Publication revision: 1.1.1-uk-20260922. Effective date: 22 September 2026. Current rollout is UK web and iOS; Android is deferred. Features described in these documents are not all enabled. Original-account and newer decision-record exports currently use separate controls. Closure and erasure requests require review across the original account, Firebase and providers; submission does not confirm completion. Your statutory rights are unchanged.
FLURZI COMMIT BUSINESS PRIVACY POLICY Document key: PRIVACY_BUSINESS Version: 1.1.1-uk-20260922 Effective date: 22 September 2026 Flurzi entity: Flurzi Limited, company number 16640198, registered office at Suite G04 1 Quality Court, Chancery Lane, London, England, WC2A 1HR. ICO registration: ZC201939 (data protection fee registration). 1. Scope 1.1 This Business Privacy Policy explains how Flurzi uses personal data in connection with Business accounts, Business Portfolios, Business workspaces, billing, security, support and Flurzi's own platform operations. 1.2 It also explains the important distinction between personal data for which Flurzi acts as controller and Business Customer Content for which Flurzi generally acts as processor on the Business Customer's instructions. 1.3 The Business Data Processing Agreement forms part of the Business Terms and governs processor activities in more detail. 2. Controller and processor roles 2.1 Flurzi as controller. Flurzi generally determines the purposes and means of processing personal data used for account registration, authentication, security, fraud and abuse prevention, billing, subscription administration, product operations, service telemetry, support administration, legal compliance and Flurzi's own audit obligations. 2.2 Business Customer as controller; Flurzi as processor. Where a Business Customer uploads or generates personal data about its employees, directors, customers, suppliers, contractors, accountants, counterparties or other individuals in a Business workspace and instructs Flurzi to host, organise, reconcile, classify, report or otherwise process that data to provide the service, the Business Customer generally acts as controller and Flurzi acts as processor. 2.3 If Flurzi processes particular Business Customer Content for a purpose it determines independently because the law requires it or because a separate controller purpose clearly applies, Flurzi acts as controller for that specific processing and will comply with the corresponding controller obligations. 3. Personal data Flurzi processes as controller Depending on the relationship, this may include: Business user name, business email, role, workspace membership and access status; authentication, MFA, device, session and security-event information; billing contact, billing address, tax identifier where provided, subscription and payment-status references; product usage, feature entitlement, operational telemetry and error information; support requests, support-access grants and support interaction history; consent/acceptance records, privacy requests, complaints, export and closure records; audit information showing important actions by users, administrators and support personnel; and communication preferences and notification-delivery metadata. 4. Business Customer Content processed on instructions Business Customer Content may include personal data contained in or associated with: bank transactions and financial-account information; customers, suppliers and counterparties; invoices, bills, receipts, attachments and payment allocations; journals, reconciliations, accounting records and period-close activity; business commitments, decisions, approvals, forecasts and management reports; user-generated notes and classifications; payroll commitments or baselines where the Customer chooses to enter them; and other business documents or records the Customer lawfully places in the workspace. The categories vary by Customer. Flurzi does not require Customers to upload special-category personal data merely to use ordinary accounting features. Customers should avoid uploading unnecessary sensitive information and must ensure that any sensitive data they do provide is lawful and necessary. 5. Why Flurzi uses controller data Purpose Typical lawful basis Create/administer Business users and memberships; provide account-level service functions Performance of contract or steps connected to the Business service; legitimate interests where the individual is a user acting for the Customer Manage Business subscriptions, billing and purchase state Performance of the Business contract; legitimate interests in administering the Customer relationship; legal obligation where applicable Authenticate users, secure workspaces, prevent fraud and abuse, maintain audit trails Legitimate interests in security, accountability and service integrity; legal obligation where applicable Provide support and manage time-limited support access Legitimate interests in customer service and secure support; performance of contract Operate and improve service reliability using minimised telemetry Legitimate interests; consent where applicable e-privacy law requires it Optional analytics/marketing Consent where required Establish, exercise or defend legal claims and comply with law Legitimate interests/legal claims; legal obligation 6. Business Customer responsibilities as controller 6.1 The Business Customer determines why it places Customer Content in Flurzi and is responsible for its lawful basis, transparency notices, employee/customer/supplier rights and any other controller obligations for that data. 6.2 The Customer must ensure that its instructions to Flurzi are lawful and that authorised users have appropriate access to the workspace. 6.3 If an individual asks Flurzi directly to exercise a right in relation to Customer Content for which Flurzi is processor, Flurzi may direct the request to the relevant Business Customer and will assist the Customer as required by the DPA. 7. Recipients and service providers 7.1 Flurzi uses service providers for connected-account data, billing and entitlement management, app distribution, hosting and storage, security and key management, backups, transactional communications, push/SMS, translation and optional AI processing. 7.2 Current product integrations may include Plaid, Stripe, RevenueCat, Apple, Google and the configured AI provider. The specific legal entities, processing locations and subprocessor roles used in production are maintained in the current subprocessor register at https://flurzicommit.com/legal/subprocessors. 7.3 We may also disclose controller data to professional advisers, auditors, insurers, regulators, courts, law enforcement or a corporate successor where lawful and necessary. 8. International transfers Where a service provider or Customer instruction involves a restricted transfer outside the UK, Flurzi applies the transfer rules relevant to its role. Where required, safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses or another lawful mechanism, together with any required transfer-risk/data-protection assessment and supplementary measures. For processor transfers of Customer Content, the DPA applies in addition to this Policy. 9. AI processing in Business 9.1 Authoritative accounting figures are produced by deterministic systems, not by an AI model. 9.2 Where the Customer or authorised user enables an AI-enabled feature, Flurzi minimises the data sent to the configured AI provider and uses structured financial facts where possible. 9.3 The configured production terms are intended to prohibit training on sensitive Customer financial data and minimise provider retention where those controls are offered. 9.4 AI can be disabled where supported, in which case deterministic template explanations remain available. 10. Support and staff access 10.1 Staff may not casually browse Business Customer data. Support access is purpose-limited, time-limited and audited. Access beyond basic account status may require approval by the relevant user or Customer, and especially sensitive data requires stronger internal authorisation. 10.2 Support-access history is designed to be auditable and visible through the service. 11. Retention and immutable business records 11.1 Controller data is kept only as long as necessary for account administration, security, support, billing, legal claims, legal duties and accountability. 11.2 Customer Content is retained and deleted according to the Business Customer's instructions, service lifecycle and DPA, subject to applicable legal retention duties and legal holds. 11.3 A person's deletion request does not automatically delete a company's posted journals, invoices, bills, reconciliations, accounting audit history or other records that the Business Customer must or legitimately needs to retain. Personal identifiers in those records are minimised or anonymised where appropriate while preserving the integrity of the business record. 11.4 Raw Business workspace export is available to OWNER and DIRECTOR roles. An individual's Personal data export contains their membership metadata but does not bypass Business role permissions to export company records. 12. Security Flurzi uses technical and organisational measures designed for sensitive financial and accounting data, including workspace isolation, role-based access, multi-factor authentication for sensitive actions, encryption, key/secret management, secure object storage, logging and monitoring, backup/recovery, secure development, malware/file controls and restricted support access. The Business Customer is responsible for its own authorised-user management, device security, internal controls and lawful configuration. 13. Automated processing Flurzi may use deterministic classification, anomaly detection, forecasts, attention prioritisation, simulations and other profiling to provide the Business service. These systems support Customer decision-making and internal workflows. The Business Customer remains responsible for decisions about employees, customers, suppliers, spending, hiring and other business actions. Flurzi does not use Business Commit Score or similar product intelligence to make a lending or external credit decision about an individual. 14. Rights of Business users Where Flurzi acts as controller, individuals may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent and safeguards in relation to certain automated processing, subject to applicable law. Where a request concerns Customer Content for which the Business Customer is controller, the individual should normally contact that Business Customer. Flurzi will assist the Customer under the DPA. 15. Complaints Privacy enquiries and complaints about Flurzi's controller processing can be sent to privacy@flurzicommit.com. We maintain an internal data-protection complaints process. Individuals may also complain to the UK Information Commissioner's Office where UK data-protection law applies, or to another competent supervisory authority where applicable. 16. Changes We may update this Policy when the service, processing, provider arrangements or law changes. Material changes will be notified as appropriate. Where a new optional processing purpose requires consent, it will not begin merely because this Policy changed. 17. Contact Flurzi Limited Company number 16640198 Registered office: Suite G04 1 Quality Court, Chancery Lane, London, England, WC2A 1HR Privacy: privacy@flurzicommit.com Business support: hello@flurzimobileapp.co.uk