Who we are
Fiscana is operated by Innovate360 Lda, a company registered in Portugal. We operate the service at fiscana.pt. When this policy says "we", "us", or "Fiscana", it means Innovate360 Lda.
For any privacy-related questions, you can reach us at legal@fiscana.pt.
We process personal data under Article 6(1)(b) GDPR (performance of a contract) when you create an account and use the service, and Article 6(1)(f) GDPR (legitimate interests) for service improvement and security purposes.
What data we collect
We collect only what we need to provide the service:
- Email address — when you create an account, used to identify you and send transactional emails
- Conversation messages — the questions you ask Fiscana and the responses generated, stored to provide the service and improve accuracy
- Usage data — your credit balance, plan type, session timestamps, and feature usage, used to manage your account and enforce limits
- Payment data — handled directly by Stripe; we do not store card numbers or full payment details
We do not collect your name, phone number, address, or any other personal information beyond what is listed above.
Why we collect it
- To provide the Fiscana service and respond to your questions
- To manage your account, credits, and subscription plan
- To process payments securely via Stripe
- To send transactional emails (account confirmation, credit notifications) via Brevo
- To detect abuse and maintain the security of the service
We do not use your data for advertising. We do not sell your data to any third party, ever.
Data processors
We use the following third-party services to operate Fiscana. Each has a data processing agreement in place:
- Supabase — database and authentication, hosted in the EU (Frankfurt, Germany)
- Anthropic — the Claude AI model that powers Fiscana's responses; EU data processing agreement in place
- Stripe — payment processing; PCI DSS compliant, EU data processing agreement in place
- Brevo — transactional email delivery; EU-based provider, GDPR compliant
No other third parties have access to your personal data.
How long we keep your data
- B2C users (individual accounts) — conversation data is anonymised after 90 days. Account data (email, plan, credits) is retained for as long as your account is active, and for up to 12 months after deletion to comply with legal obligations.
- B2B clients (business accounts) — conversation and usage data is retained for the duration of the contract and for a reasonable period thereafter as required by applicable law.
Cookies
Fiscana uses session cookies only. These are strictly necessary to keep you logged in during a session. We do not use tracking cookies, analytics cookies, or advertising cookies of any kind. No third-party cookies are placed on your device.
Your rights
Under the GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data ("right to be forgotten")
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
To exercise any of these rights, email us at legal@fiscana.pt. We will respond within 30 days. You also have the right to lodge a complaint with the Portuguese data protection authority, the CNPD (cnpd.pt).
Changes to this policy
If we make material changes to this policy, we will notify registered users by email. The current version is always available at fiscana.pt/privacy.
Last updated: May 2026