Skip to content

Privacy

What we know about you, and why

A bank has to know its customers — the law requires it and the service does not work otherwise. This page says exactly what, for how long, and what you can do about it.

Who processes your data

The controller is the institution identified on the legal notice page. Any question about your data goes to the contact address at the foot of this page; we answer within the legal period of one month.

What you give us when you register

Your name, e-mail address, telephone, date of birth, postal address, country, the currency of your accounts and the language you want to be served in. Without these an account cannot be opened: they are required by the know-your-customer rules.

What identity verification adds

An identity document and a proof of address, which you upload. These files live on a PRIVATE disk, never served directly by the web server: every access goes through a controller that checks who is asking, and that access is logged. Their type is judged on the file's content, not on its extension.

What your use produces

Every movement writes a line in the ledger: amount, currency, reference, timestamp, and the name of whoever approved it. To these are added your cards, your beneficiaries, your credit applications and the receipts that follow. This is the service itself: a balance without entries is not a balance, it is an opinion.

The audit log, and why it does not erase

Every sensitive action — a sign-in, an approved transfer, an identity document accepted or refused, a manual adjustment — writes an audit line carrying the actor, their IP address, their browser and the moment. These lines cannot be deleted: that is what they are for. A trace that can be erased proves nothing, neither for you nor against us.

What is encrypted

Your postal address and your two-factor authentication secret are encrypted at rest. Your password and your PIN are not stored: only irreversible fingerprints are, and nobody here can read them back. Card numbers are kept as a fingerprint only, never in the clear.

The legal bases

Performance of the contract between us, to hold your accounts and carry out your orders. Legal obligation, for identity verification, anti-money-laundering and the retention of records. Legitimate interest, for the security of the service: capping attempts, logging access, refusing a doubtful operation.

For how long

Identification data and supporting documents are kept for the duration of the relationship, then for the period the regulation imposes after it ends. Ledger entries and audit lines are kept under the same obligation. Beyond that, they are deleted or anonymised.

Deletion, and its honest limit

You may ask for your data to be erased. What a legal obligation requires us to keep cannot be erased on request — that would be a promise we could not honour. An account whose actions are audited is ANONYMISED rather than deleted: the personal elements disappear, the accounting trace remains, and it no longer names you.

Who else has access

Hosting is located in the European Union. Sending e-mail goes through a mail provider, which receives your address and the content of the message. Payment and IBAN verification providers are not enabled to date; the day they are, this page will name them before they receive anything.

Outside the European Union

No transfer of your data outside the European Union takes place. Should that change, this page would be amended before the transfer and not after, and the date at the top would say so.

Your rights

Access, rectification, erasure within the limits above, restriction, objection and portability. Most are exercised directly from your space: your personal information is editable, your receipts downloadable, your documents viewable. For the rest, write to us. You may also refer the matter to the supervisory authority of your country of residence.

What this site keeps. A session cookie, an anti-forgery token, and your display preferences. No audience measurement, no third-party script. The cookies page