1. Data controller
The controller of personal data collected through the Dispendo app and the dispendo.app website is [COMPANY / NAME], registered at [ADDRESS]. For any data request: privacy@dispendo.app.
2. Data we process
Account data: email and login credentials (managed by the authentication provider, never in plain text).
Read-only banking data obtained via Open Banking (PSD2) with your authorization: transactions, balances, identifiers of connected accounts. Your banking credentials never pass through our systems.
Aggregated app-usage data, to improve the service.
3. Purposes and legal bases
We process data to provide the service (performance of contract), to comply with legal obligations and — only with consent — for clearly stated optional purposes.
Automatic transaction categorization is an essential part of the service: it runs on local rules, caches and aggregated suggestions; only ambiguous cases are sent to an AI service in minimized, anonymous form (cleaned merchant name, amount, technical codes; never IBANs, people's names or full references).
4. Open Banking (PSD2)
Account connections are established through an AIS provider authorized under Directive (EU) 2015/2366 (PSD2). Authorization is granted by you directly to your bank, is read-only and can be revoked at any time from the app or the bank.
5. Retention
We keep data for as long as needed to provide the service and in any case no longer than legally required. When you close your account, personal data is deleted or anonymized within [N] days.
6. Your rights (GDPR)
You have the rights of access, rectification, erasure, restriction, portability and objection under Articles 15–22 GDPR, plus the right to lodge a complaint with your supervisory authority. Write to privacy@dispendo.app.
7. Contact
For any question about this notice: privacy@dispendo.app.