Privacy notice
What this covers
This notice explains what personal data the Scaleup FP&A application holds about the people who use it, where it is kept, who processes it on our behalf and how long it stays. The financial content of a planning model belongs to the client company; this notice is about the data that identifies people.
What we hold
- Account data: your name as you entered it, your email address, a hashed password, sign-in sessions and the time of your last sign-in.
- Invitations: the email address an owner invited, the role offered, when, and whether it was accepted.
- Activity: who opened, saved, shared, restored or deleted a model and when, and whether a change came from the browser or from a Claude connector. This record exists so a client can see what happened to their plan.
- People in a plan: when a client enters employees in a headcount driver, those names and salaries sit inside the client's model. The client company is the controller of that data; we process it for them.
- Technical: error reports with the page, the request and an internal user id (never your email); request counts per half hour (no identity).
Where it is kept
All of it in the EU. The application runs in Amsterdam, the database and sign-in service in Ireland, error monitoring in Germany, and transactional email leaves from an EU region.
Who processes it for us
| Provider | What | Where |
|---|---|---|
| Railway | runs the application and its logs | Amsterdam, NL |
| Supabase | database and sign-in | Ireland |
| Resend | invitation and password emails | EU |
| Sentry | error reports and uptime checks | Germany |
| Anthropic | the in-app AI assistant, only while it is used (below) | USA |
The first four are US-based companies hosting this data in the EU; their support staff may in principle reach systems from outside the EU, which is covered by their standard contractual clauses. The full list with entities is in the data processing agreement.
The AI assistant
The application has an optional assistant ("FP&A Helper"). When someone asks it a question, the parts of the model needed to answer are sent to Anthropic's API in the USA for that request. Anthropic does not use data sent through its API to train its models. The owner of a model can switch the assistant off for that model; it then disappears for everyone on it and nothing from that model is sent.
The Claude connector is different: there a person connects their own Claude account (claude.ai, the desktop or mobile app) to Scaleup FP&A with their own rights. The data that Claude reads is then processed under that person's or their company's agreement with Anthropic, not ours. Every change made that way is recorded under their name, with a restore point taken first.
How long
- Account and activity data: for the life of the client's contract, then deleted within 30 days of the client asking, after an export if they want one.
- Restore points: 30 days. Deleted models: 30 days in "Deleted customers", then removed with their restore points.
- Error reports: 90 days. Request counts: 30 days.
Your rights
You can ask us what we hold about you, have it corrected or deleted, or have a copy. Deleting an account removes its access to every model within the hour and its sign-in at once. Write to ts@copenhagenfinancepartners.com. You may also complain to the Danish Data Protection Agency (Datatilsynet).
If something goes wrong
Should a breach affect personal data in the application, the affected clients are told within 72 hours of us learning of it, with what happened and what we did.
Cookies
The application sets no tracking cookies and uses no analytics. Your sign-in session is kept in your browser's local storage so you stay signed in; signing out clears it.