Legal

Privacy Policy

Last updated 2 October 2026

This policy explains how Aspen Point Group AB (org. no. 559377-7716), Sweden (“Aspen Point Group AB”, “we”) handles personal data when you visit our website or use finnMCP (the “Service”). We process personal data in line with the EU General Data Protection Regulation (GDPR).

In short: bookkeeping data stays in Xero and QuickBooks. It passes through finnMCP while a request runs and is not kept by us, apart from an optional cache of up to two minutes that you can switch off.

1. Who is responsible

As controller, Aspen Point Group AB is responsible for personal data about our customers and website visitors: account details, billing, support conversations and usage of the Service.

As processor, we process personal data contained in your accounting data (for example names and contact details of your clients' customers and suppliers) only on your instructions, to provide the Service. For that data, you are the controller. Data processing terms are available on request at support@finnmcp.com.

2. What we collect

  • Account data: name, work email, organisation name, role, and your sign-in method (password hash, email link or Google).
  • Billing data: the organisation's billing contact and subscription details. Card details are collected and stored by Stripe, not by us.
  • Connection data: which Xero organisations and QuickBooks companies you link, their names and identifiers, and encrypted access and refresh tokens for those connections.
  • Activity metadata: for each request from an AI assistant, who made it, which AI client, which company, which tool, the outcome and timing. Not the accounting figures themselves.
  • Accounting data in transit: records and reports read from or written to Xero and QuickBooks while a request runs, an optional short-lived cache, and files you upload or download, which are deleted within minutes.
  • Support and website data: messages you send us, including through the website chat, and basic technical data such as IP address, browser and pages visited.

3. How we use it, and our legal bases

  • To provide and secure the Service, connect your accounting systems and AI clients, and keep the activity log (performance of our contract with you).
  • To bill for the Service and keep accounting records (contract and legal obligation).
  • To send service emails such as sign-in links, invitations, and notices about connections and your trial (contract).
  • To answer support requests and improve the Service (legitimate interests).
  • To detect abuse and enforce our Terms (legitimate interests and legal obligation).

4. AI assistants

The AI assistants you connect (such as Claude, ChatGPT or Microsoft Copilot) are run by their own providers. Data returned by the Service to your AI assistant is processed by that provider under your agreement with them and their privacy policy, not ours. We do not use your data to train AI models and do not share it with AI providers other than through the assistant you connect.

5. Who we share it with

We do not sell personal data. We share it only with:

  • the accounting systems and AI assistants you connect, as you direct;
  • service providers that process data on our behalf, under data processing agreements (below);
  • authorities or advisers where required by law or to protect our rights.
ProviderPurpose
VercelApplication hosting
SupabaseDatabase and temporary file storage
UpstashCache and rate limiting
Trigger.devBackground jobs
StripePayments and invoicing
ResendTransactional email
CrispSupport chat on our website
GoogleSign in with Google, if you choose it

6. International transfers

Some providers process data outside the European Economic Area. Where they do, we rely on an adequacy decision (such as the EU-US Data Privacy Framework) or the European Commission's Standard Contractual Clauses, with additional safeguards where needed.

7. How long we keep it

  • Account and connection data: while your account is active, and deleted within 30 days after it is closed.
  • Access tokens: until you disconnect the company, are removed from the organisation, or close the account.
  • Activity log: 30 days by default; admins can set between 7 and 365 days.
  • Cached accounting data: at most two minutes, or not at all if the cache is switched off.
  • Uploaded and downloaded files: deleted within 15 minutes.
  • Billing records: as long as accounting law requires, currently seven years in Sweden.

8. Security

Data is encrypted in transit. Access and refresh tokens for accounting systems are encrypted at rest. Each person connects companies with their own login, so their permissions in Xero and QuickBooks always apply, and access is revoked with the provider when a company is disconnected or a member is removed. Access to production systems is limited to staff who need it.

9. Cookies

We use strictly necessary cookies to keep you signed in and protect sign-in flows. The support chat on our website (Crisp) sets cookies to keep your conversation; you can avoid them by contacting us by email instead. We do not use advertising cookies.

10. Your rights

You can ask for access to, correction, deletion or a copy of your personal data, and object to or restrict processing based on legitimate interests. Email support@finnmcp.com. If your data is in an account managed by your organisation, we may refer you to its admin. You can also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or your local data protection authority.

11. Changes to this policy

We will update this policy when our practices change and show the date at the top. For material changes we will notify customers by email.

12. Contact

Aspen Point Group AB (org. no. 559377-7716), Sweden. Email support@finnmcp.com.