Last updated: 15 July 2026
1. Who we are
Finsuri ("Finsuri", "we", "us") provides an AI-powered workflow platform for licensed insurance intermediaries — agents, brokers and financial advisers — operated from Singapore and available at app.finsuri.com. This policy covers both our marketing site and the Finsuri application.
2. What we collect
- Account data — your name, work email address, role, and the details of the firm you set up or join (firm name, UEN, licence category).
- Client records your firm uploads — insurance policy documents, quotes and related files, plus the structured data Finsuri extracts from them (for example insured names, policy numbers, coverage terms and premiums). These documents may contain personal data of your firm's clients.
- Contact details your firm adds — such as a client's contact person and email address, used only to send the correspondence your firm composes.
- Waitlist data — the email address you submit to join the waitlist.
- Usage and technical data — sign-in events, actions taken in the app (kept in an audit log for your firm's own recordkeeping), and error diagnostics.
3. How we use it
- To provide the service: reading and extracting policy documents, building your client book, flagging coverage gaps, comparing quotes, and drafting correspondence for your review.
- To send transactional email — sign-in links, team invitations, document-processing confirmations, and the emails your firm explicitly sends through Finsuri.
- To secure the service, investigate problems, and keep an accurate audit trail of actions taken in your workspace.
We do not sell personal data, and we do not use your documents or your clients' data for advertising.
4. AI processing
Finsuri uses various AI models to read documents and draft text. Document content is sent for processing and is not used to train AI models. Every AI output — extracted fields, drafted emails, gap findings — is presented to the licensed intermediary for review before it is relied on or sent.
5. Where your data lives
Your firm's documents, records and audit logs are stored in Singapore, and our application servers run in Singapore. Some supporting providers process limited data outside Singapore:
| Purpose | Data involved | Provider type | Location |
|---|---|---|---|
| AI document extraction & drafting | Document content during processing | AI model (LLM) provider | United States |
| Email sending & inbound document intake | Email content and attachments | Email delivery provider | United States |
| Website and app hosting | Technical request data | Hosting / CDN provider | Global |
| Error monitoring | Technical diagnostics | Error-monitoring provider | United States |
Where data is transferred outside Singapore, we rely on providers' contractual commitments to a standard of protection comparable to the PDPA.
6. Your firm's clients
For personal data contained in the documents your firm uploads, your firm remains the organisation responsible to its clients under the PDPA; Finsuri processes that data on your firm's behalf and instruction, as a data intermediary. If you are a client of a firm that uses Finsuri and have questions about your data, please contact your intermediary — we will support them in responding.
7. Security
- Every record is scoped to your firm — tenant isolation is enforced at the database layer (row-level security), not just in application code.
- Data is encrypted in transit (TLS) and at rest.
- Uploaded documents live in private storage, never on public URLs.
- Actions in your workspace are recorded in an append-only audit log that cannot be edited or deleted from the application.
8. Retention and deletion
We keep your firm's data for as long as your account is active. When your firm leaves Finsuri, you may export your records (including the audit trail), and we delete your data on request, subject to any retention required by law. Residual copies in encrypted backups age out on the backup cycle.
9. Your rights
Under the PDPA you may request access to or correction of your personal data, or withdraw consent to its processing (which may mean we can no longer provide the service to you). Write to us at the address below and we will respond within the timelines the PDPA sets.
10. Cookies
The application uses only the cookies and local storage needed to keep you signed in. We do not use advertising or cross-site tracking cookies.
11. Changes to this policy
If we make material changes, we will note the new date at the top of this page and, for significant changes, notify account holders by email.
12. Contact
Data protection queries: privacy@finsuri.com.