FINWAX Privacy Policy
Effective date: 2026-07-06 Version: 1.0 URL: https://finwax.in/legal/privacy
FINWAX ("FINWAX", "we", "us") is a product studio that also operates an authentication service (identity provider). When you sign in to a product that uses FINWAX — for example VELDAT — the sign-in itself is handled by FINWAX at zitadel.finwax.in. This Policy explains what data we process when you visit the finwax.in website and when you create and use a FINWAX account, and what rights you have.
Operator / Controller: FINWAX Contact: support@finwax.in
1. Roles: when we are a controller and when a processor
- Controller. For your FINWAX account itself (the sign-in data listed in Section 2), for the security of the authentication service, and for the finwax.in website, FINWAX determines the purposes and means of processing and acts as a controller.
- Processor. Where a business customer of FINWAX uses our service to authenticate its users under its own instructions, FINWAX acts as a processor on behalf of that customer under a Data Processing Addendum. In that case the customer's privacy policy governs the underlying relationship, and this Policy applies to the operation of the authentication service itself.
- What FINWAX is not. FINWAX does not receive or store the business data of the products you sign in to (appointments, payments, messages, documents). Those are processed by the respective product (e.g. VELDAT) under its own privacy policy.
2. What data we process
We process only the data needed to operate authentication and to understand aggregate usage of the finwax.in website:
| Category | Data | Source |
|---|---|---|
| Account data | Email address; given name and family name (collected at registration); account identifier; preferred language | You |
| Credentials | Password — stored only as a salted cryptographic hash; second-factor data if you enable 2FA (e.g. TOTP secret, passkey public key) | You |
| Sessions and tokens | Session identifiers, access/refresh/ID tokens, token issuance and expiry times | Generated by the service |
| Security log (login events) | Date and time of sign-in attempts, IP address, user agent (browser/device type), event outcome, account roles/claims issued | Generated by the service |
| Support | Correspondence if you contact us at the support address | You |
| Website analytics | Page views, clicks on outgoing links, referrer, approximate location derived from IP, device and browser type, screen size | Generated when you visit finwax.in (OpenPanel — see below) |
We do not process special categories of data, we do not profile you, we do not use your data for advertising, and we do not sell or share personal data for advertising purposes.
Website analytics. The finwax.in website uses OpenPanel, a privacy-focused analytics tool, to measure page views and clicks on outgoing links. It operates without cookies or cross-site identifiers and gives us aggregate statistics, not advertising profiles. Analytics runs on a self-hosted OpenPanel instance on FINWAX's own infrastructure; the data is not shared with any third-party analytics provider.
The sign-in pages (zitadel.finwax.in) contain no analytics, no session replay, and no third-party trackers (see the Cookie Notice).
3. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Creating and maintaining your account; authenticating you to connected products | Account data, credentials, sessions/tokens | Art. 6(1)(b) — performance of a contract (the Terms of Service) |
| Security: preventing unauthorized access, detecting brute-force and anomalous sign-ins, audit trail | Security log | Art. 6(1)(f) — legitimate interest in the security of the service; where FINWAX acts as processor, the customer's instructions |
| Compliance with legal obligations (e.g. responding to lawful requests, accounting) | Minimal necessary data | Art. 6(1)(c) |
| Responding to your requests | Support correspondence | Art. 6(1)(b), 6(1)(f) |
| Measuring aggregate website usage (pages viewed, outgoing links clicked) | Website analytics data | Art. 6(1)(f) — legitimate interest in understanding and improving our website; no cookies are used and no advertising profiling takes place |
We do not rely on consent for the operation of authentication, because the processing is necessary to provide the service you request. Where the law of your country requires consent as the basis (see the country sections below), your acceptance of these documents at sign-up constitutes that consent, and a separate consent instrument is used where required.
4. Retention
- Account data and credentials: for the life of the account and deleted or irreversibly anonymized within 3 years after account deletion.
- Sessions/tokens: for the token lifetime; expired tokens are purged automatically.
- Security log (incl. IP addresses): 3 years from the event, then deleted, unless a specific event must be retained longer as evidence of an incident or to comply with a legal obligation.
- Support correspondence: 3 years after the ticket is closed.
- Website analytics: event data retained for 3 years; reports are aggregate.
5. Where data is stored; international transfers
FINWAX infrastructure is hosted with Spaceweb. Depending on your region, your data is stored and processed on servers located in Russia or Sweden.
Where personal data needs to be transferred between these locations or to another country without an adequacy decision, we rely on the transfer mechanisms available under applicable law (such as the EU Standard Contractual Clauses for transfers from the EEA). The current list of sub-processors is published at https://finwax.in/legal/subprocessors. The country-specific sections below describe any additional local safeguards.
6. Recipients
We share personal data only with:
- The product you sign in to. When you authenticate, the connected product (e.g. VELDAT) receives your account identifier, email, name and the roles/claims needed for your access. That product processes these under its own privacy policy.
- Sub-processors (hosting infrastructure) listed at https://finwax.in/legal/subprocessors, bound by data processing agreements.
- Authorities, where required by applicable law, on a valid legal request; we verify each request and disclose the minimum necessary.
We never sell personal data.
7. Security
Passwords are stored only as salted hashes using a modern password-hashing algorithm. All connections are encrypted (TLS). Access to production systems is restricted, logged and protected by multi-factor authentication. Our technical and organizational measures are summarized in the TOMs annex to our Data Processing Addendum. If a personal data breach occurs that is likely to result in a risk to you, we will notify the competent authority and, where required, you, within the timelines of applicable law (including within 72 hours to the supervisory authority under GDPR).
8. Your rights
Depending on your jurisdiction, you have the right to: access your data and obtain a copy; rectify inaccurate data; delete your account and data; restrict or object to processing based on legitimate interest; data portability; withdraw consent where processing is based on consent; and lodge a complaint with your supervisory authority.
Most account data can be viewed and edited directly in your FINWAX account console. For anything else, contact support@finwax.in. We verify your identity via your authenticated account (or equivalent verification) and respond within one month (GDPR) or the shorter/longer period your local law prescribes. We will not discriminate against you for exercising your rights.
If FINWAX processes your data as a processor for a business customer, we will forward your request to that customer or refer you to them, as the decision rests with the controller.
9. Country- and region-specific terms
9.1 United States
This section applies to residents of US states with comprehensive privacy laws (including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Indiana, Kentucky, Rhode Island and others as they take effect).
- Notice at collection. The categories collected are listed in Section 2: identifiers (email, name, account ID, IP address), internet activity (login events), and account credentials. Credentials (email + password) are "sensitive personal information" under the CCPA; we use them only to provide the authentication service you request — a purpose for which no "Limit the Use of My Sensitive Personal Information" mechanism is required.
- No sale, no sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and have not done so in the preceding 12 months. We do not use or disclose sensitive personal information beyond the permitted service purposes.
- Your rights (know, access, correct, delete, portability, non-discrimination) can be exercised as described in Section 8. We do not respond to browser "Do Not Track" signals because we do not track; Global Privacy Control signals are honored where applicable, though we engage in no selling/sharing to opt out of.
- Children. The service is not directed to children under 13, and we do not knowingly collect their data (see Terms of Service, eligibility).
- Where FINWAX authenticates users for a business customer, FINWAX acts as a service provider / processor under a written contract that prohibits any use of the data beyond the services.
9.2 Russian Federation
For data subjects located in Russia, FINWAX processes personal data in accordance with Federal Law No. 152-FZ "On Personal Data":
- The purposes, categories and retention periods are as set out in this Policy; processing is limited to what is necessary for authentication.
- Legal bases correspond to Art. 6 of 152-FZ (performance of a contract with the data subject; the operator's legitimate interests in service security; consent where required). Where 152-FZ requires consent to be given as a separate instrument, a standalone consent form is presented at registration.
- Data location. For users in Russia, personal data is processed on servers located in Russia (Spaceweb), consistent with the data-localization requirement of 152-FZ.
- Data subjects in Russia may exercise the rights under Chapter 3 of 152-FZ (access, clarification, blocking, destruction, withdrawal of consent) via support@finwax.in.
9.3 China (PIPL)
If you are in mainland China: the categories, purposes and retention are as stated above; data is stored outside China (in Russia or Sweden), which constitutes a cross-border provision of personal information under PIPL. By creating an account you acknowledge and, where PIPL requires, separately consent to this transfer, which is necessary to perform the contract with you. You may contact support@finwax.in to exercise PIPL rights (access, copy, correction, deletion, withdrawal of consent). Our processing volume is below the thresholds requiring a CAC security assessment or Chinese SCC filing; we monitor these thresholds.
9.4 Singapore, Japan, South Korea, and other jurisdictions
- Singapore (PDPA): our data protection contact is support@finwax.in. Overseas transfers are protected by contractual safeguards ensuring a comparable standard of protection.
- Japan (APPI): the data is stored outside your country (in Russia or Sweden); by registering you consent to the provision of your data to a foreign operator under the safeguards described in this Policy. You may request disclosure, correction or cessation of use.
- South Korea (PIPA): the items collected, purposes, retention and overseas storage location (Russia or Sweden) are as stated in Sections 2, 3, 4 and 5. You may request access, correction, deletion or suspension of processing.
- India (DPDP Act): we monitor the phased entry into force of the DPDP Rules and will update this Policy before the substantive obligations apply.
10. Changes to this Policy
We may update this Policy at any time. We do not send individual notices of changes: the current version is always published at https://finwax.in/legal/privacy, and it is your responsibility to review it.
11. Contact
FINWAX Email: support@finwax.in