Privacy Policy

Version 1.1 · Effective 2 September 2026

1. Who we are

Pavitt Public Finance, LLC ("we", "us") operates the service at pfmexpert.net. This policy explains what we collect, why, and your choices. Questions: support@pfmexpert.net.

2. Information we collect

Account data you provide (name, email, job title, organisation, and the pathway and access level chosen at registration). Billing data handled by our payment processor, Stripe (billing address and tax identifiers; card details are entered with Stripe and are not stored by us). Usage data (how you use the training and the Desk). Content you submit, including Desk questions and any documents you upload. Technical data such as authentication cookies and, for security and abuse-prevention, a hashed form of your IP address and your browser user-agent.

3. How we use it

To provide and operate the service; to authenticate you and keep accounts secure; to process payments and applicable taxes; to respond to your questions; to maintain and improve the service; and to comply with law. We rely on performing our contract with you, our legitimate interests in running and securing the service, and your consent where required.

4. Service providers and subprocessors

We share data only as needed with providers that help us operate the service: Supabase (database, authentication, and document storage), Vercel (hosting), Stripe (payments and tax), Resend (transactional email), OpenRouter and the underlying model providers it routes to, including OpenAI (generating Desk answers and creating text embeddings for search), and Mistral AI (optical character recognition, in the EU (Paris) region, used only to read scanned or photographed document uploads; on our paid plan your content is not used to train models and is deleted within 30 days). We use these providers under terms governing their processing for us. Where a provider acts as a processor or subprocessor, we put required data-processing terms in place. For customers for whom we process personal data as a processor under a data processing addendum (DPA), additions or replacements of subprocessors are governed by that DPA, including any required advance notice and opportunity to object.

5. AI processing of your questions and documents

When you use the Desk, your question, any documents you attach, and the source material retrieved to answer it are sent through OpenRouter to a language-model provider to generate a response. For the call that carries your uploaded documents, we instruct OpenRouter to route only to providers that do not retain or train on the content. Scanned or photographed uploads are first read by an optical-character-recognition service (Mistral AI, in the EU (Paris) region) to extract their text; on our paid plan that content is not used to train any model and is deleted within 30 days. We do not use your submitted content to train any model, and we do not sell your data.

6. Retention

We keep account and billing records for as long as your account is active and as required for legal, tax, and accounting purposes, then delete or anonymise them. Desk conversations, answers, and any documents you upload are retained while your account is active so you can refer back to them; you can delete an uploaded document, together with the text extracted from it, at any time from the conversation. Deleted customer content may remain in encrypted managed backups for up to seven days until those backups expire in the ordinary course; backups are used for restoration and security, not as active customer content. Provider-specific transient retention, including the Mistral AI period stated in Section 5, is separate. Acceptance records of the Terms are kept as a record of the agreement.

7. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise them, contact support@pfmexpert.net. You can also manage billing details through the customer portal.

8. International transfers and data location

We and our providers process personal data in the countries needed to operate the service. For the standard shared pfmexpert.net deployment as of the effective date of this policy, the primary application database and document storage are hosted in Mumbai, India, and optical character recognition for scanned or photographed uploads is performed in the European Union (Paris, France). Hosting, model inference, payment, email, and related processing may also occur in the United States, the European Union, and other countries used by the providers named above. Where required, we rely on appropriate safeguards for cross-border transfers. These statements describe the current standard deployment; they are not a contractual data-residency or localisation promise. Any binding customer-specific residency or localisation commitment is stated in a signed Order Form, DPA, or security schedule, and that signed document controls for that customer.

9. Security

We use access controls, encryption in transit and at rest, row-level security in our database, and private, per-account storage for uploaded documents to protect data. No system is perfectly secure; you are responsible for keeping your credentials safe.

10. Children

The service is not directed to children under 13, and we do not knowingly collect their data.

11. Changes

We may update this policy to reflect changes in the service, providers, law, or our data practices. We will revise the version and effective date when we do and provide appropriate notice of a material change. Replacing or adding a provider that performs materially the same function does not, by itself, require reacceptance of the Terms or this policy. We will seek affirmative reacceptance or other consent when a change materially alters the contractual or consented data bargain, or when applicable law requires it. Relevant factors include a new or materially expanded processing purpose, material new data categories, new model-training or other secondary-use rights, materially longer retention, a material change in transfer or residency geography, a material reduction in security commitments, or a material reduction in user rights. Where a DPA applies, its subprocessor notice and objection process applies independently of whether the site Terms or this policy require reacceptance.