Legal & Compliance

Privacy Policy

How Fintory collects, uses, shares and protects personal data, and the rights you have under the GDPR and other applicable data protection laws.

Last updated: 5 October 2026

1. Who we are (Data Controller)

Fintory ("Fintory", "we", "us") operates the Fintory fintech factory platform and the website at fintory.tech. We are the data controller for personal data collected through this website and through our sales and business contacts. When we provide platform services to a business customer, that customer is normally the controller and we act as its data processor.

Privacy contact: vm@fintory.tech. This is also the address for exercising your data protection rights.

2. Personal data we collect

  • Contact and business data you submit: full name, company, job title, email address, phone number, country, industry and your project description (for example through the Leave a Request form).
  • Communication data: the content of messages, emails and meeting notes exchanged with our team.
  • Recruitment and partner data: information you choose to send us about your company, investors or team.
  • Technical data: IP address, browser type, device type, referring page and pages visited, collected only through essential cookies and, with your consent, analytics.
  • Platform data: if you are granted access to our internal or demo environments, we process account credentials and activity logs required to operate and secure those environments.

We do not intentionally collect special categories of personal data (such as health, biometric or political data). Please do not send us such information unless we specifically request it in writing.

3. Why we use it and our legal bases

  • To respond to your enquiry and prepare a proposal or demo — necessary to take steps at your request before entering into a contract.
  • To provide, operate and support our platform and website — performance of our contract with you or your employer.
  • To improve our products, understand demand and measure the performance of our website — our legitimate interests in developing our business, or your consent where analytics cookies are involved.
  • To send relevant product, event and service updates — your consent, or our legitimate interest in direct business-to-business marketing where permitted, and you can opt out at any time.
  • To meet legal, regulatory, tax and audit obligations, including KYC/AML requirements where they apply — compliance with a legal obligation.
  • To protect our services, prevent fraud, abuse and security incidents and enforce our terms — our legitimate interests in keeping our services safe.

4. Cookies and similar technologies

We use essential cookies and local storage to operate this website and to remember your cookie consent and accessibility preferences. Analytics cookies are used only after you consent, and we do not use advertising, profiling or cross-site tracking cookies. You can change or withdraw your choice at any time through "Cookie Settings" in the website footer.

Full details are set out in our Cookie Policy, which forms part of this Privacy Policy.

5. Who we share data with

We do not sell personal data. We share it only where necessary, with:

  • Service providers acting as our processors: cloud hosting and infrastructure providers, email and communication providers, customer relationship management and analytics providers, and professional advisers (legal, accounting, audit).
  • Our own sub-processors used to deliver the platform, under written data processing terms.
  • Regulators, courts, law enforcement or other authorities where required by law or to establish, exercise or defend legal claims.
  • A buyer or successor in the context of a merger, acquisition or asset sale, subject to this Privacy Policy.

Every processor is bound by contract to process personal data only on our instructions and to apply appropriate technical and organisational security measures. A current list of sub-processors is available on request from vm@fintory.tech.

6. International transfers

We may transfer personal data to countries outside the European Economic Area, the United Kingdom or your own jurisdiction, including to providers located in the United States and Israel. Where we do so, we rely on an appropriate transfer mechanism — the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision covering the destination country — together with additional safeguards where required.

7. How long we keep data

  • Sales enquiries and contact records: up to 24 months after our last interaction, unless we agree a longer relationship or you ask us to delete earlier.
  • Contract, invoicing and compliance records: for the period required by applicable tax, accounting and anti-money-laundering rules.
  • Website analytics: no longer than 14 months in aggregated or pseudonymised form.
  • Cookie and accessibility preferences stored in your browser: until you clear them or change your choice.

8. Your rights

Subject to the conditions in the GDPR and other applicable laws, you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data (the right to be forgotten) where we no longer need it or processing is unlawful.
  • Restrict or object to processing, including profiling and direct marketing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Lodge a complaint with your local supervisory authority.

To exercise any of these rights, email vm@fintory.tech. We respond within one month. We may ask for information to confirm your identity before acting. California residents have additional rights under the CCPA/CPRA, including the right to know, delete and correct, and the right not to be discriminated against; we do not sell or share personal information for cross-context behavioural advertising.

9. Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access control on a need-to-know basis, role-based permissions, secrets management, logging and monitoring, secure development practices and vendor due diligence. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority without undue delay and, where required, affected individuals.

10. Children

Our website and services are intended for businesses and professional users. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Automated decision-making

Our platform includes risk-scoring, credit-intelligence and fraud-detection capabilities that may be used by our customers in their own environments. Decisions with legal or similarly significant effects remain subject to human review, and we do not use this website to make automated decisions about website visitors. Where such processing is used on our customers' behalf, it is governed by our data processing agreement with them.

12. Changes to this policy

We may update this Privacy Policy to reflect changes in our services or in applicable law. The "Last updated" date at the top of this page always shows the current version. Material changes will be highlighted on this page.

13. Contact

For any question about this Privacy Policy, your personal data, a data processing agreement or our sub-processors, contact vm@fintory.tech. Requests relating to GDPR or UK GDPR can also be sent to this address, which is monitored by our privacy team.