Last updated: 6 September 2026

Privacy Policy

This Privacy Policy explains how Dori Finance collects, uses, stores, shares and protects personal data when you visit our website at dorifinance.com (“Website”), create an account or use our application at app.dorifinance.com (“Platform”), or otherwise interact with us.

Dori Finance is a business-to-business service. Our customers are companies and the people who act on their behalf. We process two broad categories of data, and our role is different for each. Section 3 explains this in detail.

1. Who we are

Dori Finance is the trading name of:

Leancfo, Unipessoal Lda is the data controller for the data described in Section 3.1 and the data processor for the data described in Section 3.2.

2. Data protection contact

We are not required to appoint a Data Protection Officer under Article 37 of the GDPR and have not done so. All privacy questions, requests to exercise your rights, and complaints are handled by our privacy team. Write to us at hello@dorifinance.com or by post at the address above.

3. Our role: controller and processor

3.1 Data for which we are the controller

We decide how and why the following data is processed, and we are the controller for it under the GDPR:

3.2 Data for which we are the processor

When your company connects a bank account or uploads invoices, receipts and other financial documents, that content may contain personal data about your company’s customers, suppliers, employees and other third parties. Examples are names, tax numbers, bank account numbers, and transaction descriptions.

Your company is the controller of that data. Dori Finance processes it only on your company’s instructions, as set out in our Terms and Conditions and, where applicable, a data processing agreement. If you are a third party whose data appears in a customer’s records, please direct requests to that company. We will assist them in responding.

4. What we collect and where it comes from

CategoryExamplesSource
Account dataName, work email, role, companyYou, when you sign up or are invited
Financial dataSales, expenses, bank transactions, invoices, receiptsYour company, through uploads and bank connections
Bank connection dataAccount holder name, IBAN, balances, transaction historyYour bank, through GoCardless Bank Account Data, after you authorise access
Billing dataCompany details, plan, invoicesYou and Stripe
Usage dataFeature use, clicks, session lengthCollected automatically inside the Platform
Technical dataIP address, browser, device, error reportsCollected automatically by our servers and error monitoring
CommunicationsEmails, support messages, form submissionsYou

We do not collect special categories of personal data (such as health or biometric data) and we ask that you do not upload documents containing them.

PurposeData usedLegal basis (GDPR Article 6)
Create and manage your account, provide the PlatformAccount data, financial data, bank connection dataPerformance of a contract (Art. 6(1)(b))
Extract, categorise and reconcile financial documents using AIFinancial dataPerformance of a contract (Art. 6(1)(b))
Send transactional emails (verification, invitations, alerts)Account dataPerformance of a contract (Art. 6(1)(b))
Bill you and keep accounting recordsBilling dataContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Keep the Platform secure, prevent fraud and abuseTechnical data, usage dataLegitimate interest (Art. 6(1)(f)) in protecting our service and customers
Diagnose errors and improve the productTechnical data, usage dataLegitimate interest (Art. 6(1)(f)) in a reliable product; analytics cookies only with consent (Art. 6(1)(a))
Respond to your questions and support requestsCommunicationsContract (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f))
Send newsletters and marketingEmail addressConsent (Art. 6(1)(a)), which you can withdraw at any time
Comply with tax, accounting and other lawsBilling data, account dataLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interest, we have assessed that our interest does not override your rights. You can ask for a copy of that assessment.

Providing account and billing data is a contractual requirement. Without it we cannot create your account or provide the service. Providing marketing consent is optional and does not affect the service.

6. Artificial intelligence and automated processing

The Platform uses AI models to read documents, suggest categories, and propose reconciliation matches. To do this, we send document content and transaction data to the AI providers listed in our Subprocessors page. Under our agreements with those providers, your data is not used to train or improve their models, and we do not use it to train models of our own.

All AI outputs are suggestions. A person at your company reviews and confirms them before they take effect. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you, within the meaning of Article 22 of the GDPR.

7. Bank connections

When you connect a bank account, you authenticate directly with your bank through GoCardless Bank Account Data, an authorised account information service provider. Dori Finance never sees or stores your online banking credentials. We receive account details, balances and transaction history for the accounts you choose, for the period your bank authorisation allows. You can revoke that authorisation at any time in the Platform or with your bank.

8. Who we share data with

We do not sell personal data. We share data only with:

9. International transfers

Our application data and documents are stored in the European Union. Some subprocessors, mainly for email delivery, error monitoring and analytics, are based in the United States or the United Kingdom. Where data leaves the European Economic Area we rely on:

The Subprocessors page states which mechanism applies to each provider. You can request a copy of the relevant clauses at hello@dorifinance.com.

10. How long we keep data

DataRetention period
Account and financial data, while your account is activeFor the life of the account
Account and financial data, after your account is closedKept so you can export it or reactivate, until you ask us to delete it. On request, deleted within 30 days, except where a longer period applies below
Billing records and invoices10 years, as required by Portuguese tax and accounting law
Bank connection tokensUntil you revoke the connection or close the account
Support communications3 years after the ticket is closed
Technical logs and error reportsUp to 90 days
Newsletter subscriptionUntil you unsubscribe
Website form submissions12 months
Website analytics data (Google Analytics)Up to 14 months

After the retention period, data is deleted or anonymised. Backup copies are removed in line with our backup rotation schedule.

11. How we protect data

We apply technical and organisational measures appropriate to the sensitivity of financial data, including:

No system is completely secure. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify the competent supervisory authority within 72 hours and inform affected customers without undue delay, as the GDPR requires.

12. Your rights

Under the GDPR you have the right to:

To exercise any right, email hello@dorifinance.com. We may ask you to verify your identity. We respond within one month, extendable by two further months for complex requests, in which case we will tell you.

Where we act as a processor (Section 3.2), we will forward your request to the customer that controls the data and help them respond.

13. Complaints

If you believe we have not handled your data lawfully, we would like the chance to put it right. Please contact us first. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live or work. In Portugal, that is:

14. Cookies and similar technologies

Website (dorifinance.com). The Website sets essential cookies and similar storage needed for it to work, such as remembering your language choice and your cookie preferences.

With your consent, we also use Google Analytics 4 to measure how visitors use the Website (pages visited, approximate location, device and browser type, and how you arrived at the site) so that we can improve it. Analytics cookies (_ga and _ga_*) are set only after you accept them in the cookie banner. Before you accept, the Google tag runs in cookieless mode (Google Consent Mode): it sets no cookies and stores no identifiers, but your browser does contact Google’s servers, which receive your IP address as a technical consequence. You can withdraw your consent at any time via “Cookie settings” in the footer of every page. We have disabled Google signals and advertising features, so this data is not used for advertising, and Google Analytics does not store full IP addresses. The Website does not use advertising cookies.

Some pages load resources from third parties, which receive your IP address as a technical consequence:

Platform (app.dorifinance.com). The Platform sets essential cookies for authentication and security. We also use product analytics (PostHog) to understand how features are used and to fix problems. Analytics cookies are set only with your consent, which you can give or withdraw in the Platform. Analytics data is not shared with advertisers.

You can also delete or block cookies in your browser settings. Blocking essential cookies will prevent you from signing in.

15. Children

The Website and Platform are intended for businesses and their staff. They are not directed at anyone under 18, and we do not knowingly collect data from children.

16. Changes to this Policy

We may update this Policy when our service or the law changes. The date at the top shows the latest version. For material changes we will notify account holders by email or in the Platform at least 14 days before they take effect. Previous versions are available on request.

17. Contact