Legal
Privacy Policy
Effective date: December 31, 2025.
1. Introduction and scope
This Privacy Policy explains how FinSuites, LLC ("FinSuites", "we", "us") collects, uses, discloses and protects personal data in connection with the provision of its software-as-a-service platform and related services (the "Services").
FinSuites provides its Services exclusively to business customers (B2B). The Services are not directed at consumers or private individuals acting outside a commercial or professional capacity.
This Privacy Policy applies to visitors of our websites, to customers and authorized users of the Services, and to individuals whose personal data is processed in connection with the Services. It should be read together with our Terms & Conditions and, where applicable, the Data Processing Agreement (DPA).
This Privacy Policy does not govern the content of customer data that FinSuites processes exclusively on behalf of customers as a processor. Such processing is subject to the respective customer's privacy policy and the applicable DPA.
2. Controller and EU representative
FinSuites, LLC
30 North Gould St Ste R
Sheridan, WY 82801
United States of America
Email: privacy@finsuites.com
BestLife Group GmbH
Lenzstraße 5
90408 Nürnberg
Germany
Email: info@bestlifestudios.de
The EU representative serves as the point of contact for supervisory authorities and data subjects with regard to the processing activities covered by this Privacy Policy. The EU representative acts exclusively within the scope of Art. 27 GDPR and does not assume the role of controller or processor.
3. Roles and scope of processing
Depending on the processing context, FinSuites acts either as a controller or as a processor.
Processing as controller: FinSuites acts as controller where personal data is processed for its own business purposes, in particular for operating the website, account management and authentication, billing and payment administration, sales, marketing and affiliate attribution, customer support and communication, as well as security, fraud prevention and compliance with legal obligations.
Processing as processor: Where customers use the Services to process personal data of their own customers, leads, employees or contractors, FinSuites acts exclusively as a processor on the customer's behalf. In these cases, the customer remains the controller and determines the purposes and means of the processing. This processing is governed by a separate Data Processing Agreement (DPA) under Art. 28 GDPR.
4. White-label platform and infrastructure
FinSuites operates its Services as a white-label implementation of the GoHighLevel / LeadConnector platform. The core infrastructure, features and technical processing mechanisms correspond to those of GoHighLevel and its affiliated companies. This structure does not change the responsibility of FinSuites as controller or its role as processor under the DPA.
5. Categories of personal data
FinSuites processes personal data only to the extent necessary to provide the Services and comply with applicable law.
a) Account and customer data: name, company name, business address, email address, phone number, login credentials, user roles and permissions.
b) End-customer data (processed on behalf of customers): names, email addresses, phone numbers, communication metadata, IP addresses.
c) Usage and technical data: IP address, browser and device information, operating system, log files, timestamps and interaction data.
d) Payment and transaction data: payments are processed exclusively through third-party payment providers (e.g. Stripe). FinSuites does not store full payment card data. Processed are billing details, transaction identifiers, payment status and tokenized payment references.
e) Marketing and tracking data: subject to any required consent: cookie identifiers, analytics data, data on advertising interactions.
FinSuites does not process special categories of personal data within the meaning of Art. 9 GDPR.
6. Purposes of processing and legal bases
Personal data is processed only where legally permitted.
Performance of contract (Art. 6(1)(b) GDPR): provision and operation of the Services, account management, payment processing, customer support.
Legitimate interests (Art. 6(1)(f) GDPR): security, abuse and fraud prevention, system stability and performance, internal analytics and reporting, enforcement of contractual rights.
Consent (Art. 6(1)(a) GDPR): marketing communication, non-essential cookies and tracking. Consent can be withdrawn at any time with effect for the future.
Legal obligations (Art. 6(1)(c) GDPR): accounting and tax obligations, regulatory requirements, lawful requests by authorities.
Provision of personal data: the provision of certain personal data is required to enter into and perform the contractual relationship with FinSuites (e.g. registration, authentication, billing). Without this data, FinSuites may not be able to provide the Services. Additional data may be provided voluntarily.
7. Data from third-party sources
Customers may connect third-party sources to the Services, including advertising platforms, CRM systems, communication providers or social networks. Personal data imported from such sources is processed exclusively on behalf of the customer and according to the customer's instructions. Customers are responsible for ensuring a valid legal basis for the collection and import of such data.
8. Affiliate and referral programs
FinSuites operates affiliate and referral programs. Where users access the Services through an affiliate or referral link, FinSuites may process referral identifiers, attribution data and transaction information for commission calculation, fraud prevention and performance analysis. This processing is based on legitimate interests (Art. 6(1)(f) GDPR) and, where required, on consent. Affiliates act as independent controllers with regard to their own processing activities.
9. Cookies, tracking technologies and consent management
FinSuites uses cookies and similar technologies to operate, secure and improve the Services.
Cookie categories: strictly necessary cookies, functional cookies, analytics cookies, marketing cookies.
Legal bases: strictly necessary cookies based on legitimate interests, all other cookies based on consent. Where legally required, a consent management platform (CMP) is used. Non-essential cookies are not set before consent has been given, where required by law. Consent can be withdrawn at any time without affecting the lawfulness of processing carried out before the withdrawal.
Further details are provided in the separate Cookie Policy at finsuites.com/cookies.
9a. Website-specific processing
Hosting and log files: this website is provided through the infrastructure of the LeadConnector platform. When you access the website, technically necessary data (in particular IP address, time of access, page accessed, browser information) is processed in log files to provide and secure the website (Art. 6(1)(f) GDPR). Servers may also be located in the USA; section 11 applies accordingly.
Local storage: for individual features (e.g. remembering a dismissed language notice), your browser's local storage is used. No data is transmitted to third parties in this process.
Embedded videos: product videos embedded on the website are delivered through our platform's infrastructure. Videos in our Help Center are embedded via YouTube in privacy-enhanced mode (youtube-nocookie.com). A connection to Google servers is only established when you actively play a video; personal data may be transmitted to Google in that process. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Fonts: the fonts used on this website are hosted locally. No connection to external font services takes place.
10. Subprocessors, integrations and marketplace applications
FinSuites uses subprocessors to provide the Services. A current list of authorized subprocessors, including purpose and processing location, is available at finsuites.com/subprocessors and may be updated from time to time. Customers will be informed of material changes where required by applicable data protection law.
Customers may, at their own discretion, enable integrations, marketplace applications or third-party services. These process personal data under their own privacy policies. FinSuites is not responsible for the data processing practices of such third parties.
11. International data transfers
Personal data may be transferred to and processed in countries outside the European Economic Area, including the United States.
Where required, FinSuites relies on appropriate safeguards, in particular the EU-U.S. Data Privacy Framework, where applicable, and/or the Standard Contractual Clauses (SCCs) adopted by the European Commission. Not all service providers are certified under the EU-U.S. Data Privacy Framework. Where personal data is transferred onward by subprocessors, equivalent safeguards are required contractually.
Personal data transferred internationally may be subject to access by authorities in accordance with applicable law. FinSuites does not guarantee that such access will never occur. Where Standard Contractual Clauses are used, FinSuites may implement supplementary technical and organizational measures, such as encryption and access controls, and assess transfer-related risks where legally required.
12. Automated and AI-supported features
The Services may include automated or AI-supported features that support functionality and efficiency. FinSuites does not make decisions based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR that produce legal effects or similarly significantly affect individuals. FinSuites does not use customer data to train standalone or generalized AI models for its own purposes.
13. Communication and telephony data
Where customers use communication features such as phone calls, SMS or messaging services (including WhatsApp integrations), FinSuites processes communication metadata (e.g. sender and recipient information, timestamps, delivery status) and, depending on configuration, message content exclusively on behalf of the customer. Customers are responsible for ensuring all required consents and legal bases for such communication.
14. Retention and deletion
Personal data is stored only as long as necessary for the purposes described or as required by law. Retention periods depend on the type of data, the purpose of processing and applicable legal obligations. For example, account and billing data may be retained for the duration of statutory retention periods, security and log data for limited periods to ensure system integrity, and marketing data until consent is withdrawn or the data is no longer needed.
After account termination, data is deleted or anonymized without undue delay; residual copies in backups may persist temporarily as part of security procedures. Data processed on behalf of customers is retained in accordance with the DPA.
15. Data subject rights
Where applicable, data subjects have the right to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.
Requests can be directed to privacy@finsuites.com. FinSuites may require proof of identity and will respond within the statutory deadlines. Where FinSuites acts as a processor, requests should be directed to the respective customer as controller. Data subjects have the right to lodge a complaint with a competent supervisory authority.
16. Children and minors
The Services are intended exclusively for business use and are not directed at children. FinSuites does not knowingly process personal data of individuals under the age of 16.
17. Do Not Track and Global Privacy Control
FinSuites does not currently respond to browser Do Not Track signals. Where legally required, Global Privacy Control (GPC) signals may be honored.
18. Security measures
FinSuites implements appropriate technical and organizational measures, including access controls, encryption of data in transit where appropriate, network security monitoring and role-based access restrictions. No system can guarantee complete security.
19. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time. The current version is available on our website. Material changes will be communicated where required by law.
20. Contact
FinSuites, LLC
30 North Gould St Ste R
Sheridan, WY 82801
United States of America
Email: privacy@finsuites.com
EU representative:
BestLife Group GmbH
Lenzstraße 5
90408 Nürnberg
Germany