Data and Processing Inventory

Effective and last updated: July 21, 2026.

This public inventory summarizes GlacialBooks data flows. It complements the more detailed operational record of processing activities maintained by FinArctic LLC.

Processing inventory

Category

Sources

Purposes

Legal basis

Recipients

Retention

Account and identity

User, Clerk, organization administrator

Authentication, account management, membership, security

Contract; legitimate interests; legal obligation

Clerk, Microsoft Azure

Account life plus the published deletion and security-event periods

Legal agreement acceptance evidence

User and application request

Prove the version, time, and context of Terms and Privacy Policy acceptance; resolve contract disputes

Contract; legitimate interests; legal obligation

Microsoft Azure; professional advisers or authorities when legally required

Seven years after the later of acceptance or contract termination, subject to legal hold

Financial accounts and transactions

Customer, Plaid, financial institution, imports

Bookkeeping, categorization, reconciliation, close, reporting, lineage

Customer instruction and contract; legitimate interests where we are controller

Microsoft Azure; Plaid when connected

Seven years after organization closure or termination when retained as accounting evidence

Invoices, bills, contacts, products, jobs, and payroll summaries

Customer, authorized users, imports, enabled integrations

Receivables, payables, allocations, reporting, close, support

Customer instruction and contract

Microsoft Azure; customer-directed providers

Seven years when part of accounting records

Receipts and uploaded documents

Customer and authorized users

Storage, extraction, matching, substantiation, audit trail

Customer instruction and contract

Microsoft Azure, including Document Intelligence when requested

Seven years when attached to accounting records; otherwise deletion schedule applies

Automation output and provenance

Generated from organization records and instructions

Recommendations, automated entries, anomaly review, explanations, run history

Customer instruction and contract; legitimate interests for reliability

Microsoft Azure

Follows the related accounting record or operational-run schedule

Billing

Customer and Stripe

Trial, subscription, invoice, payment status, fraud and dispute handling

Contract; legal obligation; legitimate interests

Stripe, Microsoft Azure

Contract life plus tax, dispute, and accounting retention duties

Support and customer access grants

User, support personnel, application logs

Answer requests, investigate issues, grant-bound troubleshooting

Contract; legitimate interests; consent where an access grant is requested

Microsoft Azure

Three years after ticket closure unless linked to a longer-lived record or legal hold

Security, audit, and operational telemetry

Application, device, network, providers

Authorization, fraud prevention, incident response, reliability, legal evidence

Legitimate interests; legal obligation

Microsoft Azure, Cloudflare

Security events 365 days; production telemetry 90 days; financial audit evidence seven years

Optional product analytics

Browser after consent

Understand feature use and improve usability

Consent

PostHog

Analytics identifier up to 365 days or until consent is withdrawn

Marketing preference and suppression

User

Send opted-in communications and honor opt-outs

Consent; legal obligation; legitimate interests

Microsoft Azure and email delivery service

Until consent is withdrawn; suppression record retained as needed to honor the opt-out

Controller and processor roles

A customer organization is normally the controller or business for bookkeeping records and the personal data it places in GlacialBooks. FinArctic LLC is its processor or service provider for that data. FinArctic LLC is the controller or business for account administration, direct billing, platform security, legal compliance, service communications, and consent-based product analytics. The same field may be processed in different roles for different purposes, and we limit each use to the role and purpose that applies.

Sensitive data

Financial account, transaction, tax, payroll, authentication, and precise business records can be sensitive personal information. We use that information only to provide, secure, support, and comply with law for the Service. We do not use it for targeted advertising, consumer profiling unrelated to bookkeeping, or general-purpose AI training.

Data minimization and review

We collect the data required for the selected workflow, restrict access by role and organization, and review retention and providers when the product changes. Customers should avoid uploading health records, government-classified data, payment-card security codes, bank-login credentials, or personal data that is unrelated to bookkeeping.

Related documents

Detailed rights and disclosures are in the Privacy Policy and Notice at Collection. Processing terms are in the Data Processing Addendum, and exact schedules are in the Data Retention and Deletion Policy.