Security & privacy
Your financial data deserves strong protection. We rely on modern security practices and transparent, plain-language data handling.
At a glance
Data storage
Hosted in the EU (Supabase)
Encryption
TLS in transit, encryption at rest
Isolation
Strict per-workspace separation at the database level
AI training
Your data is never used to train AI models
Deletion
Data deleted after the end of your contract
Subprocessors
Supabase (hosting) and Anthropic (AI)
1. Where is my data stored?
Infrastructure and hosting
Location
Your data is hosted on Supabase in an EU region (managed Postgres, authentication and file storage). Application and static assets are served from the EU.
- Database, authentication and uploaded files all reside in the EU region
- Encrypted backups with point-in-time recovery
AI processing
AI features send only the data needed for the request to Anthropic (the Claude models). Anthropic does not use API data to train its models.
Data minimisation
We send only what an AI step needs and keep the results in your own database.
2. How is my data encrypted?
Technical safeguards
In transit
Data on the wire
TLS 1.3
Modern transport encryption for every connection
HTTPS only
No unencrypted HTTP connections
HSTS
Browsers are forced to use HTTPS
At rest
Data on disk
Encrypted storage
Databases and files are stored encrypted at rest
Encrypted backups
Backups are encrypted as well
Password hashing
Passwords are salted and hashed, never stored in plain text
Account security
Two-factor authentication
Optional TOTP or email one-time codes, with trusted-device support.
Secure password reset
One-time, time-limited links with cryptographically secure tokens.
Brute-force protection
Rate limiting and a bot challenge on sign-in and sign-up.
3. How is my data kept separate from other customers?
Multi-tenancy and isolation
Row-level security (RLS)
We use row-level security directly in the database. Even if a bug slipped into the application, the database physically cannot return another workspace's rows.
SELECT * FROM entities
WHERE workspace_id = [your workspace]
Workspace architecture
- Every workspace is isolated from the others
- UUID-based identifiers — no guessable IDs
- No cross-workspace access — enforced at the database level
- File uploads are stored under access-controlled paths
4. Who has access to my data?
Access control and permissions
Your team members
You control who can access your data. Our role-based system offers:
MLR Ventures (us)
Our access to your data is strictly limited:
- No routine access to your financial data
- We do not read your uploaded documents
- Only for support and with your explicit consent
- Administrative actions are logged in an audit log
5. How is my data protected during AI processing?
Artificial intelligence and privacy
What we guarantee
- 1
No training on your data
Your financial data is never used to train or improve AI models.
- 2
Data minimisation
Only the data an AI step needs is sent to the provider.
- 3
No long-term retention by the provider
Anthropic does not use API inputs or outputs to train its models.
- 4
You stay in control
You decide when AI features run — nothing is processed automatically.
Technical measures
Minimal payloads
Only the data required for a given request is transmitted.
Data processing agreement
Our use of Anthropic is covered by a data processing agreement.
Results stored with you
AI outputs are saved in your own database, not with the provider.
6. What happens to my data when my contract ends?
Data lifecycle and deletion
Cancellation
You cancel your contract or delete your account
Export window (30 days)
You have 30 days to export all of your data (PDF, Excel)
Full deletion
After 30 days, your data is permanently deleted
While your subscription is active
As long as your subscription is active, all of your data is securely stored and available to you at any time.
Important: record retention
IFRS Financial Statements is not a long-term archive. Meeting the statutory record-retention requirements that apply to you is your responsibility. We strongly recommend exporting your documents regularly and keeping them in your own archive.
7. Which subprocessors handle my data?
Third parties and subprocessors
We work with a small set of carefully chosen subprocessors, each under a data processing agreement.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Managed database, authentication and file storage | EU |
| Anthropic | AI text generation and trial-balance mapping (Claude) | US, under a data processing agreement |
| Email delivery provider | Transactional email (magic links, one-time codes, notifications) | EU |
| Payment provider | Subscription billing | EU / global, under a data processing agreement |
We'll notify you by email before any material change to this list.
8. What rights do I have?
Your data-subject rights under the GDPR
Access
Request a copy of the personal data we hold about you
Rectification
Ask us to correct inaccurate data
Erasure
Ask us to delete your data ('right to be forgotten')
Restriction
Ask us to restrict processing of your data
Portability
Export your data in a common format
Objection
Object to certain processing of your data
To exercise your rights, contact:
support@ifrsfinancialstatements.com
9. Frequently asked questions
Other security questions
© 2026 MLR Ventures UG (haftungsbeschränkt). Operated in the EU.