LEGAL
Privacy Policy
Last updated: 10 October 2026
1. Who we are
Fintech Accounting Services (Pty) Ltd, trading as Finly, operates FinlyOS. Finly is our trading name and FinlyOS is our branded finance and practice operating system.
In this policy, “Finly”, “we”, “us”, and “our” refer to Fintech Accounting Services (Pty) Ltd. We help authorised accounting professionals and their clients connect accounting systems, analyse financial information, process approved workflows, and prepare management reports.
Questions or privacy requests can be sent to support@finly.co.za.
2. Information we process
We process account and profile details, the companies a user is permitted to access, OAuth connection details, and accounting information made available by connected services such as QuickBooks Online, Xero, Zoho Books, and approved future providers. Accounting information may include chart-of-account data, financial reports, invoices, bills, customers, suppliers, balances, and related transaction information.
When an authorised practice uses the Payroll module, we also process employee records supplied by that practice, which may include names, employee numbers, identity or passport numbers, tax numbers, dates of birth, employment dates, remuneration, statutory deductions and payslips. This information is processed only to provide payroll services for the relevant employer.
We also process basic technical and security information needed to operate and protect the service, such as timestamps, connection status, error records, and audit information.
3. How we use information
We use information only to authenticate users, maintain authorised data connections, synchronise accounting data, generate dashboards and reports, calculate and record authorised payroll, produce payslips, archive reports when requested, provide support, prevent abuse, and improve the reliability and security of FinlyOS.
We do not sell personal information or use connected accounting information for advertising.
4. QuickBooks and other connected services
Access to connected services is authorised through each provider's OAuth process. Fintech Accounting Services (Pty) Ltd, trading as Finly, receives access and refresh tokens rather than the user's provider password. Tokens are stored server-side and protected using encryption and access controls.
Information obtained from Intuit products is handled in accordance with this policy and the applicable Intuit developer requirements. Users may revoke an integration from the provider or request disconnection from Finly.
5. Service providers and international processing
Finly uses carefully selected infrastructure and service providers to host the application and database, deliver authentication, generate authorised reports, monitor reliability, and store report files. These providers process information only as needed to provide their contracted services and are subject to appropriate confidentiality and security obligations.
Because these providers operate internationally, information may be processed outside South Africa. We take reasonable steps to ensure that cross-border processing receives appropriate protection.
6. Security and retention
We use role-based access, encrypted transport, protected server-side credentials, database security policies, and operational monitoring. No system is completely secure, but we apply reasonable administrative, technical, and organisational safeguards appropriate to the information processed.
We retain account and accounting information only for as long as required to provide the service, meet contractual or legal obligations, resolve disputes, and maintain security records. Information no longer required is deleted or de-identified.
7. Your choices and rights
Subject to applicable law, users may request access to, correction of, or deletion of their personal information, object to certain processing, or request information about how their data is used. A user can also revoke a connected accounting service at any time. We may need to verify identity and authority before acting on a request.
8. Changes to this policy
We may update this policy when the service or legal requirements change. The current version and its effective date will always be available on this page.