Privacy Policy

Last updated: July 2026

Draft under review: this document is undergoing legal review and may change before launch.

1. Data controller

The controller of personal data collected through the Dispendo app and the dispendo.app website is [COMPANY / NAME], registered at [ADDRESS]. For any data request: privacy@dispendo.app.

2. Data we process

Account data: email and login credentials (managed by the authentication provider, never in plain text).

Read-only banking data obtained via Open Banking (PSD2) with your authorization: transactions, balances, identifiers of connected accounts. Your banking credentials never pass through our systems.

Aggregated app-usage data, to improve the service.

3. Purposes and legal bases

We process data to provide the service (performance of contract), to comply with legal obligations and — only with consent — for clearly stated optional purposes.

Automatic transaction categorization is an essential part of the service: it runs on local rules, caches and aggregated suggestions; only ambiguous cases are sent to an AI service in minimized, anonymous form (cleaned merchant name, amount, technical codes; never IBANs, people's names or full references).

4. Open Banking (PSD2)

Account connections are established through an AIS provider authorized under Directive (EU) 2015/2366 (PSD2). Authorization is granted by you directly to your bank, is read-only and can be revoked at any time from the app or the bank.

5. Retention

We keep data for as long as needed to provide the service and in any case no longer than legally required. When you close your account, personal data is deleted or anonymized within [N] days.

6. Your rights (GDPR)

You have the rights of access, rectification, erasure, restriction, portability and objection under Articles 15–22 GDPR, plus the right to lodge a complaint with your supervisory authority. Write to privacy@dispendo.app.

7. Contact

For any question about this notice: privacy@dispendo.app.