohibited.
Scope. Subject matter: hosting and processing Forms and Responses. Duration: the term of the Agreement plus the deletion period in Clause A.8. Data subjects: Respondents and any other people whose data you upload. Data categories: whatever your Forms collect, plus visit metadata described in Article 2. Special categories may only be processed as permitted by Clause 5.2 of the Terms.
Confidentiality. Anyone we authorise to process the personal data is bound by confidentiality.
Security. We implement the measures described in Article 10, appropriate to the risk. You are responsible for configuring the Service securely, including Workspace access, Form access controls and API keys.
Subprocessors. You authorise us to use the subprocessors listed in Article 7. We impose data protection obligations on them that are no less protective than this DPA and remain responsible for them. We will update Article 7 before adding or replacing a subprocessor; if you object on reasonable data protection grounds, you may terminate the affected Subscription Plan.
Assistance. Taking into account the nature of the processing, we will reasonably assist you in responding to data subject requests, and with security, breach notification, data protection impact assessments and consultations with authorities. We will forward to you any request we receive from your Respondents.
Breaches. We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably available to help you meet your own obligations.
Deletion. You can delete and export Responses at any time. At the end of the Agreement, we delete your personal data as described in Clause 19.5 of the Terms, unless the law requires us to keep it.
Information. We will make available the information reasonably necessary to demonstrate compliance with this DPA. Given our current stage, this is provided in writing on request to [email protected].
Transfers and liability. International transfers follow Article 8. The limitations of liability in the Terms apply to this DPA.