FinCipro

Privacy Policy

Last updated: 13 July 2026

FinCipro ("we", "us") operates the personal finance application at app.fincipro.com. This policy explains what data we process when you use FinCipro and how we protect it. We process personal data in accordance with the EU General Data Protection Regulation (GDPR).

1. Data controller

FinCipro
Contact: Sofian.zarti@fincipro.com

2. What we collect

  • Account data — email address and authentication identifiers when you register or sign in (via Firebase Authentication).
  • Financial data you enter — assets, liabilities, transactions, notes, and preferences you choose to store in your workspace.
  • Bank connection data (optional) — if you link a bank account, we receive account metadata and transaction history from your bank through our regulated open-banking partner Enable Banking. We never receive or store your online-banking password, PIN, or other credentials.
  • Technical data — basic logs required to operate the service (e.g. error reports, request timestamps). We do not sell your data.

3. Bank connections (PSD2 / open banking)

When you connect a bank, you are redirected to your bank (or Enable Banking) to give consent under PSD2. Enable Banking Oy acts as the technical access provider for account information services. FinCipro receives only the data you authorise — typically account names, masked identifiers, balances, and transactions — to display and categorise activity in your ledger.

You can revoke access at any time by removing the bank connection in FinCipro settings and, where applicable, in your bank's consent management portal.

4. Why we use your data

  • To provide and improve the FinCipro application
  • To authenticate you and keep your workspace secure
  • To import and display bank transactions you have authorised
  • To respond to support requests and comply with legal obligations

5. Legal bases (GDPR)

  • Contract — processing necessary to deliver the service you signed up for
  • Consent — optional bank linking and marketing communications where applicable
  • Legitimate interests — security, fraud prevention, and service reliability, balanced against your rights

6. Sharing and processors

We use trusted subprocessors to run FinCipro, including:

  • Firebase / Google Cloud — authentication and database hosting
  • Vercel — application hosting
  • Enable Banking — regulated open-banking connectivity (EEA)

We do not sell personal data. Data may be disclosed if required by law or to protect our rights and users' safety.

7. Retention

We keep your data while your account is active. If you delete your account or remove a bank connection, we delete or anonymise associated data within a reasonable period, except where longer retention is required by law.

8. Your rights

Under GDPR you may request access, correction, deletion, restriction, portability, or objection to certain processing. You may also lodge a complaint with your local supervisory authority. Contact us at Sofian.zarti@fincipro.com to exercise these rights.

9. Security

We use industry-standard measures including encrypted transport (HTTPS), access controls, and separation of production secrets. No method of transmission over the internet is 100% secure; we work continuously to protect your information.

10. Changes

We may update this policy from time to time. Material changes will be reflected on this page with a new "Last updated" date.