Legal

Studio Privacy Notice

EffectiveSeptember 2026

This Studio Privacy Notice describes how FinCatch Limited (“FinCatch”, “we”, “us”) collects, uses, stores, shares, and protects personal data and proprietary research inside FinCatch Studio (the “Service”). It applies to all authorized users and institutional clients accessing the Service under a paid or trial subscription.

1.

Categories of Data Collected

  1. 1.1Account Information: Name, professional email address, organization name, billing details, and hashed authentication credentials (passwords are cryptographically salted and hashed; cleartext passwords are never stored).
  2. 1.2User Data (Proprietary Research & Files): All materials uploaded or submitted to the private Library, Agent Memory, or custom Skills, including PDF financial disclosures, internal research memos, spreadsheets (.xlsx), presentation slides, transcripts, investment theses, and portfolio lists.
  3. 1.3Model-Interaction & Audit Logs: Prompts submitted to the agent, agent-generated responses, tool-call execution metadata (file reads, graph traversals, spreadsheet computations, verification results), and timestamps. These logs are maintained strictly to support the auditability and cross-check features described in Section 16 of the Terms.
  4. 1.4Telemetry & Usage Data: Feature utilization frequency, query response latencies, error reports, and interface performance metrics.
  5. 1.5Support Inquiries: Direct communications submitted to team@fincatch.io from within Studio.
2.

Purposes of Processing & Zero Model Training Guarantee

We process data strictly to: (a) provide and operate the Service, execute agentic research workflows, and preserve tenant-scoped state across sessions; (b) generate auditable citation trails and mathematical verification logs; (c) enforce role-based access security and detect unauthorized account activity; (d) manage billing, account provisioning, and customer support; and (e) comply with legal, tax, and regulatory obligations.

Contractual Zero Model Training Guarantee: FinCatch contractually guarantees that User Data, uploaded private Library files, Agent Memory notes, model-interaction logs, and User Outputs are NEVER used to train, fine-tune, or improve any public, shared, or third-party artificial intelligence foundation models. Your proprietary research remains strictly tenant-isolated.

3.

Legal Bases for Processing (Under GDPR / UK GDPR / HK PDPO)

  1. 3.1Contractual Necessity: Processing account information, User Data, and model interaction logs is necessary to deliver the Service agreed upon under the Terms.
  2. 3.2Legitimate Interests: Processing aggregated usage telemetry and security logs to protect infrastructure integrity, prevent unauthorized access, and optimize system uptime.
  3. 3.3Legal Obligation: Maintaining financial and transaction records to satisfy Hong Kong statutory accounting, corporate, and tax laws.
4.

Third-Party Disclosure & Sub-Processors

FinCatch shares data with authorized sub-processors solely to the extent required to deliver the Service. These include cloud infrastructure hosts, compute/GPU providers, artificial intelligence foundation model API providers, and system telemetry monitors. FinCatch does not sell personal data or proprietary research, and does not share user information with advertisers or data brokers.

5.

Data Retention & Deletion Schedules

  1. 5.1Account Data: Retained for the active duration of the subscription plus thirty (30) days following account closure, after which it is permanently deleted.
  2. 5.2User Data (Library & Agent Memory): Retained during active subscription custody. When a user deletes a file, a thirty (30) day recovery grace period applies, after which the data is permanently purged from active and backup storage.
  3. 5.3Model-Interaction Logs: Retained for the active life of the account plus thirty (30) days to support institutional audit and compliance inspection, then permanently deleted.
  4. 5.4Aggregated Telemetry: Retained indefinitely in de-identified, non-personal form for infrastructure benchmarking.
6.

User Rights

Users possess statutory rights under Hong Kong PDPO, GDPR, and equivalent data protection regulations, including the right to: (a) request access to personal data held by FinCatch; (b) request correction of inaccurate data; (c) request permanent erasure of personal data; (d) export all User Data and Outputs in portable JSON and native document formats; (e) object to or restrict specific processing operations; and (f) lodge a complaint with the Hong Kong Privacy Commissioner for Personal Data (PCPD) or relevant supervisory authority. Requests should be submitted to team@fincatch.io.

7.

International Data Transfers

FinCatch is headquartered in Hong Kong and utilizes geographically distributed cloud and compute infrastructure. Cross-border transfers of personal data are conducted under recognized lawful transfer mechanisms, including European Commission Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and Hong Kong PCPD model clauses.

8.

Technical & Organizational Security Measures

  1. 8.1Encryption: All data is encrypted in transit using modern TLS (TLS 1.3) and at rest using AES-256 encryption.
  2. 8.2Tenant Isolation: Logical and architectural separation guarantees that one client organization cannot access or query another client’s private Library or Agent Memory.
  3. 8.3Access Control: Multi-factor authentication (2FA), role-based permissions, and immutable system audit logging.
  4. 8.4Incident Notification: FinCatch will notify affected clients of any confirmed security breach involving personal data without undue delay, and within seventy-two (72) hours of becoming aware of the incident where required by law.
9.

Sub-Processor Management

FinCatch engages sub-processors across four functional infrastructure categories: (1) cloud hosting, storage, and GPU compute; (2) artificial intelligence foundation model API providers; (3) transactional messaging and support tools; and (4) infrastructure telemetry and error monitoring. An authoritative, dynamically updated roster of named sub-processors is published at studio.fincatch.io/privacy/subprocessors. FinCatch provides at least thirty (30) days’ advance notice before onboarding new sub-processors that handle User Data.

10.

Contact & Data Protection Officer

Inquiries, privacy requests, or regulatory communications should be directed to FinCatch’s Data Protection Officer at team@fincatch.io (Attn: Data Protection Officer). Operated by FinCatch Limited, Hong Kong.