Legal
Privacy Policy
Last updated 24 September 2026
AFS Pro is business software. Our customers are companies, and the data we process is their own accounts-receivable data — their customer list, their invoices, and the payments they receive. We do not sell data, and we do not use one customer's data to serve another.
Who we are
Emagia Corporation, Santa Clara, California. AFS Pro is our order-to-cash automation product, available at app.afsemagia.com.
What we process, and why
- Account data — the name and email address of each person who signs in, so we can authenticate them and record who approved what.
- Customer master and invoices — imported from your ERP or uploaded by you, so the agents can match payments to the right invoices.
- Bank transactions — read from a bank file you send us, or from an account you connect, so incoming credits can be matched and applied.
- Remittance documents — emails, PDFs and scans you forward or upload, read to extract which invoices a payment settles.
- Operational records — what each agent did and why, so every decision is auditable.
We process this to provide the service you have asked us to provide. We do not use it for advertising, we do not sell it, and we do not share it with third parties except the infrastructure providers listed below.
Bank connections
If you connect a bank account through Plaid, you are authorising read-only access to that account's transactions. We use this to identify incoming payments. Specifically:
- We read transactions only. We cannot move money, initiate payments, or make changes to your account.
- The account is your own company's account. We do not ask for, or access, accounts belonging to consumers.
- Access credentials are held encrypted in AWS Secrets Manager, never in our database, and never in our application logs. Your bank login is entered with Plaid and is never seen by us.
- You can disconnect a bank at any time from Data & Connections, which revokes our access immediately.
Plaid's own handling of your information is governed by the Plaid End User Privacy Policy.
Where it is held
All data is held in Amazon Web Services in the United States (us-east-2). It is encrypted in transit and at rest. Each customer's data is isolated at the database level and reachable only by users authenticated to that workspace.
How long we keep it
Operational records are retained according to a retention period you set in the product, and enforced automatically. Paid invoices are archived rather than deleted so that a reversal remains possible within the reversal window. When you close your account we delete your data within 30 days, except where we are required to retain records by law.
Sub-processors
- Amazon Web Services — hosting, database, storage and secrets management (US)
- Plaid Inc. — bank account connectivity, where you choose to use it (US)
- Anthropic / AWS Bedrock — the language model that reviews payments the rules engine cannot settle. Payment text is sent for that decision; it is not used to train any model.
Your rights
You can access, export, correct or delete your data at any time — most of it directly in the product, and the rest on request. If you are covered by the GDPR or the CCPA you have the rights those laws give you, and we will honour a request within 30 days.
Contact
Write to privacy@emagia.com with any question about this policy or any request concerning your data.