Skip to main content
FYNRA
FYNRA
0%
FYNRA LogoFYNRA

Privacy Policy

Effective Date: April 8, 2026  |  Last Updated: April 8, 2026

FYNRA Consulting Inc. ("FYNRA," "we," "us," or "our") operates the website fynra.ai and related client portal services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website, use our client portal, or otherwise interact with us.

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use our Services.

1. Information We Collect

1.1 Information You Provide Directly

  • Contact Form Submissions: First name, last name, email address, phone number (optional), and message content when you submit our contact form.
  • Account Registration: Email address used for magic-link authentication when accessing our client portal.
  • Payment Information: Billing details processed through Stripe, Inc. We do not directly store credit card numbers, CVVs, or full payment card data on our servers. Stripe handles all payment processing in compliance with PCI-DSS Level 1.
  • Consultation Bookings: Name, email, and scheduling preferences when you book through our Calendly integration.
  • Client Portal Activity: Documents you upload, support tickets you submit, and communications within the portal.
  • Correspondence: Any information you provide when contacting us via email or other communication channels.

1.2 Information Collected Automatically

  • Device & Browser Data: IP address, browser type and version, operating system, device identifiers, screen resolution, and language preferences.
  • Usage Data: Pages visited, time and date of visits, time spent on pages, click patterns, referring URLs, and navigation paths.
  • Cookies & Similar Technologies: We use cookies, local storage, and similar technologies as described in our Cookie Policy.
  • Log Data: Server logs that record requests made to our website, including timestamps, HTTP methods, response codes, and user agents.

2. How We Use Your Information

We process your personal information for the following purposes:

  • Service Delivery: To respond to your inquiries, provide our consulting services, manage your client account, process payments, and fulfill our contractual obligations.
  • Communication: To send you service-related notifications, respond to your messages, and provide customer support.
  • Security & Fraud Prevention: To protect against unauthorized access, detect fraudulent activity, and maintain the security of our Services.
  • Website Improvement: To analyze usage patterns, diagnose technical issues, and improve the functionality and user experience of our website and portal.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.

We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects.

3. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:

  • Consent: Where you have given explicit consent (e.g., submitting a contact form, accepting cookies).
  • Contract Performance: Where processing is necessary to perform our contract with you (e.g., providing client portal access and services).
  • Legitimate Interests: Where processing is necessary for our legitimate business interests (e.g., website security, service improvement), provided these do not override your fundamental rights.
  • Legal Obligation: Where processing is required to comply with applicable law.

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share your information with the following categories of recipients, solely to operate and improve our Services:

Service ProviderPurposeData Shared
Supabase (Postgres)Database hosting & authenticationAccount data, form submissions, portal data
VercelWebsite hosting & CDNIP addresses, request logs
StripePayment processingBilling details, transaction data
CalendlyConsultation schedulingName, email, scheduling preferences
ResendTransactional email deliveryEmail addresses, notification content
UpstashRate limitingHashed IP addresses

We may also disclose information when required by law, court order, or governmental authority, or when necessary to protect our rights, safety, or property.

5. Cookies & Tracking Technologies

We use cookies and similar technologies to operate our website and provide our Services. For detailed information about the cookies we use, their purposes, and how to manage your preferences, please see our Cookie Policy.

When you first visit our website, you will be presented with a cookie consent banner that allows you to accept or decline non-essential cookies. Essential cookies required for the website to function cannot be disabled.

6. Data Retention

  • Contact Form Submissions: Retained for up to 3 years from the date of submission, or until you request deletion.
  • Client Portal Data: Retained for the duration of the client relationship and for 5 years thereafter for legal and accounting purposes.
  • Payment Records: Retained as required by applicable tax and financial regulations (typically 7 years).
  • Server Logs: Automatically deleted after 90 days.
  • Cookies: See our Cookie Policy for specific retention periods per cookie type.

7. Data Security

We implement industry-standard technical and organizational measures to protect your personal information, including:

  • Encryption of data in transit via TLS/SSL
  • Encryption of sensitive data at rest (AES-256)
  • Secure authentication via magic-link (passwordless) to reduce credential-based attack vectors
  • Row-Level Security (RLS) policies in our database ensuring clients can only access their own data
  • Rate limiting on all public endpoints to prevent abuse
  • Regular security audits of our codebase and infrastructure
  • Strict access controls limiting employee access to personal data on a need-to-know basis

While we take reasonable precautions to protect your data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security but are committed to promptly addressing any data breach in accordance with applicable law.

8. Your Privacy Rights

8.1 Rights Under GDPR (EEA/UK Residents)

If you are in the EEA or UK, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete personal data
  • Erase your personal data ("right to be forgotten")
  • Restrict processing of your personal data
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time for consent-based processing
  • Lodge a complaint with your local data protection authority

8.2 Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Delete your personal information
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of personal information (we do not sell your data)
  • Non-discrimination for exercising your privacy rights

In the preceding 12 months, we have not sold any personal information, nor have we shared personal information for cross-context behavioral advertising purposes.

8.3 How to Exercise Your Rights

To exercise any of the above rights, please contact us at davit@fynra.ai. We will respond to your request within 30 days (or sooner if required by applicable law). We may ask you to verify your identity before processing your request.

9. International Data Transfers

Our Services are hosted in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required by applicable law.

10. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will promptly delete that information. If you believe a child has provided us with personal information, please contact us at davit@fynra.ai.

11. Third-Party Links

Our website may contain links to third-party websites, services, or applications that are not operated by us (e.g., Calendly, Stripe, social media platforms). We are not responsible for the privacy practices of these third parties. We encourage you to review their respective privacy policies before providing them with any personal information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by law, provide additional notice (such as a banner on our website or an email notification). Your continued use of our Services after any changes indicates your acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

FYNRA Consulting Inc.

Email: davit@fynra.ai

Website: fynra.ai