1. Who we are
Steinfin provides outsourced accounts receivable and credit control services to businesses. Steinfin is operated by Consul International, company ID M61319502J.
- Trading name
- Steinfin
- Legal name
- Consul International
- Company ID
- M61319502J
For anything about this policy or your personal information, email [email protected].
2. Our two roles
Data protection law treats organisations differently depending on who decides how personal information is used. Steinfin can be in either position.
When we are the controller
We decide how and why information is used for our own business. This covers website visitors, people who contact us or request an AR health check, people at businesses we contact about our services, and the staff of our clients we work with.
When we act for a client
When we run accounts receivable for a client, we handle information about that client's customers on the client's behalf and on its instructions, under an agreement that includes data processing terms. The client is the controller of that information and decides the basis for using it. We use it only to provide the service. Section 4 explains this in more detail.
3. Information we collect
Information you give us
- Contact form: your name, work email and message, and if you choose to add them, your company, phone number and the topic of your enquiry.
- AR health check: your work email and company, and anything else you choose to share, such as your name, website, country, industry, rough invoice volumes, outstanding and overdue amounts, accounting system and the main problem you face.
- Emails, calls and meetings: what you tell us when you correspond or speak with us.
- As a client: contact details of the people we work with at your business, and information needed to agree, deliver and bill our service.
Our website forms do not ask for special category data, such as health information, and we ask you not to send it.
Information from public sources
We may collect business contact details for people at companies we think could benefit from our services, such as names, job titles and business email addresses published on company websites or business directories.
Technical information
When you use our website, our hosting and website security providers process technical information such as your IP address, browser type, the pages requested and the time of each request. This is needed to deliver and protect the website. See section 12 for cookies and how we work out your country for pricing.
4. Data we handle for clients
To run accounts receivable for a client, we handle information about that client's customers, who are usually businesses. This can include:
- names, business email addresses and phone numbers of customer contacts
- company details
- invoice details, outstanding balances and payment status
- payment promises, queries and disputes
- remittance information
- records of our emails and calls with the customer
Where it comes from
This information comes from the client: through a connection to the client's accounting system, such as Xero, QuickBooks or Sage, which the client authorises and can revoke, or from information the client shares with us directly. Customers also give us information when they reply to us.
Contacting customers
We contact a client's customers by email and phone about their invoices with that client, in the client's name and following the client's instructions. We do not use this information to market our own services, or for any purpose other than providing the service to the client.
Payment information, not payment funds
We use payment information, such as payment status, references and remittance details, to keep accounts accurate. We do not hold client funds: customers pay the client directly, through the client's own payment arrangements. We do not ask for online banking logins, and we never ask customers for card or bank details.
If you are a customer of one of our clients and have a question about your information, you can contact us or the client. Some requests may need to be handled by the client as controller, and we will help route them.
5. How we use information
Where UK or EU data protection law applies, we must have a legal basis for each use of personal information. This table shows what we do, the information involved and the basis we rely on when we are the controller.
| Purpose | Information used | Legal basis |
|---|---|---|
| Responding to messages and enquiries | Name, email, company, phone, your message | Legitimate interests in answering people who contact us, or steps you ask us to take before a contract |
| Providing a free AR health check | The details you submit about your business and receivables | Steps you ask us to take before a possible contract |
| Following up with people who have contacted us | Contact details and the history of our conversation | Legitimate interests. You can object at any time |
| Contacting businesses that may benefit from our services | Business contact details from public sources | Legitimate interests. You can object at any time |
| Providing our services and managing client relationships | Contact details of client staff, agreement and billing details | Contract, and legitimate interests for client staff who are not a party to it |
| Keeping the website secure and preventing spam | IP address, request details, form timing, a short-lived hashed IP | Legitimate interests in protecting our website and forms |
| Showing prices in your local currency | Country, derived from your IP address | Legitimate interests in showing relevant prices |
| Meeting legal obligations | Records we are required to keep, and information requested by authorities | Legal obligation |
Where we rely on legitimate interests, we have considered our interests against yours. You can object, as explained in section 13. For information we handle for clients, the client decides the legal basis.
6. Marketing and outreach
We do not run a newsletter, and we do not add you to a mailing list because you used one of our forms. If we ever offer marketing emails, we will ask for your permission separately where the law requires it, and every message will include a simple way to opt out.
We may contact people at businesses we think could benefit from our services, using business contact details from public sources. We keep this relevant and limited, and we stop as soon as you tell us you are not interested. You can object at any time by replying to us or emailing [email protected].
7. AI and automation
We use automation, and may use AI tools, to help organise accounts, highlight what needs attention, keep priorities in order and prepare routine work. People at Steinfin review what goes to customers, and commercial decisions stay with our clients.
This is workflow support. We do not make decisions based solely on automated processing that have legal or similarly significant effects on individuals.
If you are a client or prospective client and want to know which tools would process your information, and on what terms, ask us before you start and we will tell you.
9. International transfers
Some of our providers operate internationally, so personal information may be processed outside the UK or the European Economic Area. Where that happens, we use a safeguard recognised under data protection law, such as an adequacy decision or standard contractual clauses. You can ask us for more information about how a particular transfer is protected.
10. How long we keep information
We keep personal information only for as long as we need it for the purpose we collected it, including to meet legal, accounting and reporting requirements, resolve disputes and enforce our agreements. When we no longer need it, we delete it or anonymise it.
- Enquiries and AR health checks: kept while we are in conversation with you and for a reasonable period afterwards, unless you become a client or ask us to delete them sooner.
- Client information: kept for the length of the service and afterwards only as long as our agreement and the law require.
- Spam protection on the contact form: the hashed IP address is kept for no more than 15 minutes for rate limiting.
When a client relationship ends
The client's accounting connection is disconnected. Information we handled for the client is returned or deleted in line with our agreement, except where the law requires us to keep certain records.
11. Security
We use technical and organisational measures appropriate to the information we handle. Access to client information is limited to the people working on that client's account, and we use only the information the service needs. Our Security page explains our approach in more detail.
13. Your rights
If UK or EU data protection law applies to your information, you have rights that include:
- asking for a copy of your personal information
- asking us to correct information that is wrong
- asking us to delete your information
- asking us to restrict how we use it
- objecting to our use of it, including for outreach
- asking for your information in a portable format
- withdrawing consent where we rely on it
Some rights apply only in certain circumstances, and some have exceptions, for example where we must keep information by law. We will explain if a right does not apply.
How to make a request
Email [email protected] or use our contact page. We may need to confirm your identity before acting on a request, and we will only ask for what we need to do that. If your request concerns information we handle for a client, we may need to pass it to that client, and we will tell you if so.
Complaints
If you are unhappy with how we have handled your information, please contact us first so we can try to put it right. You also have the right to complain to the data protection authority in the country where you live or work.
Outside the UK and EU
If you are elsewhere, you may have rights under local law. Contact us and we will respond in line with the law that applies to you.
14. Children
Steinfin is a business-to-business service. Our website and services are not aimed at children, and we do not knowingly collect information about children.
15. Other websites
Our website links to other websites, such as those of accounting software providers. They have their own privacy practices, which this policy does not cover.
16. Changes to this policy
We may update this policy to reflect changes to our services, our providers or the law. The date at the top shows when it was last updated. If we make a significant change that affects how we use information you have already given us, we will take reasonable steps to let you know.
17. Contact
For any question about this policy or your personal information, email [email protected] or use our contact page. You can also read our Website Terms and Service Terms.