1. Scope and responsibilities
This Policy covers the FinAlpha website and its financial data and AI research services, including FinStock, FinRadar and FinData. It applies to website visitors, registered users, customers and people who contact us.
For account, billing, support and service administration, the Company determines why and how the relevant personal information is processed. Where an organisation submits information for processing on its behalf, the applicable service agreement and lawful instructions also govern that processing.
Public company information and financial datasets can contain information about individuals, such as directors or major shareholders. Where such information is personal data, applicable data protection requirements continue to apply even if it is publicly available.
2. Information we process
Account and profile information: information you provide to register, authenticate and manage an account, such as your name, email address, organisation, account identifier and login-related records. If you choose a third-party login, we receive the profile information shared through that login.
Research inputs and outputs: questions, prompts, documents or other content you submit, the research context you choose to provide, and the reports, tables, charts and responses generated for your account. These may contain personal information if you include it.
Preferences and activity: language, selected settings, saved research or watchlists where available, features used, Credit consumption and service interactions needed to deliver and maintain your account.
Subscription and billing records: the selected plan, billing interval, order references, payment status, invoices, cancellation and refund requests, and billing or tax details needed for those purposes. Payment card details are handled by the designated payment intermediary; the Company does not directly receive or hold them.
Technical and security information: IP address, device and browser information, timestamps, request and error logs, session information and records needed to operate the service, troubleshoot problems and detect misuse.
Communications: information you provide in support emails, enquiries, demo requests or other correspondence, including attachments and the details needed to respond.
Integration and workspace information: if you enable a notification channel, API, MCP connection or organisation workspace, the identifiers, permissions, membership and request information needed for that feature. The information involved depends on what you enable and are authorised to share.
3. How information is collected
Directly from you when you create or manage an account, submit a research request, provide content, select a plan or contact us.
Automatically when your browser or application communicates with the service, including technical logs and browser storage needed for operation and preferences.
From providers or integrations you use, such as a login provider, payment intermediary or a notification channel you connect, and from your organisation's workspace administrator.
From public or licensed financial and company information sources used for research. This is distinct from information you provide privately in your account.
4. Purposes and legal grounds
We use relevant information to create and authenticate accounts, provide data and AI research, return and display results, operate integrations you request and manage plan entitlements and Credits.
We use subscription and correspondence records to administer billing, renewal, cancellation and refunds, issue or reconcile service records, answer questions and send necessary account or service notices.
Technical and usage records help us maintain reliability, identify errors, investigate abuse, protect accounts and improve the operation of the service. We also process information when necessary to meet legal obligations, resolve disputes or establish and protect lawful rights.
The legal grounds depend on the applicable law and purpose. They may include steps requested before a contract, performance of a contract, legal obligations, consent where required, and legitimate interests where recognised by law and balanced against your rights. We obtain separate consent when required; merely accepting the Terms does not replace it.
Optional marketing communications, if offered, are subject to the choices and consent requirements that apply to them. You can withdraw consent or ask to stop such messages. Necessary security, billing and service notices may still be sent.
5. AI research and your content
When you request research, FinAlpha uses the question and relevant context to classify the task and plan the research. Data collection and web research retrieve relevant information; computation tools calculate metrics or comparisons; writing and visualisation components turn the results into a report, table or chart.
The relevant parts of your input, documents and retrieved context may be processed by AI, search, data or infrastructure providers involved in fulfilling the request. Only submit information you have the right to use and share for this purpose. Avoid unnecessary personal information, passwords and confidential third-party material.
Research inputs, outputs and related technical records are handled for service delivery, account features, support and security as described in this Policy. A new processing purpose requiring consent will be explained and consent obtained before that processing takes place.
The AI produces research outputs. It does not make investment decisions on your behalf. Review results for accuracy and inappropriate personal information before sharing them with others. Sharing or exporting content can make it available to recipients outside your account.
6. When information is shared
Authorised personnel may access information needed for their work, such as supporting your account, maintaining systems, handling billing or investigating a security issue.
Service providers may process information needed to supply hosting, storage, AI processing, data retrieval, authentication, communications, security, technical support or billing. Their access is limited to the relevant purpose and subject to the legal and contractual requirements that apply.
The designated payment intermediary handles the payment information it needs, including tax and invoicing obligations. We receive the payment or order information needed to administer your subscription and resolve billing issues.
An integration you choose, such as a notification channel or connected application, receives information required for that integration. Workspace administrators may access membership, permissions, plan usage and content made available to them under the workspace's settings and agreement.
We may disclose information where required by law or a valid request from a competent authority, or where lawfully necessary to investigate fraud, protect safety and security, or establish, exercise or defend legal rights.
If the business undergoes a merger, acquisition or similar reorganisation, relevant information may be transferred subject to applicable confidentiality and data protection obligations. We provide notice when required. Independent providers' own processing is governed by their privacy practices and applicable law.
7. Cookies, browser storage and embedded video
This website stores your selected language in your browser's local storage so that the preference can be remembered. Account services may use cookies or similar storage for authentication, session security and necessary preferences.
The website includes embedded YouTube videos. When an embedded player loads or you interact with it, your browser communicates with YouTube, which can receive technical information such as your IP address, device information and playback activity. The provider's own privacy practices apply to its independent processing.
You can clear local storage and manage or block cookies using your browser controls. Doing so can reset preferences or affect sign-in and other features. You can also choose not to play embedded videos; that does not necessarily prevent the player from loading.
Where non-essential storage or tracking requires consent under applicable law, it must be subject to that consent. Consent can be withdrawn without affecting processing that was lawful before withdrawal.
8. Processing across borders
Infrastructure, AI and other service providers may operate in countries other than your country of residence. Using them can involve cross-border processing of the information needed for their services.
Where such processing occurs, we comply with the applicable conditions for cross-border transfers, including required safeguards, notices and consent. You may contact us for information about the safeguards relevant to your personal information.
9. Retention and deletion
We retain personal information for as long as reasonably needed for the purposes described in this Policy, taking account of the information involved, your use of the service, legal requirements, security needs and unresolved disputes.
Account information and research content may be retained to provide your account and its available history or saved features. Billing, tax and dispute records may need to be kept after a subscription ends where legally required or necessary to resolve an outstanding matter.
You may request deletion or account closure using the contacts below. Information that must be retained for a lawful purpose is not necessarily deleted at the same time as the active account. Residual backup copies are handled through the applicable backup retention cycle and protected from routine use.
When the purpose for retaining personal information ends and no lawful reason to keep it remains, it is deleted or anonymised. Cancelling renewal does not by itself request deletion of your account or research history.
10. Security and incidents
We use reasonable organisational, technical and physical safeguards appropriate to the service and information, including access controls, encryption, monitoring and backups where applicable. Access should be limited to authorised people and providers with a relevant need.
No system is completely secure. Protect your password and authentication codes, keep devices secure, and promptly report suspected account misuse. Do not send sensitive account secrets to support.
If a personal data incident occurs, we investigate, take measures to address it and notify affected people and authorities where required by applicable law. Reports can be sent to contact@fintechai.vn.
11. Your choices and rights
Depending on the law that applies, you may have rights to know about processing, obtain access to or a copy of your personal information, correct inaccurate information, request deletion, withdraw consent, object to or restrict processing, or receive portable information where that right applies.
Send a request to contact@fintechai.vn. Describe the right you wish to exercise and the account or information concerned. We may ask for proportionate information to verify your identity or authority before disclosing or changing personal information.
We respond within the period required by applicable law. Some rights have legal limits: for example, we may need to retain an invoice or information needed for a legal claim. Where a request cannot be fulfilled in full, we explain the reason as required by law.
Withdrawing consent does not affect the lawfulness of processing before withdrawal. If information is necessary to provide a feature or meet a legal obligation, a request to stop its processing may affect whether that feature can continue.
You may raise a concern with us and, where applicable, complain to the competent data protection or other supervisory authority. Nothing in this Policy limits that right.
12. Children
FinAlpha is intended for people aged 18 and over. We do not intentionally collect personal information from children for an account. If you believe a person under 18 has provided account information, contact us so that we can investigate and take appropriate action, including deletion where required.
13. Changes to this Policy
We may update this Policy when the service, processing practices or legal requirements change. The current version is published on this page with its effective and last-updated dates.
We notify you of material changes and obtain additional consent where required by law. A policy update does not by itself authorise processing that requires a new legal basis or your separate consent.
14. Contact us
Responsible company: Fintech AI Joint Stock Company. Privacy requests, legal enquiries, security reports and customer support: contact@fintechai.vn. Hotline: 0967915569.
Please include your registered email address, if applicable, and a clear description of your question. Send only the information needed to handle the request. Do not include your password, authentication codes or full payment card details.