Privacy

Privacy policy

Last updated: 27 August 2026

Fisco runs pre-close diligence for funds and their counterparties. That means we hold confidential documents belonging to companies that are not our customers, so we take a narrow position: we collect what a deal needs, we never sell it, we never train models on it, we never pool it across customers, and every access is logged. This policy explains what we hold, why, and your rights.

01

Who we are

VALENOR CORE DESIGN FZCO (trading as Fisco) ("we", "us"), a free zone company registered in the United Arab Emirates, is the data controller for information about our customers — the funds, firms and foundations who create accounts — and a data processor for everything those customers bring into a deal, including documents and contact details belonging to their counterparties. For questions about this policy or your data, write to legal@fisco.finance; for anything else, support@fisco.finance.

02

What we collect

Account data. Your name, email address and sign-in credentials, plus your firm's name, logo and settings.

Deal and counterparty data. The companies and people on a deal — names, roles, email addresses — together with the requirement list, its state, and the record of who accepted what and when. We process this on your instructions, as your processor.

Documents. Whatever a counterparty sends, or you upload, against a deal: statutory and management accounts, bank statements, contracts, board minutes, corporate records. These are stored privately — never on a public URL — under a key that begins with your workspace, and are readable only through an authenticated request. We extract text from them so the product can match evidence to requirements and answer questions without asking anyone twice.

Mailbox data. When you connect a sending mailbox (Google Workspace or Microsoft 365), we send your requests from your own address and read replies to those threads so the product can file the attachments and classify the answer. We do not read unrelated email.

Linked folders and connections. Where you point us at a data room or folder, or a counterparty grants access to an accounting system, we read what that grant allows. Access granted by a counterparty is scoped to one deal, carries a stated purpose, and can be revoked by either side at any time.

Usage data. Standard logs and privacy-friendly analytics about how the product is used, to keep it reliable and improve it.

03

If you are a counterparty

If you reached a Fisco page from a link someone sent you, you are a counterparty on their deal. You have no account with us and no contract with us, and the firm that sent you the link decides what happens to what you send.

What you send goes to that firm. We store it on their behalf, privately, and use it only to match it against the items they have asked you for and to answer questions on that deal. We do not use it for anything else, we do not share it with any other customer, and we do not train models on it.

Your link is revocable. Once it is revoked it stops working immediately and cannot be reinstated — a new one has to be issued. The list you see never shows items owed by other parties on the same deal, and never shows the firm's internal work.

To ask what is held about you, contact the firm that sent you the link, since we act on their instructions. Write to legal@fisco.finance if you cannot reach them and we will help route the request.

04

How we use it

We use data to run the product: keeping the requirement list current, reading and classifying what arrives, drafting requests and follow-ups for a person to approve, answering questions from what is already on file, and producing the record of who accepted what. Legal bases under UK GDPR are performance of our contract with you, our legitimate interest in operating and securing the service, and consent where a specific integration requires it.

We never sell personal data. We never use your data, or your counterparties' data, to train AI models. Drafting and classification use a large-language-model provider under terms that prohibit training on your content; document text and reply content are treated as customer data, logged only for your own audit trail, and encrypted at rest.

Nothing is pooled across customers. We derive no cross-customer statistics, benchmarks or risk scores from deal files, and we publish none. A document a borrower gave one fund is used for that fund's deal and for nothing else.

05

Who we share it with

We share data only with the subprocessors needed to run the service: cloud hosting, database and blob storage, our billing provider (who acts as merchant of record for your subscription — we never see your full card details), the LLM API used for classification and drafting, transactional email delivery for our own notifications, and error monitoring. Each is bound by a data-processing agreement.

Google user data. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Gmail data is used only to send your requests, read the replies to those threads, and file what is attached to them. It is never used for advertising, never used to train generalised AI models, and never transferred except as necessary to provide those features, for security, or to comply with law.

06

Retention

Account and deal data is kept while your account is active and for 30 days after cancellation, then deleted. Documents are deleted with the deal they belong to.

Because a diligence file often has to outlive the decision it supported, you can set a longer retention period per deal, and you can delete a deal and its documents at any time without waiting for a cancellation. OAuth tokens are encrypted at rest and can be revoked by you — or by the counterparty who granted them — at any time, from settings or from the provider's own security page.

07

Security

All data is encrypted in transit and at rest. Documents are stored privately and are never reachable by URL alone. Access is scoped per workspace at the query layer, and links shared with a counterparty are unguessable, never indexed, and revocable.

Every acceptance carries who made it and when, and every access is covered by audit logging. We follow the restricted-scope requirements of the providers we integrate with, including Google's API Services User Data Policy and its Limited Use requirements.

08

Where your data is held

The service runs on managed cloud infrastructure, and the subprocessors listed above hold data in their own regions under their data-processing agreements with us. VALENOR CORE DESIGN FZCO is established in the United Arab Emirates, so our own team accesses that data from outside the UK and the European Economic Area.

The UAE is not the subject of a UK or EU adequacy decision. That access is therefore a restricted transfer, and we make it under the standard contractual protections UK and EU data protection law provides for transfers to countries without adequacy, together with the technical controls described above — encryption in transit and at rest, per-workspace scoping, and audit logging of every access. You can ask us for the details of the mechanism, and for the name of our UK representative, at legal@fisco.finance.

09

Your rights

Under UK GDPR you can ask for access to, correction of, or deletion of your personal data; ask us to restrict or object to processing; and ask for a portable copy. Email legal@fisco.finance and we will respond within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office (ico.org.uk). If your data is in a deal file because a firm is running diligence on you, contact that firm first — we act on their instructions — though we will help route your request.

10

Changes

We will update this policy as the product evolves and note the date above when we do. Material changes will be announced by email to account owners before they take effect.