Privacy and Data Protection Policy
1. Introduction and Scope
This Policy describes how Bankingly collects, uses, processes, and protects information during the course of providing its Electronic Banking as a Service (SaaS). Bankingly operates under the Data Processor model in accordance with SOC 2 standards. Our clients, the Financial Institutions (hereinafter, "The FI" or "The Controller"), act as the Data Controllers and owners of their end-users'
data.
2. Data Classification and Collection
Bankingly adheres to the Data Minimization principle. We strictly
distinguish between the data we store and the data we simply process in transit. All end-customer data is critical to Bankingly; no explicit classification of data is made, as all are considered of high importance and subject to our security policies.
2.1. Stored Data (Persistent)
Bankingly only stores information essential for managing
identity, security, and audit. This includes:
• Limited Personally Identifiable Information (PII): First name,
last name, phone number, and email address.
• Device Information: Device identifiers, security tokens,
IP addresses, and geolocation (if applicable for fraud prevention).
• Audit Logs: Activity records, access times, and operation traces for security compliance and traceability.
2.2. Financial Data (Not Stored / In Transit)
Bankingly does NOT store sensitive financial information at rest in its
databases.
• Types of data: Balances, full credit/debit card numbers,
and bank statements are stored in the core of the financial institution and not in Bankingly's infrastructure. • Mechanism: This information resides exclusively in the FI's Core Banking
system. Bankingly queries this information in real time through
secure channels, only after successful user authentication, for front-end visualization. Once the session is ended, this
information does not persist in Bankingly's infrastructure.
2.3. Additional Data
Any storage of additional data required by the FI will be carried out under
a specific and documented request, always respecting the criteria of not
storing unnecessary information for the provision of the service.
3. Roles and Responsibilities
3.1. Responsibility of the Financial Institution (Controller)
• Relationship with the End User: The FI is solely responsible for obtaining consent from its users (clients/members) for data processing. The FI may carry out any extra external procedures to
Bankingly before accepting the registration of a user on the platform.
• Terms and Conditions: The FI must generate and manage the Terms and
Conditions and Privacy Policies that end users accept to use the channels provided by Bankingly.
• Processing Instructions: The FI determines the purposes and
means of processing the data.
3.2. Responsibility of Bankingly (Processor)
• Process personal data strictly following the instructions
documented in the service agreement with the FI.
• Implement technical and organizational measures to ensure data
security.
4. Data Retention and Disposal
4.1. Retention Periods
The data stored by Bankingly is retained strictly within the timeframes established in:
1. The service agreements (MSA) signed with the FI.
2. Applicable legal requirements for audit and security logs. 3. If the Financial Institution desires a special retention period, it must be specified in the contract. The FI can request full backups of the DB and apply its own data retention policy.
4.2. Deletion and Return
Upon termination of the contractual relationship or after a specific request from the FI:
• The FI may request the secure deletion (sanitization) of its users' data
stored in Bankingly.
• The FI may request full backups of the information to
apply its own retention policies.
• Bankingly will certify the destruction of the data once the
retention period has expired or the request has been processed, unless conservation is required by law.
5. Information Security (SOC 2)
Bankingly implements security controls aligned with SOC 2 to protect the confidentiality and integrity of data:
• Encryption: All data is encrypted in transit (TLS 1.2 or higher) and at
rest (AES-256) for stored information.
• Access Control: Access to data by Bankingly personnel
is restricted under the principle of "least privilege" and requires
multi-factor authentication (MFA).
• User Authentication: Access to financial information requires
user identification, an active session, and defined security factors.
6. Rights of Data Subjects (End Users)
Since Bankingly is not the owner of the data:
• Any request for access, rectification, cancellation, or opposition
(ARCO/GDPR rights) by an end user must be directed to the Financial Institution.
• Bankingly will assist the FI in responding to such requests when formally required by the FI, ensuring that the request complies with
contractual conditions.
7. Transfers and Sub-processors
Bankingly will not share data with third parties except for:
• Infrastructure providers (e.g., AWS/Azure) necessary for operations,
who must also comply with security standards. • Legal or judicial requirements, with prior notification to the FI (if permitted
by law).
1. Introduction and Scope
This Policy describes how Bankingly collects, uses, processes, and protects information in the course of providing its Electronic Banking as a Service (SaaS) services. Bankingly operates under the Data Processor model in accordance with SOC 2 standards. Our clients, the Financial Institutions (hereinafter, "The FI" or "The Controller"), act as the Data Controllers and owners of their end
users' data.
2. Data Classification and Collection
Bankingly adheres to the Data Minimization principle. We strictly
distinguish between the data we store and the data we simply process in transit. Any end-customer data is critical for Bankingly; there is no explicit categorization of data because all are considered of high importance and subject to our security policies.
2.1. Stored (Persistent) Data
Bankingly stores only the essential information for identity management,
security, and auditing. This includes:
• Limited Personally Identifiable Information (PII): First names,
last names, telephone number, and email address.
• Device Information: Device identifiers, security tokens,
IP addresses, and geolocation (if applicable for fraud prevention).
• Audit Logs: Activity logs, access times, and operation traces for security compliance and traceability.
2.2. Financial Data (Not Stored / In Transit)
Bankingly does NOT store sensitive financial information at rest
in its databases.
• Types of data: Balances, full credit/debit card numbers,
and account statements are stored in the core of the financial institution and not in Bankingly's infrastructure. • Mechanism: This information resides exclusively in the FI's Core Banking
system. Bankingly queries this information in real-time through
secure channels, only after successful user authentication, for front-end visualization. Once the session is closed, this
information does not persist in Bankingly's infrastructure.
2.3. Additional Data
Any additional database storage required by the FI will be performed under
a specific and documented request, always respecting the criteria of not
storing unnecessary information for the provision of the service.
3. Roles and Responsibilities
3.1. Responsibility of the Financial Institution (Controller)
• Relationship with the End User: The FI is solely responsible for obtaining the consent of its users (clients/members) for data processing. The FI may carry out any extra external procedure outside of
Bankingly before accepting the registration of a user on the platform.
• Terms and Conditions: The FI must generate and manage the Terms and
Conditions and Privacy Policies that end users accept in order to use the channels provided by Bankingly.
• Processing Instructions: The FI determines the purpose and
means of the data processing.
3.2. Responsibility of Bankingly (Processor)
• Process personal data strictly following the instructions
documented in the service contract with the FI.
• Implement technical and organizational measures to ensure data
security.
4. Data Retention and Disposal
4.1. Retention Periods
The data stored by Bankingly is retained strictly for the periods established in:
1. The service agreements (MSA) signed with the FI.
2. Legal requirements applicable to audit and security logs. 3. If the Financial Institution desires a special retention period, it must be specified in the contract. The FI can request full backups of the DB and apply its own data retention policy.
4.2. Erasure and Return
At the end of the contractual relationship or upon specific request from the FI:
• The FI may request the secure erasure (sanitization) of its users' data
stored in Bankingly.
• The FI may request total backups of the information to
apply its own retention policies.
• Bankingly will certify the destruction of the data once the
retention period has expired or the request has been processed, unless conservation is required by law.
5. Information Security (SOC 2)
Bankingly implements security controls aligned with SOC 2 to protect the confidentiality and integrity of data:
• Encryption: All data is encrypted in transit (TLS 1.2 or higher) and at
rest (AES-256) for stored information.
• Access Control: Access to data by Bankingly personnel is
restricted under the "least privilege" principle and requires
multi-factor authentication (MFA).
• User Authentication: Access to financial information requires
user identification, an active session, and defined security factors.
6. Rights of Data Subjects (End Users)
Given that Bankingly is not the owner of the data:
• Any request for access, rectification, cancellation, or objection
(ARCO/GDPR rights) by an end user must be directed to the Financial Institution.
• Bankingly will assist the FI in responding to such requests when formally requested by the FI, ensuring that the request complies with
contractual conditions.
7. Transfers and Sub-processors
Bankingly will not share data with third parties except:
• Infrastructure providers (e.g., AWS/Azure) necessary for the
operation, who must also comply with security standards. • Legal or judicial requirements, with prior notification to the FI (if permitted
by law).
The results
begin here

SOLUTIONS
Rbla. Mahatma Gandhi 409 Montevideo, Uruguay.
425 Madison Avenue New York, NY. USA
The results
begin here
SOLUTIONS
Rbla. Mahatma Gandhi 409 Montevideo, Uruguay.
425 Madison Avenue New York, NY. USA
The results
begin here

SOLUTIONS
Rbla. Mahatma Gandhi 409 Montevideo, Uruguay.
425 Madison Avenue New York, NY. USA