This Privacy Policy explains how Dori Finance collects, uses, stores, shares and protects personal data when you visit our website at dorifinance.com (“Website”), create an account or use our application at app.dorifinance.com (“Platform”), or otherwise interact with us.
Dori Finance is a business-to-business service. Our customers are companies and the people who act on their behalf. We process two broad categories of data, and our role is different for each. Section 3 explains this in detail.
1. Who we are
Dori Finance is the trading name of:
- Leancfo, Unipessoal Lda
- Registered in Portugal, tax and registration number (NIPC) 518703045
- Rua Penha de França, Nº 125, 1º Dtº, 1170-302 Lisboa, Portugal
- Privacy contact: hello@dorifinance.com
Leancfo, Unipessoal Lda is the data controller for the data described in Section 3.1 and the data processor for the data described in Section 3.2.
2. Data protection contact
We are not required to appoint a Data Protection Officer under Article 37 of the GDPR and have not done so. All privacy questions, requests to exercise your rights, and complaints are handled by our privacy team. Write to us at hello@dorifinance.com or by post at the address above.
3. Our role: controller and processor
3.1 Data for which we are the controller
We decide how and why the following data is processed, and we are the controller for it under the GDPR:
- Account data: name, work email address, password (stored hashed), role, company name, and the language and settings you choose.
- Billing data: the company’s legal name, tax number, billing address, and the subscription plan. Card details are entered directly with our payment provider, Stripe, and never reach our servers.
- Website and contact data: your email address and any message you send through our contact form, newsletter sign-up, demo booking, or the Financial Health Assessment.
- Usage and technical data: log data (IP address, browser, device type, pages visited, timestamps), product analytics events inside the Platform, error reports, and support correspondence.
3.2 Data for which we are the processor
When your company connects a bank account or uploads invoices, receipts and other financial documents, that content may contain personal data about your company’s customers, suppliers, employees and other third parties. Examples are names, tax numbers, bank account numbers, and transaction descriptions.
Your company is the controller of that data. Dori Finance processes it only on your company’s instructions, as set out in our Terms and Conditions and, where applicable, a data processing agreement. If you are a third party whose data appears in a customer’s records, please direct requests to that company. We will assist them in responding.
4. What we collect and where it comes from
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, role, company | You, when you sign up or are invited |
| Financial data | Sales, expenses, bank transactions, invoices, receipts | Your company, through uploads and bank connections |
| Bank connection data | Account holder name, IBAN, balances, transaction history | Your bank, through GoCardless Bank Account Data, after you authorise access |
| Billing data | Company details, plan, invoices | You and Stripe |
| Usage data | Feature use, clicks, session length | Collected automatically inside the Platform |
| Technical data | IP address, browser, device, error reports | Collected automatically by our servers and error monitoring |
| Communications | Emails, support messages, form submissions | You |
We do not collect special categories of personal data (such as health or biometric data) and we ask that you do not upload documents containing them.
5. Why we process data and on what legal basis
| Purpose | Data used | Legal basis (GDPR Article 6) |
|---|---|---|
| Create and manage your account, provide the Platform | Account data, financial data, bank connection data | Performance of a contract (Art. 6(1)(b)) |
| Extract, categorise and reconcile financial documents using AI | Financial data | Performance of a contract (Art. 6(1)(b)) |
| Send transactional emails (verification, invitations, alerts) | Account data | Performance of a contract (Art. 6(1)(b)) |
| Bill you and keep accounting records | Billing data | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Keep the Platform secure, prevent fraud and abuse | Technical data, usage data | Legitimate interest (Art. 6(1)(f)) in protecting our service and customers |
| Diagnose errors and improve the product | Technical data, usage data | Legitimate interest (Art. 6(1)(f)) in a reliable product; analytics cookies only with consent (Art. 6(1)(a)) |
| Respond to your questions and support requests | Communications | Contract (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)) |
| Send newsletters and marketing | Email address | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Comply with tax, accounting and other laws | Billing data, account data | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interest, we have assessed that our interest does not override your rights. You can ask for a copy of that assessment.
Providing account and billing data is a contractual requirement. Without it we cannot create your account or provide the service. Providing marketing consent is optional and does not affect the service.
6. Artificial intelligence and automated processing
The Platform uses AI models to read documents, suggest categories, and propose reconciliation matches. To do this, we send document content and transaction data to the AI providers listed in our Subprocessors page. Under our agreements with those providers, your data is not used to train or improve their models, and we do not use it to train models of our own.
All AI outputs are suggestions. A person at your company reviews and confirms them before they take effect. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you, within the meaning of Article 22 of the GDPR.
7. Bank connections
When you connect a bank account, you authenticate directly with your bank through GoCardless Bank Account Data, an authorised account information service provider. Dori Finance never sees or stores your online banking credentials. We receive account details, balances and transaction history for the accounts you choose, for the period your bank authorisation allows. You can revoke that authorisation at any time in the Platform or with your bank.
8. Who we share data with
We do not sell personal data. We share data only with:
- Subprocessors that host our infrastructure, run AI models, send email, process payments, and monitor errors. Each is bound by a contract that meets Article 28 of the GDPR. The current list, with the location of each and the safeguard used for any transfer outside the EEA, is published on our Subprocessors page. We update that page when we add or replace a provider.
- People your company invites, such as colleagues or your external accountant. Your company controls who is invited and what they can see, and is responsible for those choices.
- Authorities, courts and regulators, when the law requires it or to protect our rights or the safety of others.
- A buyer or successor in the event of a merger, acquisition or sale of assets. We will notify you before your data becomes subject to a different privacy policy.
9. International transfers
Our application data and documents are stored in the European Union. Some subprocessors, mainly for email delivery, error monitoring and analytics, are based in the United States or the United Kingdom. Where data leaves the European Economic Area we rely on:
- an adequacy decision of the European Commission (for the United Kingdom, and for US companies certified under the EU-US Data Privacy Framework); or
- the European Commission’s Standard Contractual Clauses, together with any supplementary measures needed.
The Subprocessors page states which mechanism applies to each provider. You can request a copy of the relevant clauses at hello@dorifinance.com.
10. How long we keep data
| Data | Retention period |
|---|---|
| Account and financial data, while your account is active | For the life of the account |
| Account and financial data, after your account is closed | Kept so you can export it or reactivate, until you ask us to delete it. On request, deleted within 30 days, except where a longer period applies below |
| Billing records and invoices | 10 years, as required by Portuguese tax and accounting law |
| Bank connection tokens | Until you revoke the connection or close the account |
| Support communications | 3 years after the ticket is closed |
| Technical logs and error reports | Up to 90 days |
| Newsletter subscription | Until you unsubscribe |
| Website form submissions | 12 months |
| Website analytics data (Google Analytics) | Up to 14 months |
After the retention period, data is deleted or anonymised. Backup copies are removed in line with our backup rotation schedule.
11. How we protect data
We apply technical and organisational measures appropriate to the sensitivity of financial data, including:
- encryption of data in transit using TLS, and encryption at rest for our databases and file storage;
- daily backups stored within the European Union;
- access to production data restricted to staff who need it, protected by authentication and logged;
- bank credentials never handled by us, as explained in Section 7;
- contractual security obligations for every subprocessor.
No system is completely secure. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify the competent supervisory authority within 72 hours and inform affected customers without undue delay, as the GDPR requires.
12. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data, where there is no overriding legal reason to keep it;
- restrict processing in certain circumstances;
- data portability: receive your data in a structured, machine-readable format, and have it transmitted to another provider where technically feasible. Customers can export their financial data from the Platform at any time;
- object to processing based on legitimate interest, and to direct marketing at any time;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any right, email hello@dorifinance.com. We may ask you to verify your identity. We respond within one month, extendable by two further months for complex requests, in which case we will tell you.
Where we act as a processor (Section 3.2), we will forward your request to the customer that controls the data and help them respond.
13. Complaints
If you believe we have not handled your data lawfully, we would like the chance to put it right. Please contact us first. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live or work. In Portugal, that is:
- Comissão Nacional de Proteção de Dados (CNPD)
- Av. D. Carlos I, 134, 1º, 1200-651 Lisboa, Portugal
- www.cnpd.pt · geral@cnpd.pt
14. Cookies and similar technologies
Website (dorifinance.com). The Website sets essential cookies and similar storage needed for it to work, such as remembering your language choice and your cookie preferences.
With your consent, we also use Google Analytics 4 to measure how visitors use
the Website (pages visited, approximate location, device and browser type, and
how you arrived at the site) so that we can improve it. Analytics cookies
(_ga and _ga_*) are set only after you accept them in the cookie banner.
Before you accept, the Google tag runs in cookieless mode (Google Consent
Mode): it sets no cookies and stores no identifiers, but your browser does
contact Google’s servers, which receive your IP address as a technical
consequence. You can withdraw your consent at any time via “Cookie settings”
in the footer of every page. We have disabled
Google signals and advertising features, so this data is not used for
advertising, and Google Analytics does not store full IP addresses. The
Website does not use advertising cookies.
Some pages load resources from third parties, which receive your IP address as a technical consequence:
- Google Fonts, for typography;
- Cloudinary, for images;
- YouTube, in privacy-enhanced mode, only when you play an embedded video;
- Formspree, Kit, Loops and Cal.com, only when you submit a form or book a demo.
Platform (app.dorifinance.com). The Platform sets essential cookies for authentication and security. We also use product analytics (PostHog) to understand how features are used and to fix problems. Analytics cookies are set only with your consent, which you can give or withdraw in the Platform. Analytics data is not shared with advertisers.
You can also delete or block cookies in your browser settings. Blocking essential cookies will prevent you from signing in.
15. Children
The Website and Platform are intended for businesses and their staff. They are not directed at anyone under 18, and we do not knowingly collect data from children.
16. Changes to this Policy
We may update this Policy when our service or the law changes. The date at the top shows the latest version. For material changes we will notify account holders by email or in the Platform at least 14 days before they take effect. Previous versions are available on request.
17. Contact
- Email: hello@dorifinance.com
- Post: Leancfo, Unipessoal Lda, Rua Penha de França, Nº 125, 1º Dtº, 1170-302 Lisboa, Portugal