Publication revision: 1.1.1-uk-20260922. Effective date: 22 September 2026. Current rollout is UK web and iOS; Android is deferred. Features described in these documents are not all enabled. Original-account and newer decision-record exports currently use separate controls. Closure and erasure requests require review across the original account, Firebase and providers; submission does not confirm completion. Your statutory rights are unchanged.
FLURZI COMMIT PERSONAL PRIVACY POLICY Document key: PRIVACY_PERSONAL Version: 1.1.1-uk-20260922 Effective date: 22 September 2026 Controller: Flurzi Limited, company number 16640198, registered office at Suite G04 1 Quality Court, Chancery Lane, London, England, WC2A 1HR. ICO registration: ZC201939 (data protection fee registration). 1. Scope and who we are 1.1 This Personal Privacy Policy explains how Flurzi Limited (Flurzi, we, us or our) uses personal data in connection with Flurzi Commit Personal, our website, mobile apps, Personal account, support and related services. 1.2 For Personal accounts, Flurzi is generally the controller of the personal data described in this Policy. If you are also a user of a Business workspace, different controller/processor roles may apply to Business workspace content; see the Business Privacy Policy. 1.3 Privacy enquiries and data-protection complaints can be sent to privacy@flurzicommit.com. 2. Personal data we collect We may collect and generate the following categories of personal data, depending on how you use Flurzi: Account and profile data: name or display name, email address, country, language, timezone, preferences and account status. Authentication and security data: password hash, MFA status, recovery-code hashes, device and session information, app version, security events, hashed IP data and coarse location/security signals. Connected financial data: information about financial institutions, accounts, balances, currencies, transaction history, merchant/category information, pending/posted transaction state, connection health and last-sync information received through a connected-account provider. Manual and imported financial data: manual accounts, balances, transactions, statement files and mapping choices, debt information, income, recurring costs and user-entered assumptions. Commitment and planning data: commitments, occurrences, goals, reserves, rules, scenarios, choices and outcome information. Derived financial intelligence: Financial Overlay and Twin data, Financial Capacity, Safe-to-Commit, runway, goal probabilities, Spend Weather, income and recurring patterns, Commit Score, Decision Memory, Replay and other deterministic model outputs. AI interaction data: questions you submit to AI-enabled features, structured facts supplied to the AI layer, generated explanations, model/provider operational metadata and safety/validation records where AI processing is enabled. Household and sharing data: household membership, field-level permissions, shared goal information, Money Passport share configuration, recipient/share-link metadata and revocations. Subscription and billing data: plan, entitlement, purchase and renewal state, billing scope, billing contact information, payment status and limited references received from Stripe, RevenueCat, Apple or Google. We do not need to store your full card number when the billing provider handles it. Support and service data: support requests, support-access approvals, messages, issue records and product feedback. Audit and compliance data: consent/authorisation records, document versions accepted, important security and account actions, exports, deletion requests and administrative/support access logs. Notification data: notification preferences, delivery state, device notification tokens where relevant and message interaction metadata. 3. Where the data comes from 3.1 We collect personal data directly from you when you register, configure the service, enter financial information, upload documents, ask questions, create commitments/goals, manage preferences or contact support. 3.2 We receive connected financial information from our connected-account provider and the financial institutions it accesses on your instructions. The current Flurzi Commit build uses Plaid as the connected-account data provider. 3.3 We may receive billing and subscription state from Stripe, RevenueCat, Apple and Google, depending on where you subscribe. 3.4 We generate derived data by applying Flurzi's deterministic models to information available in your workspace. 3.5 We may receive security or technical data automatically from your device, browser, network and our service infrastructure. 4. Why we use personal data and our lawful bases We use personal data only where we have a lawful basis. The principal purposes are: Purpose Typical lawful basis Create and administer your account; provide the Personal service; calculate financial outputs; maintain goals, commitments and Personal history Performance of our contract with you Receive and process connected-account data you ask us to use Performance of our contract; and any separate authorisation/consent required by the connected-account flow or applicable law Process payments, subscriptions, upgrades, downgrades and billing support Performance of contract; legal obligation where applicable Secure accounts, detect abuse, investigate fraud, protect service integrity and keep audit records Legitimate interests in security, fraud prevention, service integrity and accountability; legal obligation where applicable Provide customer support and resolve disputes Performance of contract; legitimate interests in customer service and legal claims Generate AI-assisted conversational explanations Your separate AI-processing consent where the external AI route is optional; the deterministic fallback remains available when you decline or withdraw it Optional product analytics that require consent or access to information on your device Consent Essential operational telemetry needed to run, diagnose and secure the service Legitimate interests, where consent is not required by applicable e-privacy law Send electronic marketing where consent is required Consent; you can withdraw it at any time Share information with a household member or recipient you choose Your data-sharing instruction and, where required, consent Comply with law, regulator, court or law-enforcement requirements Legal obligation; or establishment/exercise/defence of legal claims where appropriate Improve reliability, test models and understand service performance using appropriately minimised data Legitimate interests in improving and operating the service, balanced against your rights; consent where required 4.1 Where we rely on legitimate interests, the interests may include security, preventing fraud and abuse, maintaining reliable financial calculations, operating and improving the service, supporting users, establishing legal claims and protecting Flurzi and other users. We assess whether those interests are overridden by your rights and expectations. 4.2 Where we rely on consent, you may withdraw it at any time for future processing. Withdrawal does not make earlier lawful processing unlawful. 4.3 Accepting the Terms is contract acceptance, not GDPR consent. Reading or acknowledging this Privacy Policy is not consent for optional processing. 5. Connected financial accounts and bank data 5.1 When you choose to connect an account, the connected-account provider controls the institution-authentication flow. Flurzi ordinarily receives the resulting account and transaction data, not your online-banking password. 5.2 We use connected data to provide the Financial Overlay, Twin, financial calculations, transaction intelligence, commitments, goals, scenarios and other features you request. 5.3 Connected data can be delayed, incomplete or corrected by the institution or provider. We record freshness and provenance because those characteristics affect financial outputs. 5.4 You can disconnect a connection. Future ingestion stops, and the provider access credential held by Flurzi is erased once no longer required. For Personal data, you can choose whether eligible previously ingested history is retained or deleted, subject to applicable legal obligations and dependency rules. 6. AI processing 6.1 Flurzi's authoritative financial calculations are produced by deterministic engines. When you enable AI processing, we may send a minimised set of structured financial facts and your relevant question or instruction to the configured AI provider so that it can generate a conversational explanation or structure your request. 6.2 We design the AI layer to avoid sending bank credentials, full account numbers, identity documents and unnecessary raw personal information. Raw transaction descriptions are not supplied where structured facts are sufficient. 6.3 Our intended production configuration is to prohibit training on sensitive user financial data and, where the provider offers the option, to minimise provider retention. The exact provider terms and configuration in force at launch are controlled through our production provider arrangements. 6.4 You can turn AI processing off in the Privacy Centre. AI-enabled surfaces then use Flurzi's deterministic template provider rather than sending your request to the external AI provider. 7. Analytics, marketing, cookies and similar technologies 7.1 We distinguish service-essential technologies from optional analytics and marketing technologies. 7.2 Where the law requires consent before storing or accessing information on your device, we obtain that consent before using the relevant non-essential cookie, SDK, pixel, local-storage identifier or similar technology. 7.3 Optional analytics and marketing are not treated as necessary to provide the core service. You can reject or withdraw optional consent without losing core Flurzi functionality. 7.4 Further details, including the live categories and controls, are in the Cookie & Similar Technologies Policy and your Privacy/Cookie settings. 8. Who we share personal data with We may share personal data with the minimum recipients necessary for the relevant purpose, including: connected-account data providers such as Plaid; billing and entitlement providers such as Stripe and RevenueCat, and Apple or Google where you use their stores; hosting, object-storage, database, security, key-management, backup and infrastructure providers; the configured AI provider where you enable AI processing; translation providers for approved localisation workflows where personal data is involved; transactional email, push-notification and SMS providers where those channels are enabled; professional advisers, auditors and insurers where necessary; regulators, courts, law enforcement or public authorities where disclosure is legally required or permitted; and a buyer, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and data-protection safeguards. We do not disclose your connected financial data to another household member merely because they are in the same household. Sharing requires the permissions described in the product. 9. International transfers 9.1 Some service providers may process personal data outside the United Kingdom. Before making a restricted transfer, we assess the applicable transfer rules. 9.2 Where required, we use a lawful transfer mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, another approved safeguard, or a valid exception. Where required, we also complete the applicable transfer-risk/data-protection assessment and adopt supplementary protections. 9.3 The specific transfer mechanism depends on the legal entity, location and service actually configured in production. We do not claim that every provider processes data in one fixed country. 10. How long we keep personal data 10.1 We keep personal data only for as long as needed for the purpose for which it is held, including providing the service, maintaining user-requested history, security, dispute resolution, legal claims and compliance with legal obligations. 10.2 Important product-specific rules include: full Financial Twin snapshots are ordinarily retained for 90 days, with daily roll-ups for 24 months and then monthly history, subject to account deletion and legal-hold rules; Decision Memory plan limits control in-product access, not automatic deletion of older retained decisions; privacy export archives are short-lived and are ordinarily purged within 7 days of becoming ready, or earlier after download plus any configured grace period; connected-account access credentials are deleted when the connection is removed and the credential is no longer needed; unverified webhook payloads used for diagnosis are short-lived under the service's operational retention policy; security and audit records may be kept for longer periods where reasonably required for integrity, accountability, fraud prevention, claims or legal duties. The product specification currently requires core audit records to be retained for at least seven years. 10.3 If you request erasure, we delete or irreversibly anonymise eligible personal data. Data that must lawfully be retained is minimised and access-restricted. Active legal holds suspend deletion of covered data until the hold is released. 11. Your rights Depending on the law that applies to you, you may have rights to: be informed about how your personal data is used; obtain access to your personal data; correct inaccurate or incomplete data; request erasure; restrict certain processing; receive certain data in a portable format; object to processing based on legitimate interests; object to direct marketing at any time; withdraw consent where processing is based on consent; and receive safeguards in relation to certain automated decision-making. 11.1 You can use the in-product Privacy Centre for many actions, including connected-account management, AI settings, export and account deletion. You can also contact privacy@flurzicommit.com. 11.2 We may need to verify your identity before acting on a rights request. Rights can be limited by law, for example where data must be retained for legal claims or another person's rights would be affected. 12. Data portability and account deletion 12.1 Personal data portability is available to every plan, including Free, and is not a premium report-export feature. We protect the export with re-authentication, MFA and a short-lived single-use download link. 12.2 Account closure and data erasure are related but distinct. Closure ends access; erasure removes or anonymises eligible personal data. Subscription cancellation may still require a separate action through Apple or Google. 12.3 If you own a Business Portfolio, company records are not erased merely because you close your Personal account. You must transfer ownership/billing responsibility or close the Business Portfolio through its own process. 13. Automated processing and profiling 13.1 Flurzi uses deterministic profiling and modelling to calculate financial indicators, probabilities, classifications, forecasts and Commit Score. 13.2 These outputs are designed to support your own decisions. Flurzi Commit Personal does not use Commit Score as a credit bureau score and does not make a solely automated lending or credit decision about you. 13.3 The current service is not designed to make a solely automated decision that produces a legal or similarly significant effect on you. If that changes, we will update this Policy and provide the information and safeguards required by law. 14. Security 14.1 We use technical and organisational safeguards designed for sensitive financial information, including access controls, workspace isolation, multi-factor authentication for sensitive actions, encrypted transport, encryption at rest for sensitive fields and stored objects, secure secret management, audit logging, monitoring, backup and recovery controls, security testing and restricted staff access. 14.2 No internet service can promise absolute security. You also play a role by protecting your devices, credentials and MFA recovery material and by reporting suspected compromise promptly. 15. Staff and support access 15.1 Staff are not permitted to casually browse raw financial information. Support access requires a recorded purpose and is time-limited. Access beyond basic account status may require your in-app approval; especially sensitive categories require stronger internal authorisation. 15.2 Support-access activity is audited and is designed to be visible to you in the Privacy Centre. 16. Children Flurzi Commit Personal is intended for adults aged 18 or over. We do not intentionally offer the Personal service described by these documents to children. 17. Changes to this Policy We may update this Policy when our processing, providers, law or product changes. The current version and effective date are shown at the top. Where a change materially affects how we use your personal data, we will provide appropriate notice and, where a new consent is required, ask for it before beginning that processing. 18. Complaints and supervisory authority 18.1 Please contact privacy@flurzicommit.com first if you have a privacy complaint. We will maintain an internal process for receiving, investigating and responding to data-protection complaints. 18.2 You also have the right to complain to the UK Information Commissioner's Office (ICO) if UK data-protection law applies to the processing. Information on how to complain is available from the ICO's official website. If you are in another country, you may also have a right to complain to your local supervisory authority. 19. Contact Flurzi Limited Company number 16640198 Registered office: Suite G04 1 Quality Court, Chancery Lane, London, England, WC2A 1HR Privacy: privacy@flurzicommit.com Support: hello@flurzimobileapp.co.uk