Privacy Policy

Privacy Policy

Effective Date: August 2, 2024

 

This Privacy Policy (“Policy”) outlines how we at Fianellas collect, use, and process your personal data when you interact with our website https://fianellas.com (“Website”), our web application (“Web App”), our mobile app (“App”), and any email communications we may send (collectively referred to as “Services”). If any specific part of this Policy applies only to certain Services or users in particular countries, we will clearly indicate this.

Applicable Regions: Australia, Brazil, Canada, Hong Kong, India, Indonesia, Israel, Japan, Malaysia, Mexico, Philippines, Singapore, South Korea, Türkiye, UAE, and USA

By continuing to interact with us, such as by submitting information or using our Services, you confirm that you understand and agree to the collection, use, disclosure, and processing of your personal data (or the personal data of any individual you provide) as described in this Policy.

For U.S. Users

Please note that personal information related to U.S. users that we collect in connection with our payment services is subject to our Consumer Privacy Notice. If there is a conflict or inconsistency between this Privacy Policy and our Consumer Privacy Notice, the Consumer Privacy Notice will govern that information. All other information collected from U.S. users will be governed by this Privacy Policy.

 

Privacy Policy Summary

To help you navigate our Privacy Policy, we’ve included a brief overview below. For more detail, please refer to each section in full.

1. Data Controller

The Data Controllers responsible for managing and using personal information are listed in the table below. For any questions on data protection, please reach out to us at privacy@fianellas.com.

2. Data We Collect About You

What Personal Information Means

"Personal data" refers to any details that identify or could identify an individual. This does not include anonymous data that cannot be traced back to a person. We gather and process personal data as follows:

2.1 Information You Provide

You may provide us with personal data when you register to use our Services, such as your name, email address, and contact details. This also includes details shared when using our Services, such as through social media, surveys, promotions, and troubleshooting. Additional verification data, like financial information and identity documentation, may be required for security purposes.

  • Brazil: We may collect CPF registry numbers for verification purposes.
  • New Zealand: Further information may be requested for anti-money laundering compliance.

2.2 Information Collected During Service Use

When you use our Services, we gather data about transactions, technical details, and usage patterns to improve functionality and security. This includes IP addresses, device data, and communication preferences.

2.3 Information Received from Third Parties

We may receive additional information about you from third-party partners, such as payment providers and financial institutions. This could include data to confirm identity or prevent fraud.

2.4 Data from Social Networks

If you access our Services via social networks (e.g., Apple, Facebook, Google), we may obtain relevant details like your profile image and email for authentication purposes.

2.5 Sensitive Data

In specific cases, we may require sensitive data, such as biometric information, to verify your identity. This data is used solely for security and compliance purposes, in line with regulatory requirements.

2.6 Children’s Data

Our Services are designed for adult users, and we do not intentionally collect data from children. If data from a child is collected inadvertently, it will be deleted.

3. How We Protect Your Information

We take data protection seriously and use encryption and security protocols to protect your data. Internet transmission carries some risk, but we implement strict security features once your information is received, including encryption for inactive data.

4. How We Use Your Information

We use your data based on legal grounds, such as consent, legitimate interest, and compliance with legal requirements. Here’s how we use it:

  • To fulfill contractual obligations, provide products, and improve our Services.
  • To prevent fraud and detect suspicious activity.
  • To meet regulatory obligations, including responding to legal requests from authorities.
  • To communicate important changes to our Services and for other administrative purposes.
  • To provide personalized marketing and understand the effectiveness of advertising.

For U.S. users, please refer to our U.S. Consumer Privacy Notice if any sections of this Policy differ.

 

5. Disclosure of Your Personal Data

5.1 We may share your personal data with the following third parties:

  • Affiliates, business partners, suppliers, and subcontractors for the execution of any contract we enter into with them or with you, and to help them improve the services they provide to us.
  • Advertisers and advertising networks to select and deliver relevant advertisements to you and others.
  • Analytics and search engine providers that assist us in enhancing and optimizing our site.
  • Our group entities and subsidiaries, which can be viewed by clicking here.
  • In the event that we sell any of our business or assets or merge with another organization, we may disclose your personal data to the prospective buyer or the organization with which we may merge.
  • Payment beneficiaries receive limited information when you initiate a transaction.
  • If we are required by legal obligation to disclose or share your personal data to comply with any law, enforce or apply our Customer Agreement or other applicable agreements, or protect the rights, property, or safety of Fianellas, our customers, employees, or others.
  • To prevent and detect fraud or crime and to assist us in conducting or cooperating with investigations of fraud or other illegal activities where we deem it reasonable and appropriate to do so.
  • In response to a subpoena, warrant, court order, a properly constituted police request, or as otherwise required by law.
  • To assess financial and insurance risks.
  • To recover debt, in cases of insolvency, or to allow a party or a financial institution that sent money to recover funds received by you in error or due to fraud.
  • To develop customer relationships, services, and systems.
  • With your consent, to share your details while using our Services.

5.2 If your discoverability feature is enabled, other Fianellas customers can search for you using your nickname, or the email address or phone number registered to your Fianellas account. You can manage this discoverability feature in your account settings. Additionally, you can generate a shareable link to facilitate sending and receiving money with other users.

5.3 If you would like more information about the third parties with whom we’ve shared your data, or a specific list relevant to you, you can request this by emailing privacy@fianellas.com.

5.4 No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.


6. EEA (European Economic Area) - Disclosure of Your Personal Data

If you are an EEA resident holding a balance with us in a Multi-Currency Account, we are legally obligated to disclose the following personal data to the Central Point of Contact of the National Bank of Belgium (CPC):

  • On a continuous basis:
    • Belgian bank and payment accounts, including powers of attorney on these accounts. For each account, we report the account number, the capacity of the customer (account holder or proxy holder), and the start or end date of the account.
    • Information on specific financial contracts established in Belgium, including the start or end date of the contractual relationship and contract type.
    • Information on certain cash transactions, detailing the type of transaction, customer capacity (self or authorized representative), and transaction date.
  • Periodically:
    • The balance of relevant cash accounts as of June 30 and December 31 of each year.
    • The “aggregate amount” of certain investment contracts, such as the value of assets held and liabilities on June 30 and December 31 of each year.

To identify individuals connected with these accounts or contracts, we must also report:

  • For natural persons: National Register or BIS number, or, if unavailable, full name, date of birth, place of birth (optional), and country of birth.
  • For legal entities: Registration number from the Crossroads Bank for Enterprises, or, if unavailable, full name, legal form, and country of establishment.

The CPC records and retains this data for ten years, while request logs are kept for five years. Under certain conditions, the CPC may disclose this data to Belgian tax authorities or other authorized entities for tax inquiries, criminal investigations, anti-money laundering efforts, or other legally sanctioned purposes.

You have the right to view data associated with your name by contacting the National Bank of Belgium and can request corrections or deletions of inaccuracies via the NBB website.


7. Japan - Disclosure of Your Personal Data

In this section, "we" refers to Fianellas Payments Japan K.K. We do not disclose personal data to third parties unless authorized by law or with your consent. We may engage third-party service providers, ensuring they adhere to strict confidentiality and data security standards.

We also jointly use personal data, as detailed in Section 2 of our Privacy Policy, with Fianellas Payments Limited (UK) to support our services. For questions, please contact privacy@fianellas.com.


8. Sharing and Storing Your Personal Data

8.1 Although our main data centers are in the UK and EU, we may transfer and store data outside your jurisdiction, including locations that may not offer the same data protection level. Such staff, where relevant, may be involved in payment order processing, payment details handling, and support services. We take all reasonable steps to secure your data.

8.2 In cross-border transfers, we implement safeguards such as Standard Contractual Clauses or International Data Transfer Agreements. You may request a copy by emailing privacy@fianellas.com.

8.3 In Switzerland, we ensure such safeguards unless an exception applies (e.g., legal proceedings abroad or with your consent).

8.4 For UK only: Fraud prevention agencies may allow the transfer of your personal data outside of the UK. These agencies ensure your data remains protected by employing suitable safeguards.


9. Profiling and Automated Decision-Making

9.1 We may use your data to personalize Services and recommendations, such as informing you of new features based on your transaction history. We employ pseudonymized data to protect your privacy, and this activity has no legal impact on you.

9.2 Automated processes help verify your identity and prevent fraud. These processes may result in an application or transaction rejection, or account closure. In such cases, you’ll be notified and can challenge the decision by contacting Fianellas Customer Support.

9.3 If a fraud or money laundering risk is identified, Fianellas or a fraud prevention agency may deny services or terminate existing services, with records retained by the agency, which could affect your access to services, financing, or employment.


10. Cookies

We use cookies to identify you among other users, improve site functionality, and provide you with the best experience. For details on cookies and other tracking technologies, refer to our Cookie Policy.


11. Data Retention

11.1 We retain your personal data as long as necessary for the purposes collected. Due to legal requirements, some data may be retained even after account closure. Access to retained data is limited to essential personnel.

11.2 For UK only: Fraud prevention agencies may retain personal data for varying durations, up to six years if fraud or money laundering risks are identified.


12. Amazon Payment Service Provider Program

12.1 Fianellas participates in Amazon's Payment Service Provider Program. Amazon may request details such as account information, payments, and linked accounts from January 1, 2015, to prevent fraud and uphold standards.

12.4 Outside the UK, EEA, Indonesia, Türkiye, and Brazil, your continued use of your Fianellas account signals your consent to this data sharing.

12.5 If you prefer not to share information with Amazon, avoid linking your Fianellas account with Amazon.

13. Your Rights

13.1 Depending on the applicable laws in your jurisdiction, you may have certain rights regarding the personal information we hold about you. If you have questions about how we use your personal information, you may contact us at privacy@fianellas.com.

13.2 Exercising these rights may be subject to certain exceptions, such as safeguarding the public interest (e.g., preventing or detecting crime), protecting our interests (e.g., maintaining legal privilege), and protecting the rights of others (e.g., when your request involves information about other individuals).

13.3 We may need to retain certain data for record-keeping purposes and to comply with obligations under applicable laws and regulations, including anti-money laundering requirements or to complete any pending transactions prior to your request for change or deletion.

13.4 You generally will not be charged a fee to access your personal data or exercise other rights. However, we may charge a reasonable fee if your request is unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with the request in these cases.

13.5 We may request specific information to confirm your identity and your right to access your personal data or exercise other rights. This security measure ensures that data is not disclosed to anyone without authorization. Additionally, we may contact you to request more information regarding your request to speed up our response.

13.6 If you wish to stop receiving marketing emails, you may opt out by following instructions in those emails. We will make every effort to comply with your request as soon as possible. Note that you may still receive important administrative communications.

13.7 To make a formal request, contact us using the details provided in the Appendix.

13.8 Subject to certain country-specific conditions, your rights may include the following:

  • Requesting a copy of personal data we hold about you to check its lawful processing.
  • Requesting corrections to your personal data if you believe any information we hold is inaccurate. We may need to verify the accuracy of the updated data.
  • Requesting the deletion of your data if there’s no legitimate reason for us to retain it. You may also ask us to delete your data if: (i) you’ve exercised your right to object to processing (see below); (ii) we have processed it unlawfully; or (iii) we’re required to delete it to comply with local law. We may be unable to comply with all deletion requests for specific legal reasons, which will be provided in our response, including regulations that may require us to retain your data after account closure.
  • Withdrawing consent where our lawful basis for processing relies on it. Withdrawal does not impact the lawfulness of previous processing. Note that withdrawing consent may affect our ability to provide certain products or services to you.
  • Requesting that we stop direct marketing or profiling for marketing by contacting us or adjusting your preferences in your account settings.
  • Requesting information on automated decision-making and ensuring that automated decisions with a legal impact are made accurately. We may deny the request when disclosure could reveal trade secrets or hinder crime prevention/detection. Generally, we will verify the algorithm and source data to ensure accuracy.
  • Objecting to processing based on legitimate interest if it impacts your fundamental rights and freedoms due to your specific situation.
  • Requesting suspension of your data processing in cases where: (i) you want us to verify its accuracy; (ii) processing is unlawful, but you don’t wish to delete it; (iii) you need us to retain data for legal claims; or (iv) you objected to processing, pending our confirmation of overriding legitimate grounds.
  • Requesting data transfer to a third party or yourself. We will provide the personal data in a structured, commonly used, machine-readable format if it was collected based on consent or contract performance.

14. California - Your Rights

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (“CCPA”), including:

  • Right to know about the data collected, its sources, business purposes, and categories of third parties with whom it is shared.
  • Right to request specific data collected within the last 12 months.
  • Right to delete personal data that we hold about you.
  • Right to correct inaccurate data held by us.
  • Right to limit the use of sensitive personal data to essential services or product provision only.
  • Right to opt-out of the sale or sharing of personal data, though Fianellas does not sell personal information under the CCPA. We may share data with third parties for service enhancement without monetary compensation for the data.
  • Right not to face discrimination for exercising your CCPA rights.

Note that these rights do not apply to data covered by specific privacy laws, including the Gramm-Leach-Bliley Act, the California Financial Information Privacy Act, or the Driver’s Privacy Protection Act of 1994.

California residents may also request a list of all third parties to whom we disclosed certain information in the past year for direct marketing purposes. To exercise your CCPA rights or “Shine the Light” and “Eraser” rights, contact privacy@fianellas.com or call +1-888-908-3833. We are required to verify your identity before responding to your request.


15. Other Jurisdictions

In some regions, you may have additional rights concerning your personal data under relevant data protection laws. For more information, please reach out to us at privacy@fianellas.com.


16. Third-Party Links

Our Services may include links to websites owned by our partners, advertisers, or affiliates. These sites have their own privacy policies, and we assume no responsibility for them. If you choose to follow a link, please review the privacy policies on those sites before submitting any personal data.


17. Changes to Our Privacy Policy

To remain compliant with evolving laws, best practices, and adjustments in our data handling processes, we may revise this Privacy Policy by posting updates on our website. Check back periodically to stay informed of any changes.