Skip to main content

Privacy Policy — BSO Financial Services

BSO Financial Analyst — Privacy Policy

Last Updated: March 4, 2026

Effective Date: March 4, 2026

1. Overview

Bachata Sensual Orlando LLC (“BSO,” “we,” “us”) operates the BSO Financial Analyst application (“the App”), an internal bookkeeping tool used exclusively by BSO’s business owner for managing the company’s financial records. This Privacy Policy describes how financial data is collected, processed, stored, and protected.

2. Data We Collect

The App collects the following data through our banking integration provider, Plaid Inc.:

  • Transaction data: Date, merchant name, amount, and account information from connected Chase bank accounts
  • Account metadata: Account names, types, and balances
  • Plaid access tokens: Encrypted authentication credentials for bank connectivity

The App does NOT collect:

  • Bank login credentials (handled entirely by Plaid)
  • Social Security numbers or personal identification
  • Data from any person other than the business owner
  • Consumer financial data — this is a business-only tool

3. How We Use Data

Financial data is used exclusively for:

  • Categorizing business transactions against IRS 1065 line items
  • Generating Profit & Loss reports for tax preparation
  • AI-assisted categorization via Anthropic’s Claude API (transaction descriptions only — no account numbers or personally identifiable information are sent to the AI service)

4. Data Storage & Security

  • All data is stored in an encrypted SQLite database on a private server hosted by Hetzner Online GmbH in the United States
  • Plaid access tokens are encrypted at rest using Fernet symmetric encryption (AES-128-CBC)
  • The application is served over HTTPS with TLS 1.3
  • Access requires multi-factor authentication (password + TOTP)
  • The server is accessible only via SSH key authentication

5. Data Sharing

We do not sell, rent, or share financial data with any third party. Data is shared only with:

  • Plaid Inc. — for bank account connectivity (governed by Plaid’s privacy policy)
  • Anthropic — transaction descriptions only (no account numbers) for AI categorization

6. Data Retention

See our Data Retention Policy for details on how long data is kept and how it can be deleted.

7. Access Control

The App is restricted to a single authorized user (the business owner). There is no public-facing component, no consumer access, and no multi-user functionality.

8. Your Rights

As the sole user and data controller, the business owner can at any time:

  • Export all data via CSV or PDF
  • Delete the database to remove all stored data
  • Disconnect bank accounts through the Plaid dashboard
  • Revoke Plaid access tokens

9. Changes to This Policy

This policy may be updated as the application evolves. The “Last Updated” date at the top reflects the most recent revision.

10. Contact

For questions about this privacy policy, contact:
Bachata Sensual Orlando LLC
Email: info@bsolatindance.com
7800 S US HWY 17-92 Unit 124, Fern Park, FL 32730

Have questions about this policy?

Contact Us