← Back

VORNK Privacy Policy

Last updated: July 13, 2026

1. Who We Are

VORNK is operated by Arfadyne (arfadyne.com). This Privacy Policy explains how we collect, use, store, and protect your personal information.

2. Information We Collect

Information you provide:

  • Account information: name, email address, password (hashed, never stored in plain text)
  • Company information: company name, legal name, business registration number, address
  • Financial data: bank account details (institution name, account type, purpose — never account numbers or login credentials), transaction data extracted from uploaded statements, expense records, shareholder loan records, time logs, advisor information

Information from uploaded documents: When you upload bank statements or financial documents, we extract transaction data (date, merchant name, amount, category) using AI processing. The raw document is stored encrypted. The extracted transaction data is stored in your account database.

Information collected automatically:

  • IP address (used for security monitoring and share-link access logging)
  • Browser type and device type (used for session security)
  • Login timestamps and access patterns (used for security audit log)

3. How We Use Your Information

  • To provide and operate the VORNK platform
  • To process and categorize financial documents using AI
  • To generate reports and financial summaries
  • To detect and prevent security threats and unauthorized access
  • To send security notifications (new device logins, shared report accesses)
  • We do NOT sell your data to third parties
  • We do NOT use your financial data for advertising
  • We do NOT share your data with any third party except as described in Section 4

4. Third-Party Services

We work with carefully selected third-party service providers to operate the Platform. These providers process your data only as necessary to deliver the service and are contractually bound to protect your information.

Cloud database and file storage provider: Your account data and uploaded files are stored with a SOC 2 Type II compliant cloud infrastructure provider. All data is encrypted at rest and in transit. Files are stored in private buckets with no public access.

AI processing provider: Text extracted from uploaded bank statements and Smart Entry inputs is processed by a third-party AI service provider for transaction extraction and categorization. We transmit only document text content for processing — never your name, full account numbers, or login credentials. The AI provider's data handling is governed by their enterprise data processing agreement.

Authentication provider (if you use social login): If you choose to sign in using a third-party social login option, we receive only your name and email address from that provider. We do not receive your password or any other account data.

We do not sell your data to any third party. We do not use your financial data for advertising purposes. A current list of our sub-processors is available upon request at contact@arfadyne.com.

5. Data Storage and Security

  • All data is encrypted in transit using TLS 1.3
  • All data is encrypted at rest using AES-256 encryption
  • Bank statement files are stored in private encrypted storage — no public URL exists
  • Statement files are automatically deleted after your chosen retention period (30, 60, or 90 days)
  • Processed transaction data is retained until you delete your account
  • Access to files is restricted to signed URLs that expire within 1 hour
  • We maintain security audit logs of all file accesses

6. Data Retention

  • Raw uploaded statement files: deleted after 30/60/90 days per your setting
  • Processed transaction data: retained until account deletion
  • Security logs: retained for 12 months
  • Account data: retained until you request deletion

7. Your Rights (Canadian Privacy Law — PIPEDA)

  • Access all personal information we hold about you (Settings → Export all data)
  • Correct inaccurate information
  • Delete your account and all associated data (Settings → Delete account)
  • Withdraw consent for data processing (by deleting your account)
  • Know what third parties process your data (see Section 4)

For privacy requests: contact@arfadyne.com

8. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify you within 72 hours of discovery by email and through an in-app notification, in compliance with Canadian PIPEDA breach reporting requirements.

9. Children's Privacy

VORNK is not intended for users under 18 years of age. We do not knowingly collect personal information from minors.

10. Changes to This Policy

We will notify you of material changes to this Privacy Policy by email and in-app notification at least 30 days before the change takes effect.

11. Contact

Privacy Officer: contact@arfadyne.com
Arfadyne, Toronto, Ontario, Canada