Privacy Policy
In short: this is a private, self-hosted household finance tool used by one family to view their own bank accounts. It reads account data only, never initiates payments, shares nothing with third parties, and runs no analytics or advertising.
1. Who this policy covers
This policy applies to the Verdianz FIRE Dashboard ("the application"), a private, self-hosted personal-finance application. It is not a public service: it has no sign-up, no customers, and is used solely by the members of the operator's own household to view their own bank accounts.
2. Controller and contact
Data controller: Thomas Verdianz, Austria, acting in a private capacity. He alone determines the purposes and means of the processing described here, and he operates the server the data sits on.
This is a personal application. No company or business is involved in it, no business or client data is processed by it, and none of the accounts it connects to are company accounts.
For any data-protection matter, including requests under the GDPR: thomas@verdianz.com
3. What data is processed
- Account details of the household's own bank accounts: account name, currency, and a masked IBAN (country prefix and last four characters only — the full IBAN is discarded at the point of retrieval and is not stored).
- Account balances.
- Transaction records: booking and value dates, amounts, currency, counterparty name, payment reference and remittance text, and the transaction status.
- Data derived from the above: spend categories, budgets, recurring-payment series, and alerts.
No card numbers are stored. No location data, device identifiers, browsing history or behavioural data are collected.
4. Where the data comes from
Bank data is retrieved through Enable Banking Oy (Otakaari 5, 02150 Espoo, Finland), a registered Account Information Service Provider supervised by the Finnish Financial Supervisory Authority (FIN-FSA). Retrieval happens under the PSD2 account-information service, and only after the relevant account holder has explicitly authorised it at their own bank.
Access is read-only. The application holds no payment-initiation permission and cannot move money.
5. Purpose and legal basis
The data is processed to produce categorised spend analysis, household budgeting and subscription and anomaly alerts for the household's own finances.
The legal basis is consent under Article 6(1)(a) GDPR, given separately per bank account through the bank's own authorisation flow. Consent is time-limited by the bank (typically up to 180 days) and must be renewed.
6. Accounts held by children
Where an account belongs to a child under 18, it is accessed by that child's guardian, who holds the online-banking access for that account and authorises it in the same way. The data is used only for household budgeting and is visible only to the two adults in the household.
7. Storage, retention and access
Data is stored in a database on a private server operated by the controller at home. It is not stored on any public cloud service. Access requires authentication, and administrative actions require a second credential.
Data is retained until deleted by the controller. There is no fixed retention period, because the purpose — understanding household spending over time — depends on history being kept.
The application writes no financial data to its logs.
8. Who the data is shared with
Nobody. The data is not sold, rented, shared, or transferred to any third party. There is no advertising, no third-party analytics, and no tracking of any kind on the pages that display it.
The only external party involved is Enable Banking Oy, which acts as the regulated intermediary that retrieves the data from the banks under PSD2. Its own privacy notice governs that processing.
9. Your rights
As data subjects, the household members may at any time request access to, rectification of, or erasure of their data, request restriction of processing, or object to processing. Because the controller operates the application directly, such requests are actioned immediately.
Consent can be withdrawn at any time by revoking the bank's authorisation in online banking, or by deleting the connection in the application. Either stops all further retrieval.
Complaints may be lodged with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna.
10. Changes
If this policy changes, the "last updated" date above changes with it.