Security & privacy

Security & privacy

Your financial data deserves strong protection. We rely on modern security practices and transparent, plain-language data handling.

GDPR-aligned
EU hosting
TLS 1.3 in transit
Row-level security

At a glance

Data storage

Hosted in the EU (Supabase)

Encryption

TLS in transit, encryption at rest

Isolation

Strict per-workspace separation at the database level

AI training

Your data is never used to train AI models

Deletion

Data deleted after the end of your contract

Subprocessors

Supabase (hosting) and Anthropic (AI)

1. Where is my data stored?

Infrastructure and hosting

Location

Your data is hosted on Supabase in an EU region (managed Postgres, authentication and file storage). Application and static assets are served from the EU.

  • Database, authentication and uploaded files all reside in the EU region
  • Encrypted backups with point-in-time recovery

AI processing

AI features send only the data needed for the request to Anthropic (the Claude models). Anthropic does not use API data to train its models.

Data minimisation
We send only what an AI step needs and keep the results in your own database.

2. How is my data encrypted?

Technical safeguards

In transit

Data on the wire

TLS 1.3

Modern transport encryption for every connection

HTTPS only

No unencrypted HTTP connections

HSTS

Browsers are forced to use HTTPS

At rest

Data on disk

Encrypted storage

Databases and files are stored encrypted at rest

Encrypted backups

Backups are encrypted as well

Password hashing

Passwords are salted and hashed, never stored in plain text

Account security

Two-factor authentication

Optional TOTP or email one-time codes, with trusted-device support.

Secure password reset

One-time, time-limited links with cryptographically secure tokens.

Brute-force protection

Rate limiting and a bot challenge on sign-in and sign-up.

3. How is my data kept separate from other customers?

Multi-tenancy and isolation

Row-level security (RLS)

We use row-level security directly in the database. Even if a bug slipped into the application, the database physically cannot return another workspace's rows.

-- every query is filtered automatically:
SELECT * FROM entities
WHERE workspace_id = [your workspace]

Workspace architecture

  • Every workspace is isolated from the others
  • UUID-based identifiers — no guessable IDs
  • No cross-workspace access — enforced at the database level
  • File uploads are stored under access-controlled paths

4. Who has access to my data?

Access control and permissions

Your team members

You control who can access your data. Our role-based system offers:

Admin
Full access; can manage team members
Preparer
Can create and edit financial statements
Reviewer
Can review and comment, no edits
Approver
Can give final approval and lock
Client
Limited access for client contributions

MLR Ventures (us)

Our access to your data is strictly limited:

  • No routine access to your financial data
  • We do not read your uploaded documents
  • Only for support and with your explicit consent
  • Administrative actions are logged in an audit log

5. How is my data protected during AI processing?

Artificial intelligence and privacy

What we guarantee

  • 1

    No training on your data

    Your financial data is never used to train or improve AI models.

  • 2

    Data minimisation

    Only the data an AI step needs is sent to the provider.

  • 3

    No long-term retention by the provider

    Anthropic does not use API inputs or outputs to train its models.

  • 4

    You stay in control

    You decide when AI features run — nothing is processed automatically.

Technical measures

  • Minimal payloads

    Only the data required for a given request is transmitted.

  • Data processing agreement

    Our use of Anthropic is covered by a data processing agreement.

  • Results stored with you

    AI outputs are saved in your own database, not with the provider.

6. What happens to my data when my contract ends?

Data lifecycle and deletion

1

Cancellation

You cancel your contract or delete your account

2

Export window (30 days)

You have 30 days to export all of your data (PDF, Excel)

3

Full deletion

After 30 days, your data is permanently deleted

While your subscription is active
As long as your subscription is active, all of your data is securely stored and available to you at any time.

Important: record retention
IFRS Financial Statements is not a long-term archive. Meeting the statutory record-retention requirements that apply to you is your responsibility. We strongly recommend exporting your documents regularly and keeping them in your own archive.

7. Which subprocessors handle my data?

Third parties and subprocessors

We work with a small set of carefully chosen subprocessors, each under a data processing agreement.

ProviderPurposeLocation
SupabaseManaged database, authentication and file storageEU
AnthropicAI text generation and trial-balance mapping (Claude)US, under a data processing agreement
Email delivery providerTransactional email (magic links, one-time codes, notifications)EU
Payment providerSubscription billingEU / global, under a data processing agreement

We'll notify you by email before any material change to this list.

8. What rights do I have?

Your data-subject rights under the GDPR

Art. 15

Access

Request a copy of the personal data we hold about you

Art. 16

Rectification

Ask us to correct inaccurate data

Art. 17

Erasure

Ask us to delete your data ('right to be forgotten')

Art. 18

Restriction

Ask us to restrict processing of your data

Art. 20

Portability

Export your data in a common format

Art. 21

Objection

Object to certain processing of your data

To exercise your rights, contact:
support@ifrsfinancialstatements.com

9. Frequently asked questions

Other security questions

Security concerns or questions?

Found a vulnerability or have further questions about our security measures? We take every report seriously and aim to respond within one business day.

© 2026 MLR Ventures UG (haftungsbeschränkt). Operated in the EU.