Wipfin

Privacy Policy

Last Updated: September 8, 2026

WIPFIN (“WIPFIN,” “we,” “us,” or “our”) respects the privacy of individuals and the confidentiality of information entrusted to us by our clients.

This Privacy Policy explains how WIPFIN collects, uses, discloses, retains, and protects personal information when you visit our website, contact us, request information, engage with our Services, or otherwise interact with us.

Where WIPFIN processes personal information or other data on behalf of a business client in connection with our finance, accounting, services, or automation Services, that processing is also governed by the applicable client agreement and, where applicable, a Data Processing Agreement (“DPA”).

1. Information We Collect

Depending on how you interact with WIPFIN, we may collect the following categories of information.

1.1 Contact and Business Information

When you contact us, request a consultation, schedule a demonstration, submit an inquiry, or communicate with us, we may collect:

  • Name;
  • Business email address;
  • Business telephone number;
  • Job title or professional role;
  • Company or organization name;
  • Business address;
  • Information about your business requirements; and
  • Other information you voluntarily provide.

1.2 Client and Financial Information

In providing finance and accounting Services, clients may provide WIPFIN with business and financial information, which may include:

  • Accounting records;
  • Accounts payable information;
  • Accounts receivable information;
  • Invoices and transaction information;
  • General ledger information;
  • Financial statements;
  • Budgeting and forecasting information;
  • Vendor and customer information;
  • Employee-related information where required for the Services;
  • Business and operational information; and
  • Other information specified in the applicable client agreement.

Client information remains owned by the applicable client. WIPFIN processes such information only for authorized purposes in accordance with the applicable client agreement and DPA, where applicable.

1.3 Website and Technical Information

When you visit our website, we may automatically collect certain technical information, including:

  • IP address;
  • Browser type and version;
  • Device and operating-system information;
  • Pages viewed;
  • Referring URLs;
  • Approximate location derived from technical information;
  • Date and time of access; and
  • Information collected through cookies and similar technologies.

1.4 Communications

We may collect and retain information contained in emails, forms, chat messages, consultation requests, support requests, and other communications you send to us.

2. How We Use Information

WIPFIN may use information to:

  • Respond to inquiries and requests;
  • Schedule consultations and demonstrations;
  • Provide information about our Services;
  • Establish and manage business relationships;
  • Deliver finance, accounting, FP&A, services, and automation Services;
  • Process Client Data according to authorized instructions;
  • Operate, maintain, secure, and improve our website and systems;
  • Monitor and improve service quality;
  • Detect and prevent fraud, misuse, unauthorized access, and security threats;
  • Communicate service-related information and updates;
  • Send marketing communications where legally permitted and, where required, with appropriate consent;
  • Comply with legal, regulatory, contractual, tax, accounting, and compliance requirements; and
  • Establish, exercise, or defend legal rights.

We will not use Client Data for unrelated purposes without appropriate authorization, except where required or permitted by applicable law.

3. Legal Bases for Processing

Where applicable privacy laws require a legal basis for processing personal information, WIPFIN may rely on:

  • Performance of a contract;
  • Taking steps at an individual's request before entering into a contract;
  • Compliance with a legal or regulatory obligation;
  • WIPFIN's legitimate interests, where those interests are not overridden by applicable rights;
  • Consent, where required; or
  • Another lawful basis permitted by applicable law.

The applicable legal basis depends on the type of information and the circumstances of the processing.

4. Client Data and Processing on Behalf of Clients

Where WIPFIN processes personal information on behalf of a client, WIPFIN will process that information according to the client's documented instructions and the applicable client agreement and DPA.

Depending on the circumstances and applicable law, the client may act as the data controller or business, while WIPFIN may act as a data processor, service provider, or equivalent role.

WIPFIN does not sell Client Data.

WIPFIN does not use Client Data for unrelated advertising or marketing purposes unless expressly authorized by the client or otherwise permitted by applicable law.

5. How We Share Information

WIPFIN does not sell personal information.

We may share information with the following categories of recipients where reasonably necessary and legally permitted:

Service Providers and Subprocessors

We may use third-party providers that support our business operations or delivery of Services, including providers of:

  • Cloud hosting and infrastructure;
  • Information technology;
  • Cybersecurity;
  • Communications;
  • Analytics;
  • Productivity and collaboration;
  • Accounting and finance technology; and
  • Other technology-enabled services.

Where third parties process personal information on our behalf, we seek to establish appropriate contractual confidentiality, security, and data-protection obligations.

Professional Advisors

We may disclose information to lawyers, accountants, auditors, insurers, consultants, and other professional advisors where reasonably necessary.

Legal and Regulatory Authorities

We may disclose information to courts, regulators, government authorities, law-enforcement agencies, or other parties where required by law or reasonably necessary to comply with legal obligations.

Corporate Transactions

Information may be transferred in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, subject to applicable legal requirements and appropriate protections.

With Authorization

We may disclose information where you or the relevant client has provided appropriate authorization or consent.

6. Confidentiality and Data Security

WIPFIN recognizes that finance and accounting Services may involve highly confidential business and financial information.

We maintain administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, disclosure, alteration, and destruction.

Depending on the nature and sensitivity of the information, our safeguards may include:

  • Role-based access controls;
  • Access based on business need;
  • Authentication and credential-management controls;
  • Confidentiality obligations for personnel;
  • Secure information-transfer practices;
  • Security monitoring and operational controls;
  • Backup and recovery measures; and
  • Policies and procedures relating to information security and data protection.

We periodically review security practices in light of applicable risks and the nature of the Services.

No electronic transmission, storage system, or online service can be guaranteed to be completely secure.

If a security incident occurs that materially affects personal information and notification is required by applicable law or contract, WIPFIN will provide notification in accordance with those requirements.

Security Assurance

Where WIPFIN maintains independent certifications, attestations, or assurance reports, relevant information may be made available to clients subject to appropriate confidentiality and access requirements.

Any specific certification or assurance statement published by WIPFIN must accurately reflect the certification or report currently held by WIPFIN.

7. Data Retention

WIPFIN retains information only for as long as reasonably necessary to:

  • Provide Services;
  • Fulfill contractual obligations;
  • Maintain appropriate business and accounting records;
  • Comply with legal, tax, regulatory, and compliance requirements;
  • Resolve disputes;
  • Enforce agreements; and
  • Protect WIPFIN's legitimate business interests.

Retention periods for Client Data are generally governed by the applicable client agreement, DPA, client instructions, and applicable legal or regulatory requirements.

When information is no longer required, WIPFIN will delete, return, anonymize, or securely dispose of it as appropriate and as required by law or contract.

8. International Data Transfers

WIPFIN may operate and provide Services across multiple countries. As a result, information may be processed or stored outside the country in which it was originally collected.

Where applicable law requires safeguards for international transfers, WIPFIN will use legally recognized transfer mechanisms, which may include:

  • Adequacy decisions;
  • Standard Contractual Clauses;
  • Other contractual safeguards; or
  • Other mechanisms recognized under applicable law.

9. Cookies and Similar Technologies

Our website may use cookies and similar technologies to:

  • Enable essential website functionality;
  • Remember preferences;
  • Understand website usage;
  • Analyze website performance; and
  • Support marketing activities where permitted.

Where required by applicable law, WIPFIN will obtain consent before using non-essential cookies.

You may also control cookies through your browser or device settings. Disabling certain cookies may affect website functionality.

10. Marketing Communications

Where permitted by applicable law, WIPFIN may send information about our Services, industry insights, events, or other business communications.

You may unsubscribe from marketing communications at any time using the unsubscribe option provided in the communication or by contacting us.

Opting out of marketing communications will not prevent WIPFIN from sending necessary service, contractual, security, or legal communications.

11. Your Privacy Rights

Depending on your location and applicable law, you may have rights regarding your personal information, including the right to:

  • Request access to personal information;
  • Request correction of inaccurate information;
  • Request deletion of personal information;
  • Request restriction of processing;
  • Object to certain processing;
  • Request data portability;
  • Withdraw consent where processing is based on consent;
  • Opt out of direct marketing; and
  • Lodge a complaint with the applicable data protection authority.

These rights may be subject to legal limitations and exceptions.

If WIPFIN processes your personal information on behalf of one of our clients, you may need to submit your request directly to that client. Where appropriate, WIPFIN will assist the client in responding to the request.

12. California Privacy Rights

Where applicable to WIPFIN's activities, California residents may have additional rights under applicable California privacy law.

These may include rights relating to access, correction, deletion, and information concerning the collection and use of personal information.

WIPFIN does not sell personal information as defined under applicable California privacy law.

Requests may be submitted using the contact information provided below.

WIPFIN will not discriminate against individuals for exercising applicable privacy rights.

13. European Economic Area and United Kingdom

Where applicable GDPR or UK GDPR requirements apply, individuals may have additional rights relating to their personal information, including rights to access, correction, deletion, restriction, objection, portability, and withdrawal of consent where applicable.

Individuals may also have the right to lodge a complaint with the relevant supervisory authority.

Where WIPFIN acts as a processor on behalf of a client, requests relating to Client Data should generally be directed to the relevant client.

14. India Privacy Rights

Where India's applicable data protection laws apply to the processing of personal information, WIPFIN will handle personal information in accordance with applicable requirements, including applicable obligations concerning notice, consent where required, security safeguards, retention, and individual rights.

Requests may be submitted using the contact information provided below.

15. Children's Privacy

The WIPFIN website and Services are intended for business and professional use and are not directed toward children under 18.

WIPFIN does not knowingly collect personal information directly from children for the purpose of providing its business Services.

16. Third-Party Websites and Services

Our website may contain links to third-party websites, applications, or services.

Those third parties may have their own privacy policies and terms. WIPFIN is not responsible for the privacy or security practices of third parties that it does not control.

17. Complaints and Privacy Concerns

If you have a question, concern, or complaint regarding how WIPFIN handles personal information, we encourage you to contact us first so that we can investigate and address the matter.

You may also have the right to contact the relevant data protection or regulatory authority in your jurisdiction.

18. Changes to This Privacy Policy

WIPFIN may update this Privacy Policy from time to time.

When material changes are made, we will update the "Last Updated" date and, where appropriate, provide additional notice.

The latest version will be available on the WIPFIN website.

19. Contact Us

For privacy questions, data-protection requests, or concerns, please contact:

WIPFIN
Contact Email: info@wipfin@gmail.com
Registered Business Address: Sakthi Tower Ln, Anna Salai, Thousand Lights, Chennai, Tamil Nadu 600002
Country: India

Where WIPFIN processes information on behalf of a client, individuals may also contact the relevant client organization regarding their personal information.


Important Notice

This Privacy Policy is intended to provide a clear description of WIPFIN's privacy practices. It should be reviewed and approved by qualified legal counsel before publication to ensure that it accurately reflects WIPFIN's actual operations, security practices, contractual commitments, and legal obligations in the countries where WIPFIN operates or provides Services.