Privacy Policy

Verdianz FIRE Dashboard · Last updated 3 August 2026

In short: this is a private, self-hosted household finance tool used by one family to view their own bank accounts. It reads account data only, never initiates payments, shares nothing with third parties, and runs no analytics or advertising.

1. Who this policy covers

This policy applies to the Verdianz FIRE Dashboard ("the application"), a private, self-hosted personal-finance application. It is not a public service: it has no sign-up, no customers, and is used solely by the members of the operator's own household to view their own bank accounts.

2. Controller and contact

Data controller: Thomas Verdianz, Austria, acting in a private capacity. He alone determines the purposes and means of the processing described here, and he operates the server the data sits on.

This is a personal application. No company or business is involved in it, no business or client data is processed by it, and none of the accounts it connects to are company accounts.

For any data-protection matter, including requests under the GDPR: thomas@verdianz.com

3. What data is processed

No card numbers are stored. No location data, device identifiers, browsing history or behavioural data are collected.

4. Where the data comes from

Bank data is retrieved through Enable Banking Oy (Otakaari 5, 02150 Espoo, Finland), a registered Account Information Service Provider supervised by the Finnish Financial Supervisory Authority (FIN-FSA). Retrieval happens under the PSD2 account-information service, and only after the relevant account holder has explicitly authorised it at their own bank.

Access is read-only. The application holds no payment-initiation permission and cannot move money.

5. Purpose and legal basis

The data is processed to produce categorised spend analysis, household budgeting and subscription and anomaly alerts for the household's own finances.

The legal basis is consent under Article 6(1)(a) GDPR, given separately per bank account through the bank's own authorisation flow. Consent is time-limited by the bank (typically up to 180 days) and must be renewed.

6. Accounts held by children

Where an account belongs to a child under 18, it is accessed by that child's guardian, who holds the online-banking access for that account and authorises it in the same way. The data is used only for household budgeting and is visible only to the two adults in the household.

7. Storage, retention and access

Data is stored in a database on a private server operated by the controller at home. It is not stored on any public cloud service. Access requires authentication, and administrative actions require a second credential.

Data is retained until deleted by the controller. There is no fixed retention period, because the purpose — understanding household spending over time — depends on history being kept.

The application writes no financial data to its logs.

8. Who the data is shared with

Nobody. The data is not sold, rented, shared, or transferred to any third party. There is no advertising, no third-party analytics, and no tracking of any kind on the pages that display it.

The only external party involved is Enable Banking Oy, which acts as the regulated intermediary that retrieves the data from the banks under PSD2. Its own privacy notice governs that processing.

9. Your rights

As data subjects, the household members may at any time request access to, rectification of, or erasure of their data, request restriction of processing, or object to processing. Because the controller operates the application directly, such requests are actioned immediately.

Consent can be withdrawn at any time by revoking the bank's authorisation in online banking, or by deleting the connection in the application. Either stops all further retrieval.

Complaints may be lodged with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna.

10. Changes

If this policy changes, the "last updated" date above changes with it.