Privacy and Data Protection Policy

1. Introduction and Scope


This Policy describes how Bankingly collects, uses, processes, and protects information during the course of providing its Electronic Banking as a Service (SaaS). Bankingly operates under the Data Processor model in accordance with SOC 2 standards. Our clients, the Financial Institutions (hereinafter, "The FI" or "The Controller"), act as the Data Controllers and owners of their end-users'

data.

2. Data Classification and Collection


Bankingly adheres to the Data Minimization principle. We strictly

distinguish between the data we store and the data we simply process in transit. All end-customer data is critical to Bankingly; no explicit classification of data is made, as all are considered of high importance and subject to our security policies.



2.1. Stored Data (Persistent)


Bankingly only stores information essential for managing

identity, security, and audit. This includes:

• Limited Personally Identifiable Information (PII): First name,

last name, phone number, and email address.

• Device Information: Device identifiers, security tokens,

IP addresses, and geolocation (if applicable for fraud prevention).

• Audit Logs: Activity records, access times, and operation traces for security compliance and traceability.





2.2. Financial Data (Not Stored / In Transit)

Bankingly does NOT store sensitive financial information at rest in its

databases.



• Types of data: Balances, full credit/debit card numbers,

and bank statements are stored in the core of the financial institution and not in Bankingly's infrastructure. • Mechanism: This information resides exclusively in the FI's Core Banking

system. Bankingly queries this information in real time through

secure channels, only after successful user authentication, for front-end visualization. Once the session is ended, this

information does not persist in Bankingly's infrastructure.



2.3. Additional Data

Any storage of additional data required by the FI will be carried out under

a specific and documented request, always respecting the criteria of not

storing unnecessary information for the provision of the service.

3. Roles and Responsibilities



3.1. Responsibility of the Financial Institution (Controller)

• Relationship with the End User: The FI is solely responsible for obtaining consent from its users (clients/members) for data processing. The FI may carry out any extra external procedures to

Bankingly before accepting the registration of a user on the platform.

• Terms and Conditions: The FI must generate and manage the Terms and

Conditions and Privacy Policies that end users accept to use the channels provided by Bankingly.

• Processing Instructions: The FI determines the purposes and

means of processing the data.



3.2. Responsibility of Bankingly (Processor)

• Process personal data strictly following the instructions

documented in the service agreement with the FI.

• Implement technical and organizational measures to ensure data

security.

4. Data Retention and Disposal



4.1. Retention Periods


The data stored by Bankingly is retained strictly within the timeframes established in:


1. The service agreements (MSA) signed with the FI.

2. Applicable legal requirements for audit and security logs. 3. If the Financial Institution desires a special retention period, it must be specified in the contract. The FI can request full backups of the DB and apply its own data retention policy.

4.2. Deletion and Return



Upon termination of the contractual relationship or after a specific request from the FI:

• The FI may request the secure deletion (sanitization) of its users' data

stored in Bankingly.

• The FI may request full backups of the information to

apply its own retention policies.

• Bankingly will certify the destruction of the data once the

retention period has expired or the request has been processed, unless conservation is required by law.

5. Information Security (SOC 2)



Bankingly implements security controls aligned with SOC 2 to protect the confidentiality and integrity of data:



• Encryption: All data is encrypted in transit (TLS 1.2 or higher) and at

rest (AES-256) for stored information.

• Access Control: Access to data by Bankingly personnel

is restricted under the principle of "least privilege" and requires

multi-factor authentication (MFA).

• User Authentication: Access to financial information requires

user identification, an active session, and defined security factors.

6. Rights of Data Subjects (End Users)



Since Bankingly is not the owner of the data:

• Any request for access, rectification, cancellation, or opposition

(ARCO/GDPR rights) by an end user must be directed to the Financial Institution.

• Bankingly will assist the FI in responding to such requests when formally required by the FI, ensuring that the request complies with

contractual conditions.

7. Transfers and Sub-processors



Bankingly will not share data with third parties except for:

• Infrastructure providers (e.g., AWS/Azure) necessary for operations,

who must also comply with security standards. • Legal or judicial requirements, with prior notification to the FI (if permitted

by law).

1. Introduction and Scope


This Policy describes how Bankingly collects, uses, processes, and protects information in the course of providing its Electronic Banking as a Service (SaaS) services. Bankingly operates under the Data Processor model in accordance with SOC 2 standards. Our clients, the Financial Institutions (hereinafter, "The FI" or "The Controller"), act as the Data Controllers and owners of their end

users' data.

2. Data Classification and Collection


Bankingly adheres to the Data Minimization principle. We strictly

distinguish between the data we store and the data we simply process in transit. Any end-customer data is critical for Bankingly; there is no explicit categorization of data because all are considered of high importance and subject to our security policies.



2.1. Stored (Persistent) Data


Bankingly stores only the essential information for identity management,

security, and auditing. This includes:

• Limited Personally Identifiable Information (PII): First names,

last names, telephone number, and email address.

• Device Information: Device identifiers, security tokens,

IP addresses, and geolocation (if applicable for fraud prevention).

• Audit Logs: Activity logs, access times, and operation traces for security compliance and traceability.





2.2. Financial Data (Not Stored / In Transit)

Bankingly does NOT store sensitive financial information at rest

in its databases.



• Types of data: Balances, full credit/debit card numbers,

and account statements are stored in the core of the financial institution and not in Bankingly's infrastructure. • Mechanism: This information resides exclusively in the FI's Core Banking

system. Bankingly queries this information in real-time through

secure channels, only after successful user authentication, for front-end visualization. Once the session is closed, this

information does not persist in Bankingly's infrastructure.



2.3. Additional Data

Any additional database storage required by the FI will be performed under

a specific and documented request, always respecting the criteria of not

storing unnecessary information for the provision of the service.

3. Roles and Responsibilities


3.1. Responsibility of the Financial Institution (Controller)

• Relationship with the End User: The FI is solely responsible for obtaining the consent of its users (clients/members) for data processing. The FI may carry out any extra external procedure outside of

Bankingly before accepting the registration of a user on the platform.

• Terms and Conditions: The FI must generate and manage the Terms and

Conditions and Privacy Policies that end users accept in order to use the channels provided by Bankingly.

• Processing Instructions: The FI determines the purpose and

means of the data processing.


3.2. Responsibility of Bankingly (Processor)

• Process personal data strictly following the instructions

documented in the service contract with the FI.

• Implement technical and organizational measures to ensure data

security.

4. Data Retention and Disposal


4.1. Retention Periods

The data stored by Bankingly is retained strictly for the periods established in:

1. The service agreements (MSA) signed with the FI.

2. Legal requirements applicable to audit and security logs. 3. If the Financial Institution desires a special retention period, it must be specified in the contract. The FI can request full backups of the DB and apply its own data retention policy.

4.2. Erasure and Return


At the end of the contractual relationship or upon specific request from the FI:

• The FI may request the secure erasure (sanitization) of its users' data

stored in Bankingly.

• The FI may request total backups of the information to

apply its own retention policies.

• Bankingly will certify the destruction of the data once the

retention period has expired or the request has been processed, unless conservation is required by law.

5. Information Security (SOC 2)


Bankingly implements security controls aligned with SOC 2 to protect the confidentiality and integrity of data:


• Encryption: All data is encrypted in transit (TLS 1.2 or higher) and at

rest (AES-256) for stored information.

• Access Control: Access to data by Bankingly personnel is

restricted under the "least privilege" principle and requires

multi-factor authentication (MFA).

• User Authentication: Access to financial information requires

user identification, an active session, and defined security factors.

6. Rights of Data Subjects (End Users)


Given that Bankingly is not the owner of the data:

• Any request for access, rectification, cancellation, or objection

(ARCO/GDPR rights) by an end user must be directed to the Financial Institution.

• Bankingly will assist the FI in responding to such requests when formally requested by the FI, ensuring that the request complies with

contractual conditions.

7. Transfers and Sub-processors


Bankingly will not share data with third parties except:

• Infrastructure providers (e.g., AWS/Azure) necessary for the

operation, who must also comply with security standards. • Legal or judicial requirements, with prior notification to the FI (if permitted

by law).