Last update: February 4, 2026.
This Privacy Policy describes how Sors Financial Hub (hereinafter "the Service") collects, uses, and protects user personal data, as well as your rights under the GDPR and applicable legislation.
1. Data Controller and Contact
The Data Controller for data submitted through the Service is the entity operating and providing Sors Financial Hub. For requests regarding data, rights, or security, you can contact the privacy email displayed within the Service or on its corporate page.
2. What data we collect
The Service may process the following categories of data:
- Account and Identification Data: Name, email, phone, user role, company, access credentials, action history.
- Usage Data: Logins, actions within the application, pages viewed, usage time, errors, and logs.
- Technical Data: IP, device type, OS, browser, device identifiers, cookies or similar technologies.
- Financial and Operational Data: Data you input or connect to the Service, such as transactions, categories, KPIs, reports, goals, production data, or other financial metrics. These may include personal data depending on the content you upload or synchronize.
- Support Data: Communications with support, requests, attachments, screenshots, recordings for troubleshooting.
3. How we use data
- Provision and Operation of the Service: Account creation, access, roles, dashboards, reports, calculation and display functions.
- Security and Fraud Prevention: Access controls, monitoring, malicious use detection, auditing, backup, and recovery.
- Product Improvement: Usage analysis, debugging, performance monitoring, testing, user experience improvement.
- Customer Support: Request management, communication, technical issue resolution, usage guidance.
- Legal Obligations: Record keeping when required by law, compliance with authority requests.
4. Legal Bases for Processing
- Contract Performance: When processing is necessary to provide the Service.
- Legitimate Interest: For security, abuse prevention, service improvement, and statistical analysis.
- Consent: For optional cookies or optional features where explicitly requested.
- Legal Obligation: When required by law or regulation.
5. Cookies and Similar Technologies
We use cookies or similar technologies for:
- Essential Cookies: Login, session, security, basic operation.
- Functional and Analytical: Experience improvement, usage statistics, performance.
You can manage cookies from your browser settings or the consent mechanism, if provided within the Service.
6. Disclosures and Data Recipients
We do not sell data. We may share data with:
- Service Providers: Hosting, monitoring, email delivery, analytics, customer support tooling, only to the extent necessary for the Service operation.
- Intra-group or Collaborative Service Provision: When operation involves companies within the same ecosystem or authorized partners, under appropriate contracts.
- Legal Authorities: When required by law or valid request.
7. Transfers Outside EEA
If providers outside the European Economic Area are used, appropriate safeguards are applied, such as Standard Contractual Clauses or equivalent measures, ensuring an adequate level of protection.
8. Data Security
We implement technical and organizational measures for data protection, such as:
- Access control with roles and permissions.
- Encryption during transfer, and where applicable, at rest.
- Logging and auditing of actions.
- Backups and recovery procedures.
- Access restriction to personnel with a need to know.
No system is absolutely secure, but the approach is risk-based and continuously improved.
9. Retention Period
We retain data for as long as:
- It is necessary for the provision of the Service.
- Required for legal compliance.
- Needed for dispute resolution or agreement enforcement.
Afterwards, data is deleted or anonymized according to retention policies.
10. User Rights
You have the right to:
- Access your data.
- Correct inaccurate data.
- Delete under conditions.
- Restrict processing.
- Portability where applicable.
- Object to processing based on legitimate interest.
- Withdraw consent where the basis is consent.
Requests are submitted through the communication channel mentioned in section 1.
11. Third-Party Data and Customer Responsibility
If you upload or synchronize data involving third-party personal data, you are responsible for having a legal basis and fulfilling your obligations as a data controller, where applicable. The Service acts as a data processor for data uploaded by the customer, when provided by contract.
12. Minors
The Service is not addressed to minors and is not intended for use by persons under 18 years of age.
13. Changes to Policy
We may update this policy. The new version is published within the Service or on the website and the update date changes accordingly.
14. Complaint Submission
You can submit a complaint to the competent data protection supervisory authority of your country, if you consider that the processing violates the legislation.