Privacy policy
Last updated: 21 August 2026
Fisco is an AI credit controller for agencies. We take a simple position on data: we collect the minimum we need to chase your invoices well, we never sell it, we never train models on it, and money never touches our accounts. This policy explains what we hold, why, and your rights.
Who we are
Fisco is a trading brand of VALENOR CORE DESIGN FZCO ("we", "us"), a free zone company registered in the United Arab Emirates. We are the data controller for information about our customers — the agencies who create accounts — and a data processor for information those agencies bring into the product, such as their clients' contact details and invoices. For questions about this policy or your data, write to legal@fisco.finance; for anything else, support@fisco.finance.
What we collect
Account data. Your name, email address, and sign-in credentials, plus your agency's name, logo, and brand settings.
Accounting data. When you connect your accounting system (such as Xero), we sync contacts, open invoices, amounts, due dates, and payment status. We request the narrowest scopes the integration allows.
Mailbox data. When you connect a sending mailbox (Google Workspace or Microsoft 365), we send chase emails from your address and read replies to those chases so the product can classify them — a promise to pay, a query, a dispute. We do not read unrelated email.
Debtor data. Names, email addresses, invoice history, replies, and payment events for the people your agency invoices. We process this on your instructions, as your processor.
Usage data. Standard logs and privacy-friendly analytics about how the product is used, to keep it reliable and improve it.
How we use it
We use data to run the product: drafting and sending invoice chases in your voice, detecting and classifying replies, tracking promises and payments, generating your digests and reports, and providing support. Legal bases under UK GDPR are performance of our contract with you, our legitimate interest in operating and securing the service, and consent where required for specific integrations.
We never sell personal data. We never use your data — or your clients' data — to train AI models. Chase drafting uses a large-language-model provider under terms that prohibit training on your content; reply content is treated as customer data, logged only for your own audit trail, and encrypted at rest.
Aggregated payment-behaviour insights. We derive anonymised, aggregated statistics from how companies pay — days taken to pay, response to reminders, promises kept — using ledger and chasing events only, never the contents of a mailbox. These power payment-risk warnings for our customers and published benchmarks about how quickly businesses pay their suppliers. A fact about a company is only ever surfaced when it is drawn from at least three separate businesses, and we never disclose which businesses supplied it, their invoice amounts, or that any particular company is a customer of ours. Published benchmarks are aggregate only, with no individual business identifiable.
Who we share it with
We share data only with the subprocessors needed to run the service: cloud hosting and database infrastructure, our billing provider (who acts as merchant of record for your subscription — we never see your full card details), the LLM API used for drafting and classification, transactional email delivery for our own notifications, and error monitoring. Each is bound by a data-processing agreement.
Google user data. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Gmail data is used only to send your chases and read their replies, is never used for advertising, and is never transferred except as necessary to provide those features, for security, or to comply with law.
Payments from your clients to you run on your own payment rails — your Stripe, GoCardless, or bank account. Funds never touch an account we own, and we see only the payment events needed to reconcile invoices.
Retention
Account and ledger data is kept while your account is active and for 30 days after cancellation, then deleted. If you run a free AR health check without becoming a customer, the connected tokens are revoked when the session ends and the report data is deleted within 7 days. OAuth tokens are encrypted at rest and can be revoked by you at any time from the integrations settings or from the provider's own security page.
Security
All data is encrypted in transit and at rest. Access is scoped per agency at the query layer and covered by audit logging. We follow the restricted-scope requirements of the mailbox providers we integrate with, including Google's API Services User Data Policy and its Limited Use requirements.
Where your data is held
The service runs on managed cloud infrastructure, and the subprocessors listed above hold data in their own regions under their data-processing agreements with us. VALENOR CORE DESIGN FZCO is established in the United Arab Emirates, so our own team accesses that data from outside the UK and the European Economic Area.
The UAE is not the subject of a UK or EU adequacy decision. That access is therefore a restricted transfer, and we make it under the standard contractual protections UK and EU data protection law provides for transfers to countries without adequacy, together with the technical controls described above — encryption in transit and at rest, per-agency scoping, and audit logging of every access. You can ask us for the details of the mechanism, and for the name of our UK representative, at legal@fisco.finance.
Your rights
Under UK GDPR you can ask for access to, correction of, or deletion of your personal data; ask us to restrict or object to processing; and ask for a portable copy. Email legal@fisco.finance and we will respond within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office (ico.org.uk). If your data appears in an agency's ledger because they invoice you, contact that agency first — we act on their instructions — though we will help route your request.
Changes
We will update this policy as the product evolves and note the date above when we do. Material changes will be announced by email to account owners before they take effect.