Privacy Policy — BSO Financial Services
BSO Financial Analyst — Privacy Policy
Last Updated: March 4, 2026
Effective Date: March 4, 2026
1. Overview
Bachata Sensual Orlando LLC (“BSO,” “we,” “us”) operates the BSO Financial Analyst application (“the App”), an internal bookkeeping tool used exclusively by BSO’s business owner for managing the company’s financial records. This Privacy Policy describes how financial data is collected, processed, stored, and protected.
2. Data We Collect
The App collects the following data through our banking integration provider, Plaid Inc.:
- Transaction data: Date, merchant name, amount, and account information from connected Chase bank accounts
- Account metadata: Account names, types, and balances
- Plaid access tokens: Encrypted authentication credentials for bank connectivity
The App does NOT collect:
- Bank login credentials (handled entirely by Plaid)
- Social Security numbers or personal identification
- Data from any person other than the business owner
- Consumer financial data — this is a business-only tool
3. How We Use Data
Financial data is used exclusively for:
- Categorizing business transactions against IRS 1065 line items
- Generating Profit & Loss reports for tax preparation
- AI-assisted categorization via Anthropic’s Claude API (transaction descriptions only — no account numbers or personally identifiable information are sent to the AI service)
4. Data Storage & Security
- All data is stored in an encrypted SQLite database on a private server hosted by Hetzner Online GmbH in the United States
- Plaid access tokens are encrypted at rest using Fernet symmetric encryption (AES-128-CBC)
- The application is served over HTTPS with TLS 1.3
- Access requires multi-factor authentication (password + TOTP)
- The server is accessible only via SSH key authentication
5. Data Sharing
We do not sell, rent, or share financial data with any third party. Data is shared only with:
- Plaid Inc. — for bank account connectivity (governed by Plaid’s privacy policy)
- Anthropic — transaction descriptions only (no account numbers) for AI categorization
6. Data Retention
See our Data Retention Policy for details on how long data is kept and how it can be deleted.
7. Access Control
The App is restricted to a single authorized user (the business owner). There is no public-facing component, no consumer access, and no multi-user functionality.
8. Your Rights
As the sole user and data controller, the business owner can at any time:
- Export all data via CSV or PDF
- Delete the database to remove all stored data
- Disconnect bank accounts through the Plaid dashboard
- Revoke Plaid access tokens
9. Changes to This Policy
This policy may be updated as the application evolves. The “Last Updated” date at the top reflects the most recent revision.
10. Contact
For questions about this privacy policy, contact:
Bachata Sensual Orlando LLC
Email: info@bsolatindance.com
7800 S US HWY 17-92 Unit 124, Fern Park, FL 32730
Have questions about this policy?
Contact Us