Skip to content
ProductSourcesCapabilitiesDevelopersPricingTrust
Sign InSee how it works

Legal / privacy-2026-08-12

FINA1 Privacy Policy

How FINA1 collects, uses, discloses, retains, and protects personal data.

Terms of Service↗Privacy Policy
Terms of ServicePrivacy PolicyAcceptable Use PolicyCustomer-Directed Source Access TermsSource Access AttestationData Processing AddendumCopyright and Source Rights PolicySubprocessor List

Effective Date: August 12, 2026 Version: privacy-2026-08-12

This Privacy Policy explains how FINA1 collects, uses, discloses, retains, and protects personal data in connection with FINA1 websites, applications, APIs, Model Context Protocol interfaces, support channels, and ZENITH by FINA1 (collectively, the “Service”).

“FINA1,” “we,” “us,” or “our” means the legal entity identified as the service provider on the applicable Order Form, checkout record, invoice, account-acceptance record, or other commercial record governing the relevant account or subscription.

This Policy applies to business and professional users of the Service and to visitors to FINA1-controlled websites. When FINA1 processes personal data solely on behalf of a customer under that customer’s instructions, the customer is the controller or business and FINA1 acts as processor or service provider under the FINA1 Data Processing Addendum.

1. Scope and data roles

FINA1 generally acts as a controller for account administration, security, billing administration, website operations, support, legal compliance, and our own business operations.

FINA1 generally acts as a processor or service provider when a customer instructs us to process personal data through the Service, including certain customer-directed Source operations. Independent third-party Sources may act as separate controllers under their own terms and privacy practices.

This Policy does not govern an independent Source’s own collection or processing practices.

2. Personal data we collect

Depending on how you use the Service, we may collect the following categories.

Account and identity data

  • name;
  • business email address;
  • authentication identifiers;
  • organization name and membership;
  • role and permission information;
  • invitation and account-status information; and
  • account recovery and verification events.

We do not intentionally store plaintext passwords. Authentication credentials are handled through the designated authentication system.

Organization and commercial data

  • organization identifiers;
  • subscription plan and entitlement state;
  • seat assignments;
  • billing contact information;
  • invoice and transaction identifiers;
  • payment status and limited payment metadata received from our payment processor; and
  • tax-related information where required.

When a payment processor collects payment-card information directly, FINA1 does not require the full card number to be submitted to FINA1.

Usage and request metadata

  • request identifier;
  • customer, organization, API-key, or MCP-client identity;
  • Source and operation selected;
  • request status;
  • timestamps and latency;
  • record count;
  • call weight and charge;
  • policy, terms, and attestation versions;
  • source freshness and provenance metadata;
  • storage and cache decisions; and
  • rate-limit, quota, and entitlement events.

Unless a specific product or Order Form expressly provides otherwise, FINA1 does not persist third-party Source response bodies as request history and does not maintain a persistent provider-payload cache.

Security and device data

  • IP address;
  • browser and device information;
  • user-agent information;
  • session and authentication events;
  • security-event metadata;
  • credential creation, rotation, and revocation events;
  • audit events; and
  • diagnostic information reasonably necessary to investigate failures or abuse.

We design logs and exports to exclude secrets, authentication tokens, cookies, credential values, and provider payloads except where temporary access is strictly necessary to investigate a security incident and is otherwise lawful.

Customer-supplied Source credentials

If a customer chooses to bind a credential, token, key, cookie, license reference, or similar access mechanism for a Source, we may process that information in an isolated secret-management system for the limited purpose of executing the customer’s authorized request. Retrieval-capable credentials are encrypted or otherwise protected and are tenant-scoped and revocable. We do not use one customer’s Source credential for another customer.

Support, contact, and communications data

We may collect information you submit in support requests, contact forms, sales communications, feedback, ideas, account-deletion requests, privacy requests, or other communications.

Website and essential technology data

We may use cookies, local storage, or similar technologies that are reasonably necessary for authentication, security, session management, fraud prevention, preferences, and core Service functionality. We do not sell personal data or use the Service for cross-context behavioral advertising. If we introduce non-essential analytics or advertising technologies, we will update this Policy and provide any legally required choices before using them.

3. Sources of personal data

We collect personal data:

  • directly from you;
  • from an organization administrator who invites or manages you;
  • automatically from your browser, device, API client, or use of the Service;
  • from payment, email, authentication, hosting, and infrastructure providers acting for us;
  • from independent Sources when you direct the Service to retrieve information; and
  • from public, professional, or commercial sources where lawful and relevant to operating or securing the Service.

4. How we use personal data

We use personal data to:

  1. provide, operate, authenticate, and administer the Service;
  2. create and manage accounts and organizations;
  3. execute customer-directed Source requests;
  4. enforce entitlements, usage limits, rate limits, and subscriptions;
  5. process and reconcile billing through the designated payment processor;
  6. provide support and respond to communications;
  7. secure the Service, investigate incidents, prevent fraud and abuse, and enforce policies;
  8. maintain provenance, auditability, and request transparency;
  9. improve reliability, performance, accessibility, and usability using appropriately minimized or de-identified data where practicable;
  10. comply with legal obligations, court orders, lawful government requests, sanctions, and export controls;
  11. establish, exercise, or defend legal claims; and
  12. carry out corporate transactions subject to appropriate confidentiality and data-protection safeguards.

We do not use customer-provided Source credentials to create cross-customer profiles or to access a Source outside the customer’s authorized scope.

5. Legal bases for EEA and UK processing

Where the EU GDPR, UK GDPR, or similar law requires a legal basis, FINA1 relies on one or more of the following as appropriate:

  • Contract: processing necessary to provide the Service or take requested pre-contract steps;
  • Legitimate interests: operating, securing, supporting, improving, and protecting the Service and our business, where those interests are not overridden by applicable data-protection rights;
  • Legal obligation: compliance with laws, lawful requests, tax, accounting, sanctions, or regulatory duties;
  • Consent: where we specifically request consent and applicable law requires or permits it; and
  • Legal claims: where processing is necessary to establish, exercise, or defend legal rights.

When FINA1 acts only as a processor, the customer determines the applicable legal basis for its processing.

6. How we disclose personal data

We may disclose personal data to the following categories of recipients.

Service providers and subprocessors

We use service providers for hosting, database and authentication infrastructure, transactional email, payment processing, security, and related operational functions. They may process personal data only for authorized purposes and subject to contractual or legal restrictions appropriate to their role.

Our current material subprocessors are identified in the FINA1 Subprocessor List.

Customer organizations

Organization owners and authorized administrators may access account, membership, usage, security, and billing information associated with their organization, subject to role-based access controls.

Third-party Sources at your direction

When you direct the Service to access a Source, information necessary to perform the request may be transmitted to that Source, such as the requested operation, query parameters, and any authorized customer-bound credential. The Source’s own terms and privacy practices govern its independent processing.

Professional advisers and corporate transactions

We may disclose information to auditors, insurers, attorneys, accountants, financing sources, or transaction counterparties where reasonably necessary and subject to appropriate confidentiality obligations.

Legal, safety, and enforcement disclosures

We may disclose information where we reasonably believe disclosure is required by law or necessary to respond to lawful process, protect rights or safety, investigate fraud or security incidents, enforce the Agreement, or comply with sanctions or export-control obligations.

7. Sale, sharing, targeted advertising, and profiling

FINA1 does not sell personal data for monetary or other valuable consideration and does not share personal data for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws.

FINA1 does not use personal data to make solely automated decisions that produce legal or similarly significant effects about individuals on behalf of FINA1. Customers must not use the Service for prohibited high-impact or consequential decisions in violation of the Acceptable Use Policy.

If our practices materially change, we will update this Policy and provide legally required opt-out mechanisms before the new practice begins.

8. Data retention

FINA1 applies purpose-based retention. Unless a longer period is required by law, necessary for a legal hold, or stated in an applicable Order Form, our baseline retention schedule is:

Data categoryBaseline retention
Account, profile, organization, and membership recordsActive account term, then up to 24 months after closure, except legal-consent and financial records
Terms, policy, attestation, and consent evidence7 years after account or contractual termination
Billing, invoice, tax, and payment reconciliation records7 years after the relevant transaction or longer if required by applicable tax/accounting law
Usage ledger and metering records24 months after the applicable usage period, except records incorporated into billing disputes or legal holds
Request-history metadata13 months, unless a shorter plan-specific period applies or a longer period is necessary for a documented dispute, security event, or legal obligation
Security and audit events24 months, subject to extension for active investigations or legal holds
Support and contact records24 months after resolution or last substantive interaction
Customer-bound Source credentialsUntil revoked, replaced, account termination, or the applicable Source integration is removed; scheduled deletion within 30 days after no longer required, subject to secure-backup lifecycle
Provider response payloadsNo persistent storage by default; transient processing only unless an operation or Order Form expressly authorizes storage
Persistent provider cacheDisabled by default; cache TTL is zero unless an operation or Order Form expressly provides otherwise
Ephemeral authentication and one-time security artifactsThe shortest operational period supported by the relevant security mechanism, then automatic expiry
Routine backups containing deleted recordsRolled out of active backup sets within 35 days, unless preserved for a documented legal or security hold

When data is no longer required, we delete, anonymize, or securely isolate it consistent with technical and legal requirements.

9. Security

We maintain administrative, technical, and organizational safeguards designed to protect personal data based on the nature of the information and risk. These measures include, as appropriate:

  • encryption in transit and at rest through the applicable infrastructure;
  • tenant isolation and row-level authorization controls;
  • role-based access and least privilege;
  • request-scoped service authentication;
  • isolated secret storage for retrievable customer credentials;
  • credential hashing where retrieval is unnecessary;
  • logging and audit controls designed to exclude secrets;
  • secure software-development and dependency-management practices;
  • vulnerability and incident-response processes; and
  • business-continuity and recovery measures appropriate to the Service.

No security program can guarantee absolute security. Customers are responsible for protecting their own accounts, devices, API keys, MCP credentials, and Source credentials.

10. International data transfers

FINA1 and its service providers may process personal data in the United States and other countries where they operate. Where applicable law requires a transfer mechanism, we use an appropriate mechanism such as an adequacy determination, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or International Data Transfer Agreement, or another lawful safeguard.

For customer-controlled processing, the FINA1 Data Processing Addendum specifies the applicable transfer mechanisms.

11. Privacy rights

Depending on applicable law and your relationship with FINA1, you may have rights to:

  • know or access personal data;
  • obtain a portable copy;
  • correct inaccurate personal data;
  • delete personal data;
  • restrict or object to certain processing;
  • withdraw consent where processing is based on consent;
  • opt out of sale, sharing, targeted advertising, or qualifying profiling;
  • limit certain uses of sensitive personal data where applicable;
  • appeal a denied privacy request where applicable; and
  • lodge a complaint with a competent data-protection authority.

Because FINA1 does not sell personal data or share it for cross-context behavioral advertising, there is currently no sale/share activity to opt out of.

If your personal data is controlled by a FINA1 customer and FINA1 processes it only on that customer’s behalf, we may direct your request to the customer or assist the customer in responding.

12. How to exercise privacy rights

You may submit a privacy request through the privacy or legal contact mechanism identified in the Service or the legal/contact section of fina1.com. We may take reasonable steps to verify your identity and authority before fulfilling a request.

Authorized agents may submit requests where permitted by law. We may require evidence of authorization and, where allowed, direct verification from the individual.

We will respond within the period required by applicable law. If applicable law provides a right to appeal, an appeal may be submitted through the same channel and identified as a privacy appeal.

We will not unlawfully discriminate against a person for exercising applicable privacy rights.

13. California disclosures

For California residents, the categories described in Section 2 correspond generally to identifiers, customer records, commercial information, internet or electronic-network activity, professional information, and in limited circumstances sensitive personal information such as account credentials.

During the preceding 12 months, FINA1’s intended business practices are those described in this Policy. FINA1 does not sell personal information or share personal information for cross-context behavioral advertising. FINA1 uses and discloses sensitive personal information only for purposes reasonably necessary to provide, secure, administer, and comply with law in connection with the Service, unless we provide a different legally required notice before another use.

Where California law applies, consumers may exercise applicable rights to know, access, correct, delete, and obtain information about disclosure practices as described above.

14. Florida and other U.S. state privacy rights

Where the Florida Digital Bill of Rights or another U.S. state comprehensive privacy law applies to FINA1’s processing, FINA1 will provide the rights, disclosures, response process, appeal process, and other protections required by that law. This Policy is intended to provide a unified baseline and does not reduce rights available under applicable law.

15. Children

The Service is not directed to children under 18. FINA1 does not knowingly offer accounts to children or knowingly collect personal data from children for their own use of the Service. If we learn that personal data was collected from a child contrary to this Policy, we will take appropriate steps to delete or otherwise address it.

16. Customer responsibility for third-party personal data

Customers may direct the Service to process information that includes personal data obtained from a Source. The customer is responsible for determining whether it has lawful authority to request, receive, use, store, disclose, or otherwise process that information. FINA1’s technical ability to retrieve or normalize data is not a determination that a customer’s use is legally permitted.

17. Changes to this Policy

We may update this Policy as our practices, law, or the Service change. The current version will identify its effective date. For material changes, we will provide reasonable notice through the Service, account email, or another durable channel where required or appropriate.

18. Contact

Privacy questions, requests, and complaints may be submitted through the privacy/legal contact method identified in the Service or in the legal/contact section of fina1.com. Formal notices should identify the requester, relevant account or organization if applicable, the nature of the request, and a reliable method for response.

FINA1 is the public-facing technology company. ZENITH by FINA1 is its flagship secure API and MCP platform.

Production. Production customer identity and control-plane infrastructure are available. Billing and Source execution remain independently policy- and configuration-gated.

Explore

ProductSourcesCapabilitiesPricing

Build

DevelopersMCPIdeas & RequestsRequest an API

Assurance

SecurityTrustStatusResponsible Disclosure

FINA1

AboutContactPrivacyTermsAcceptable UseSource Access Terms
© 2026 FINA1. Controlling legal documents effective August 12, 2026.Every Source. One Zenith.