1. Controller and contact
The data controller is Banqa Labs S.r.l. — PLACEHOLDER, Via Dante 12, 20121 Milan (MI), Italy — PLACEHOLDER. Company and VAT details appear in the Legal Notice.
For privacy questions or to exercise a data right, email support@banqa.app. No Data Protection Officer has been appointed at this stage. If appointment becomes legally required, this notice will be updated.
2. Data we process
Account and profile
- Name, email address, authentication identifiers and account settings.
- Language, currency, timezone and device or application preferences.
- Questionnaire answers used to configure budget behaviour and the tone of the AI coach.
Budget and financial information
- Income, expenses, transaction descriptions, amounts, dates and categories.
- Main budgets, category budgets, savings goals and progress.
- For connected accounts: account identifiers, balances, transactions, consent status and connection metadata supplied through the regulated open-banking provider.
Android notification data
If permission is granted, the Android app identifies supported bank or spending notifications so the user can create expense records. This feature is optional. The implementation is designed to perform detection on the device and send only the resulting expense information chosen for Banqa, not an unrestricted copy of the notification history.
Support, website and technical data
- Name, email and message submitted through the homepage question form or support email.
- Security logs such as IP address, timestamps, request information, device and application version, error reports and suspicious activity.
- A local browser preference stores the selected light or dark theme. The contact form uses a self-hosted ALTCHA proof-of-work check without advertising cookies or third-party CAPTCHA tracking.
Future photo affordability checks
If the photo feature is released and you choose to use it, Banqa will process the submitted image and your accompanying question to compare the purchase with your budget, goals and recent spending. The feature will be optional and this notice will be updated before production release.
3. Why we process data
Provide the service — contract. Create your account, maintain budgets, classify spending, calculate progress, display transactions, personalise the coach and provide support.
Bank connection — contract and explicit user action. Request account information only after you choose a bank, review the provider flow and authorise access.
Optional Android access — consent and device permission. Detect supported spending notifications only when you enable the feature. Permission can be withdrawn in Android settings.
Security and reliability — legitimate interests and legal obligations. Prevent abuse, investigate incidents, maintain logs, enforce terms and meet applicable regulatory duties.
Product improvement — legitimate interests. Diagnose errors and improve the service using appropriately limited data. Banqa does not sell personal data or use financial data for third-party advertising.
4. Open banking and finAPI
Banqa intends to operate as an unlicensed customer using finAPI’s PSD2 licence and Web Form. finAPI, the relevant bank and other regulated participants may process identification, consent, bank-authentication and account data under their own legal obligations and privacy notices.
Before a bank connection begins, Banqa will clearly identify the regulated provider, explain that the user is leaving Banqa for authentication, link to the provider’s current legal information and collect the permissions required for account-data use.
Banqa requests read-only account information. It does not request authority to initiate payments. Consent can expire, be withdrawn or be revoked at the bank or provider. Disconnecting stops future retrieval but does not automatically erase transaction records already stored in Banqa; those can be deleted through the process described below.
5. AI coaching and profiling
Banqa uses questionnaire answers, budgets, goals and spending patterns to generate summaries, alerts and coaching language. This is personalisation and profiling, but it is not intended to make decisions that produce legal or similarly significant effects. Banqa does not approve credit, set insurance prices, execute trades or decide whether another company should serve you.
AI output may be inaccurate. You can change the questionnaire, choose a different tone, ignore a recommendation and request support. Important financial decisions should not rely only on automated output.
7. How long data is kept
- Account and budget data: while the account is active and until deletion is completed.
- Bank-connection data: while consent and the connected service remain active; connection credentials and consent records follow the regulated provider’s retention rules.
- Support messages: normally up to 24 months after the issue is closed, unless a longer period is required for a dispute or legal obligation.
- Security logs: normally up to 12 months, unless needed to investigate abuse or an incident.
- Billing and legal records: for the period required by tax, accounting, consumer and payment-services law.
- Backups: removed through the normal backup-expiry cycle after operational deletion.
These periods are operational targets and must be confirmed against the final production architecture and provider contracts before launch.
8. Your GDPR rights
Subject to applicable conditions, you may request access, correction, deletion, restriction, portability or objection; withdraw consent at any time; and complain to a supervisory authority. Withdrawal does not make earlier lawful processing unlawful.
Email support@banqa.app from the address associated with your account. Banqa may request proportionate identity verification before disclosing or deleting financial data. See the complete Data Deletion process.
If Banqa is established in Italy, the lead supervisory authority is expected to be the Garante per la protezione dei dati personali. You may also contact the authority in your EU/EEA country.
9. Children and changes
Banqa is intended for people aged 18 or older. It is not designed to collect children’s financial data.
Material policy changes will be communicated in the app or by email before they take effect where required. Earlier versions will be retained for accountability.