At Finary, the protection of your personal data is our priority.
Finary’s primary goal is, and always has been, to put technology at the service of your assets, to allow you to reclaim your banking and investment data, to understand and control it, in order to optimise your investment strategy and give you access to ever more relevant assets.
Finary is required to collect some of your personal data in order to use it for a specific purpose to carry out this mission, and to provide you with the best of services.
And because we do care about the protection of your personal data, and master current personal data security issues, we comply with the latest expectations in terms of respect and protection of personal data, and do not sell, nor will we sell, your personal data to third parties.
Your personal data belong to you, Finary adds value to it, but does not take away from it.
When you use the finary.com site (hereinafter the “Site”) and/or the Finary application (hereinafter the “Application”), we collect personal data about you.
Finary acts here as a data controller. Finary is a simplified joint-stock company (société par actions simplifiée), registered with the Paris Trade and Companies Register (RCS Paris) under number 892 357 724, whose registered office is located at 58 rue de Monceau, 75008 Paris (hereinafter “We”).
We collect and protect the personal data of our customers in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “GDPR”) and with French Law No. 78-17 of 6 January 1978 on information technology, data files and civil liberties, in its latest version in force (together, the “Applicable Regulations”).
The purpose of this policy is to inform you of why we collect your personal data, and how we protect it.
Capitalised terms that are not defined in this privacy policy have the meanings assigned to them in Finary’s terms of service, accessible here.
This policy should be read in conjunction with our cookie policy, accessible here.
1. What personal data do we collect?
Personal data is any data that makes it possible to identify an individual directly or by cross-referencing with other data.
We only collect and use the personal data necessary for our business operations and the purposes listed below.
To do so, we collect the following personal data depending on the services used:
- When you browse our Site
- Data relating to your browsing on the Site (in particular, through cookies and trackers, information about your use of the Site such as the pages visited, the links clicked, your referring web page, the browser used, your operating system, your mobile identifier (AAID or IDFA), the technical errors you may encounter, and your IP address).
- Tracking your wealth on our Site or our Application
- Identification data (including your surname, first name, email address, telephone number and age);
- Data relating to your assets (including your investments in shares, digital assets, real estate, and any other assets);
- Connection data (including your IP address, logs, encrypted passwords);
- Economic and financial data (including your account balances, your investment balances, your transaction details, your bank account details (RIB), your bank card data, your login credentials for your bank’s interface).
- Investing through Finary on our Site or our Application
- The personal data listed above and, in addition:
- For investment in digital assets
- Identity verification data (including civil status, title, date of birth and gender, a valid copy of an identity document, a selfie, and other documents as required by the laws in force);
- Investor profile data (including your professional situation, socio-professional category, your salary, your investment knowledge);
- For investment through the subscription of a life insurance contract
- Identity verification data (including civil status, title, date of birth and gender, a valid copy of an identity document, a copy of proof of address, information on the origin of your funds, a selfie, and other documents as required by the laws in force);
- Investor profile data (including your family, professional and wealth situation, your position with regard to borrowings, your financial knowledge, your projects (retirement, savings, purchase, family), your nationality where this is legally required by the insurer as a condition of subscription, our recommendation, the savings choice, the type of portfolio, your project and the planned payments).
- For financial investment advice
- Identity verification data (including civil status, title, date of birth and gender, a valid copy of an identity document, a copy of proof of address, information on the origin of your funds, a selfie, and other documents as required by the laws in force);
- Investor profile data (including your family, professional and wealth situation, your position with regard to borrowings, your financial knowledge, your projects (retirement, savings, purchase, family), your nationality where this is legally required by the insurer as a condition of subscription, our personalised recommendation, the savings choice, the type of portfolio, your project and the planned payments).
Mandatory data is indicated when you provide us with your data. Account creation journeys cannot be completed without providing the information necessary to provide you with our services.
2. On what legal bases, for what purposes and for how long do we keep your personal data?
Purposes
Lawful bases
Retention periods
Provide you with our services (monitoring of your assets, financial independence simulation (predict), and optimisations).
Performance of a contract you have entered into
Your data is kept for the lifetime of your account. If your account is inactive for 2 years, your personal data will be deleted. In addition, your data may be archived for evidentiary purposes for a period of 5 years.
Execute your order, carry out operations relating to customer management concerning contracts, orders, invoices, referral programmes and monitoring of the customer relationship.
Performance of a contract you have entered into
Personal data is kept for the duration of the contractual relationship. In addition, your data is archived for evidentiary purposes for a period of 5 years. Data relating to your bank card is kept by our payment service providers until the termination of your subscription. Data relating to your bank cards may be kept, for evidentiary purposes in the event of a dispute over a transaction, in intermediate archives for a period of thirteen (13) months following the debit date. This period may be extended to fifteen (15) months to account for the possible use of deferred debit cards.
Create a register of customers and prospects.
Our legitimate interest in developing and promoting our business
For customers: the data is kept for the duration of the commercial relationship. For prospects: the data is kept for a period of 3 years from your last contact.
Send newsletters, solicitations and promotional messages.
For customers: our legitimate interest in retaining our customers and keeping them informed of our latest news. For prospects: your consent
The data is kept for 3 years from your last contact.
Produce internal statistics on our users and their use of our services.
Our legitimate interest in improving our services
The data is kept for two years from its collection for statistical purposes.
Produce statistics on investment trends among our users and offer you relevant trends based on your profile. These global trends are shared with all our users, but your identity never appears on other users’ profiles.
Our legitimate interest in offering you relevant investment trends
The data is kept for two years from its collection for statistical purposes.
Deliver personalised advertising.
Your consent
The retention period varies depending on the advertising platform used; contact us at
DPO@finary.com for more details.
Respond to your requests for information and complaints (via our chat, by email or on social media).
Our legitimate interest in responding to your requests
The data is kept for the time necessary to process your request for information, then archived for two years.
Fight against money laundering and terrorist financing, and against fraud (in particular verifying your identity as part of our KYC obligations, taking into account international economic and financial sanctions, verifying the origin of your funds, and transaction screening) as part of the investment service only.
Compliance with our legal and regulatory obligations
For data relating to identity verification and the assessment of an alert (surname, first name, date of birth, home address, complete and valid identity document, biometric data (selfie), IBAN, origin of funds and any other relevant elements collected when entering into the relationship, etc.), the data is kept for 5 years from the closure of the investment account. Retention of alerts qualified as relevant: the data is kept for 5 years from the closure of the reviewed file.
Fight against money laundering and terrorist financing, and against fraud (in particular verifying your identity as part of our KYC obligations, taking into account international economic and financial sanctions, verifying the origin of your funds, and transaction screening) as part of the investment service only.
Compliance with our legal and regulatory obligations
The data is kept by Finary for 5 years from the closure of the investment account; no data is stored by the AI service provider.
Subscribe to a life insurance contract.
Compliance with our legal and regulatory obligations
For data relating to identity verification and the assessment of an alert (surname, first name, date of birth, home address, complete and valid identity document, biometric data (selfie), IBAN, origin of funds and any other relevant elements collected when entering into the relationship, etc.), as well as customer and investor profile data, the data is kept for 5 years from the closure of the investment account.
Receive financial investment advice.
Performance of a contract you have entered into
For data relating to identity verification and the assessment of an alert (surname, first name, date of birth, home address, complete and valid identity document, biometric data (selfie), IBAN, origin of funds and any other relevant elements collected when entering into the relationship, etc.), as well as customer and investor profile data, the data is kept for 5 years from the closure of the investment account.
Withdraw your crypto-assets to your personal wallet.
Compliance with our legal and regulatory obligations
Your wallet address, together with any additional elements that may be requested to confirm that you are the holder of the wallet and that the wallet does not present a particular risk, as well as the handling of any alerts generated by the wallet in question. The data is kept for 5 years from the closure of the investment account.
Manage requests to exercise GDPR rights.
Compliance with our legal and regulatory obligations
If we ask you for proof of identity: we keep it only for the time necessary to verify your identity. Once the verification has been carried out, the proof of identity is deleted. If you exercise your right to object to prospecting: we keep this information for 3 years.
Enable, at your request, the connection of third-party artificial intelligence assistants of your choice to your aggregated financial data, through our connector (MCP).
Your consent, collected when you activate the connector and revocable at any time.
Access tokens and connection logs are kept for 12 months from the revocation of the connector. No data is stored by Finary with the assistant provider.
3. Who are the recipients of your data?
The following will have access to your personal data:
- The staff members of our company;
- Our processors: hosting provider, chat tool, Site and Application analysis and administration provider, bug management provider, newsletter sending provider, our product launch provider, contests, our payment service providers, audience measurement provider, customer request management provider, identity document verification provider, audit and technical analysis provider;
- The service providers we use to deliver personalised advertising (Facebook Ads, Apple Search Ads, Google Ads, Snapchat, TikTok, Twitter and Reddit);
- Our partners for bank account aggregation: Powens and Flanks in Europe and Plaid in the United States. The latter will process the data in accordance with their privacy policies. You can view Powens’ privacy policy here, Flanks’ here, and Plaid’s here;
- Our banking partners (Fiat Republic, here), and our digital asset service partners (Bitstamp here, DFNS here, Aplo here), in order to provide you with our investment service. They apply their respective privacy policies;
- Our compliance solution provider (Onfido here), in order to provide you with our investment service. It applies its own privacy policy;
- Our insurance partners, in the context of the subscription of a life insurance contract. They apply their respective privacy policies;
- Your wealth advisors, for the purpose of supporting you in your financial management when you have entered into a contract with them. They will act as independent data controllers and will apply their respective privacy policies;
- The third-party artificial intelligence assistants (for example Anthropic’s Claude, OpenAI’s ChatGPT) that you choose to connect to your data through our connector: they receive your data solely upon your instruction and act as independent data controllers, in accordance with their respective privacy policies. You can view Anthropic’s privacy policy here, and OpenAI’s here. You can revoke this connection at any time;
- Where applicable: public and private bodies, exclusively to meet our legal obligations.
In the context of the referral programme, referrers are informed that their first and last names will be disclosed to the referred person in order to inform them of the identity of their referrer. Referred persons are informed that their email addresses will be disclosed to the associated referrer in a partially concealed manner, for the purpose of informing the referrer of whether or not the referral has been completed.
4. Are your data likely to be transferred outside the European Union?
Your data is kept and stored for the duration of the processing on the servers of Google (via Google Cloud Platform) in Belgium and Germany, as well as Digital Ocean in the Netherlands.
As part of the tools we use (see the article on recipients concerning our processors), your data may be transferred outside the European Union. The transfer of your data in this context is secured by means of the following tools:
- either the data is transferred to a country that has been the subject of an adequacy decision of the European Commission, in accordance with Article 45 of the GDPR: in this case, that country ensures a level of protection deemed sufficient and adequate to the provisions of the GDPR;
- or the data is transferred to a country whose level of data protection has not been recognised as adequate under the GDPR: in this case, these transfers are based on appropriate safeguards set out in Article 46 of the GDPR, adapted to each provider, including in particular, without limitation, the conclusion of standard contractual clauses approved by the European Commission, the application of binding corporate rules, or an approved certification mechanism;
In addition, if you choose to connect an artificial intelligence assistant to your data through our connector, your data is communicated, upon your instruction, to the provider of that assistant, which may process it outside the European Union in accordance with its own privacy policy. This communication is based on your explicit consent, collected when you activate the connector, which you may withdraw at any time.
You can obtain a copy of the tools enabling the transfer of your data outside the European Union by contacting us at the contact details indicated in the article “Personal data point of contact” below.
5. What are your rights over your data?
You have the following rights with regard to your personal data:
- Right to information: this is precisely why we have written this policy. This right is provided for in Articles 13 and 14 of the GDPR;
- Right of access: you have the right to access all of your personal data at any time, under Article 15 of the GDPR;
- Right of rectification: you have the right to rectify at any time your inaccurate, incomplete or obsolete personal data, in accordance with Article 16 of the GDPR;
- Right to restriction of processing: you have the right to obtain the restriction of the processing of your personal data in certain cases defined in Article 18 of the GDPR;
- Right to erasure: you have the right to demand that your personal data be erased, and to prohibit any future collection, for the reasons set out in Article 17 of the GDPR;
- Right to lodge a complaint with a competent supervisory authority (in France, the CNIL), if you consider that the processing of your personal data constitutes a violation of the applicable texts (Article 77 of the GDPR);
- Right to define directives relating to the storage, erasure and communication of your personal data after your death, in accordance with Article 40-1 of the French Data Protection Act;
- Right to withdraw your consent at any time: for purposes based on consent, Article 7 of the GDPR provides that you may withdraw your consent at any time. This withdrawal will not call into question the lawfulness of the processing carried out before the withdrawal;
- Right to portability: under certain conditions specified in Article 20 of the GDPR, you have the right to receive the personal data that you have provided to us in a standard machine-readable format and to require its transfer to the recipient of your choice;
- Right to object: under Article 21 of the GDPR, you have the right to object to the processing of your personal data. Note, however, that we may continue to process it despite this objection, for legitimate reasons or for the defence of legal claims.
You can exercise these rights by writing to us at the contact details below. We may ask you on this occasion to provide us with additional information or documents to prove your identity.
We have a maximum response time of one month from the date of receipt of the request. If the request made cannot be satisfied immediately, a dated acknowledgement of receipt will be given to you.
If the request is incomplete (for example, if the identity document is missing), we are entitled to request additional elements: the period is then suspended and runs again once these elements have been provided.
Access to these rights is free of charge. In some cases, reasonable costs related to the processing of your file may be requested, for example in the event of a request for an additional copy, or in the event of a particularly complex request.
In accordance with the applicable regulations, you are entitled to lodge a complaint with the CNIL (Commission nationale de l’informatique et des libertés) in the event of an unsatisfactory resolution of your exercise of rights in France. You can access the complaint form by clicking here.
6. Personal data point of contact
Contact email of our Data Protection Officer: DPO@finary.com
Contact address: Finary SAS, 58 rue de Monceau, 75008 Paris
7. Updates
We may update this policy at any time, in particular to comply with any regulatory, case law, editorial or technical developments. These modifications will apply on the effective date of the modified version. You are therefore invited to regularly consult the latest version of this policy. Nevertheless, we will keep you informed of any significant changes to this privacy policy.