← Insights

Why your software supplier should need permission to see your clients

13 September 2026

When a firm puts its client list, bank transactions and payroll into cloud software, it is trusting the supplier’s staff as well as its code. In many products, anyone on the supplier’s support team can open any customer’s account whenever they like. The customer never finds out.

For an accounting practice, that sits badly with client confidentiality and with UK GDPR, where your firm is the controller of your clients’ data and the software supplier is only your processor.

How support access works in FIINO

  • Nobody at FIINO can open your firm by default. A firm admin grants support access under Settings → Support access.
  • Access is time-limited. You choose four hours, a day, three days or a week, and it ends on its own.
  • You choose view-only or changes. For most questions view-only is enough.
  • You can revoke it at any time. A revoked grant ends the session on the very next click.
  • It is logged on both sides. Every support session appears in your firm’s audit log and in ours.

What about emergencies?

Sometimes a firm cannot grant access, for example because nobody can sign in. For that case, a FIINO owner, and nobody else, can open a one-hour, read-only emergency session. They must give a reason. The session is recorded as a grant your firm can see, and your firm’s admins are emailed straight away.

Questions to ask any supplier

  1. Can your staff see my clients’ data without my permission?
  2. Will I know if they do?
  3. Can I limit how long and what they can do?
  4. Is it written down in a data processing agreement?

If the answers are unclear, it is worth asking again before you move your practice’s data across.

Try FIINO with your own practice

Start free