Who processes your data
The controller is the institution identified on the legal notice page. Any question about your data goes to the contact address at the foot of this page; we answer within the legal period of one month.
What you give us when you register
Your name, e-mail address, telephone, date of birth, postal address, country, the currency of your accounts and the language you want to be served in. Without these an account cannot be opened: they are required by the know-your-customer rules.
What identity verification adds
An identity document and a proof of address, which you upload. These files live on a PRIVATE disk, never served directly by the web server: every access goes through a controller that checks who is asking, and that access is logged. Their type is judged on the file's content, not on its extension.
What your use produces
Every movement writes a line in the ledger: amount, currency, reference, timestamp, and the name of whoever approved it. To these are added your cards, your beneficiaries, your credit applications and the receipts that follow. This is the service itself: a balance without entries is not a balance, it is an opinion.
The audit log, and why it does not erase
Every sensitive action — a sign-in, an approved transfer, an identity document accepted or refused, a manual adjustment — writes an audit line carrying the actor, their IP address, their browser and the moment. These lines cannot be deleted: that is what they are for. A trace that can be erased proves nothing, neither for you nor against us.
What is encrypted
Your postal address and your two-factor authentication secret are encrypted at rest. Your password and your PIN are not stored: only irreversible fingerprints are, and nobody here can read them back. Card numbers are kept as a fingerprint only, never in the clear.
The legal bases
Performance of the contract between us, to hold your accounts and carry out your orders. Legal obligation, for identity verification, anti-money-laundering and the retention of records. Legitimate interest, for the security of the service: capping attempts, logging access, refusing a doubtful operation.
For how long
Identification data and supporting documents are kept for the duration of the relationship, then for the period the regulation imposes after it ends. Ledger entries and audit lines are kept under the same obligation. Beyond that, they are deleted or anonymised.
Deletion, and its honest limit
You may ask for your data to be erased. What a legal obligation requires us to keep cannot be erased on request — that would be a promise we could not honour. An account whose actions are audited is ANONYMISED rather than deleted: the personal elements disappear, the accounting trace remains, and it no longer names you.
Who else has access
Hosting is located in the European Union. Sending e-mail goes through a mail provider, which receives your address and the content of the message. Payment and IBAN verification providers are not enabled to date; the day they are, this page will name them before they receive anything.
Outside the European Union
No transfer of your data outside the European Union takes place. Should that change, this page would be amended before the transfer and not after, and the date at the top would say so.
Your rights
Access, rectification, erasure within the limits above, restriction, objection and portability. Most are exercised directly from your space: your personal information is editable, your receipts downloadable, your documents viewable. For the rest, write to us. You may also refer the matter to the supervisory authority of your country of residence.