K-Φ

Privacy Policy

Last updated 25 August 2026 · K-phi Enterprise Kft.

K-Φ is a treasury and financial planning application. It reads accounting data from systems you already use, turns it into statements and cash forecasts, and shows them back to you. This page describes what it holds, where, and for how long.

Who we are

K-phi Enterprise Kft., Hungary. Contact: privacy@k-phi.com. For users in the EEA and UK, we act as a data processor for the accounting data you import, and as a controller for your account details.

What we collect

Account detailsEmail address, name, organisation, role. Supplied by you or your administrator.
Accounting dataGeneral ledger entries, chart of accounts, company name and fiscal year, and analytic dimensions where your system carries them. Imported from a connected accounting system or uploaded by you as a file.
Connection credentialsOAuth access and refresh tokens for a connected accounting system, plus the identifier of the company you authorised.
Operational logsTimestamps, request paths, error messages, and the identifier of the tenant. Used to run and debug the service.

We do not collect payment card data. Payments, where applicable, are handled by a payment processor that never routes card details through K-Φ.

What we do not do

How it is protected

Where it is held

Data is hosted with our cloud provider in the European Union or the United States, depending on the region you signed up in. Transfers out of the EEA, where they occur, rely on the European Commission's standard contractual clauses.

How long we keep it

Connection credentialsDeleted when you disconnect the accounting system, or when the account is closed. Disconnecting takes effect immediately and no further data is fetched.
Imported accounting dataKept while your account is active, because it is the substance of the service. Deleted within 30 days of account closure, or sooner on request.
Account detailsDeleted within 30 days of account closure, except where we must keep records for tax or accounting law.
Operational logsRetained up to 90 days.

You may disconnect an accounting system at any time, from K-Φ or from within QuickBooks or Xero. Disconnecting stops all further access; it does not by itself delete data already imported, which you can remove from within the application or by asking us.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Write to privacy@k-phi.com and we will respond within 30 days. Where we process accounting data on behalf of your organisation, requests about that data are best directed to your organisation first.

Analysis without an account (AI assistants)

K-Φ publishes an MCP connector, so an AI assistant such as Claude can run an analysis on an accounting export without you creating an account. This path behaves differently from the rest of the service, and the differences are set out here rather than left to be inferred.

What is collectedOnly the accounting export you provide for that analysis: the ledger, balance or FEC content itself. No email address, no name, no account. We do not ask who you are and we do not attempt to find out.
Where it goes firstYou supply the file to the assistant, not to us. It therefore passes through your AI provider — Anthropic, if you use Claude — under that provider's own privacy terms, before it reaches K-Φ. We do not control that step, and this policy does not cover it.
How it is heldEach analysis gets its own dedicated database, named MCP-… and separate from every other tenant's, exactly as a customer account would be. It has no user attached, so nobody can sign in to it.
Who can see itThe answer returned to the assistant, and a personal link valid for 24 hours that opens the analysis read-only. Anyone holding that link can view the figures for as long as it is valid, so treat it as you would a shared document link. The session it opens cannot change anything.

It is deleted within 24 hours. A sweep runs hourly and removes the whole store — the database schema is dropped, not merely unlinked — along with the tenant record. Nothing is retained for training, benchmarking or analytics. If the deletion fails for any reason, the record is kept and retried on the next sweep rather than left orphaned.

Unless you keep it. If you confirm your email address from the analysis page, that database stops being temporary and becomes your account: the 30-day free period begins, and everything above in this policy — retention, your rights, deletion on request — applies to it from that point. Confirming the address is the only way anything from this path is kept, and the only point at which we learn who you are.

Sub-processors

We use a small number of providers to run the service: cloud hosting, error monitoring, email delivery, payment processing, and an AI model provider for optional assistive features. Each is bound by contract to protect the data and to process it only on our instructions. A current list is available on request.

Changes

If we change this policy in a way that materially affects you, we will say so in the application before the change takes effect.