Which origins you buy, at what spec, at what price. That is a competitive position.

So we built on the assumption that your sourcing data is the most sensitive data you have. The short version is below. The full technical documentation sits behind the form at the bottom of this page, and if your team wants to go through it with the person who built it, we will set that up.


Your data is never used to train a model anyone else can use


Your records, your contracts, your lab results and your field observations stay inside an area operated only for your company. We do not train our own models on your data. What improves across customers is our agricultural model and the correlations we validate, built from feedback our users deliberately give us. If we ever want to go further than that, we agree it with you in the contract first.

Where a model is built on your data, in a joint development project for example, it lives in your area and works only for you.

01

It stays in the EU


02

Who can see your data, including us

Your data is hosted in the EU and processed under a data processing agreement, fully GDPR compliant.

One exception is documented: our infrastructure provider processes a category of central security logs in the US under EU Standard Contractual Clauses, for security and abuse monitoring only. The technical documentation sets out exactly what that covers.

Your team signs in with your own single sign-on, and you assign the roles, so an agronomist sees their region and a category buyer sees their category.

Names and contact details are redacted before anyone at Finches can see them, and we cannot switch that off for ourselves. Every access to personal data is logged and we will produce the record on request.


03

05

Our hosting providers hold ISO 27001 and SOC 2 Type 2, with annual external penetration testing. Their certification covers the infrastructure Finches runs on, not Finches as a company.

Finches GmbH holds neither yet. We are nine people, founded in May 2025, and Q2 2027 is the target for both.

Certifications

What we run today: mandatory GDPR and security training for every employee, a record of processing activities under Art. 30 GDPR, a formal breach-notification process, and defined support for your data-subject requests inside the statutory window.

04

Deletion and exit

Your team deletes individual records in the app. Through one or two named people on your side you can have individual accounts or your entire organisation's data deleted, and you decide whether it is removed outright or detached from the user. We execute within the statutory deadline, with written confirmation on request.

On exit you decide what happens to your data: export, deletion, or both. A formal deletion concept follows in Q4 2026.


What the model says is a proposal

Every alert carries its evidence and its sources, so your team can check it instead of trusting it.

Information only leaves your system when a person sends it, and that stays true when the agentic layer arrives. Liability terms for AI output are in the contract, and we will send you the clause on request.


06

How we use AI on this website

We build AI products, so we use AI tools on our own work. Some of the text on this website was drafted or edited with AI support, and every page is reviewed and released by a person at Finches who is responsible for what it says.

Some of the imagery on this site is AI-generated, including landscape and crop photography. None of it depicts a real, identifiable person, place or event, and none of it shows a Finches customer's site or operation.

Product views are schematic representations of the Finches interface, built to show one idea per screen. They are not screenshots of a customer's live data. Where a view shows something we are still building with our Early Access partners, the text next to it says so.

Art. 50 of the EU AI Act does not require this of us, as it covers deep fakes and public-interest publishing. We state it because a buyer asking what our AI does with his data should not have to wonder what it does on our own site.

How to get the rest

Hosting model, encryption, availability, incident response, AI models. DE and EN.

OPEN TO EVERYONE

THIS PAGE

What happens to your data, who can see it, what is certified, how to delete it


BUSINESS EMAIL

THE DOCUMENTATION

Hosting model, encryption, availability, incident response, sub-processors. DE and EN.


NAMED PERSON, UNDER NDA

THE DOCUMENTATION

Your questionnaire, the DPA, the transfer assessment, live with the CTO who built it.

SLA values and liability terms for AI output sit in the contract. Ask and we will send you the clauses.

Send this to your IT and legal team.

The full technical documentation covers hosting, AI models, certifications, cyber security and data protection in the detail a security review needs, in German and English. We update it as the product changes, and we will tell you when we do.