01Who we are
The controller responsible for the processing described in this Privacy Policy is:
In this Privacy Policy, “FinDech,” “we,” “us,” and “our” refer to FinDech UAB.
For questions about this Privacy Policy or the processing of your personal data, contact us at info@findech.com.
02Scope of this Privacy Policy
This Privacy Policy applies when FinDech acts as a controller and determines why and how personal data is processed for its own corporate purposes.
It does not automatically govern:
- a payment account, wallet, card, exchange, digital-asset, investment, brokerage, lending, custody, or other financial product;
- services supplied through a FinDech portfolio brand;
- a customer portal, developer platform, API, sandbox, dashboard, application, or restricted-access service;
- employment data processed after a person joins FinDech;
- processing performed by FinDech solely on behalf of another organisation as its processor or service provider; or
- third-party websites, applications, products, or services.
Those activities may be governed by separate privacy notices, product terms, contractual documentation, or the privacy policy of another controller.
Where FinDech processes personal data on behalf of a customer, partner, portfolio operator, or other controller, that organisation determines the relevant purposes and means of processing. Requests concerning that processing should normally be directed to the relevant controller.
03Portfolio brands and other companies
The Website may refer to products, projects, portfolio brands, affiliated companies, partners, or services connected with FinDech.
A portfolio brand may be:
- operated by FinDech;
- operated by an affiliate or another company;
- developed by FinDech but supplied by a separate operator;
- operated together with a commercial or regulated partner; or
- in development, testing, pilot, or pre-launch status.
FinDech UAB is not necessarily the controller for every portfolio brand or product mentioned on the Website.
Before using a portfolio product, review the privacy notice displayed by that product. That notice should identify the relevant controller and explain the processing applicable to the product.
04What is personal data?
Personal data is information relating to an identified or identifiable natural person.
It may include information that identifies you directly, such as your name or email address, and information that can identify you indirectly when combined with other data, such as an IP address, professional role, device identifier, or communication history.
Information relating only to a legal entity is not normally personal data. However, information about a company’s employees, directors, shareholders, beneficial owners, representatives, or contact persons may be personal data.
05Personal data we collect
The personal data we collect depends on how you interact with FinDech.
5.1Information you provide directly
When you complete a form, email us, request information, arrange a meeting, or otherwise communicate with us, we may collect:
- first and last name;
- work or personal email address;
- telephone number;
- employer, organisation, or portfolio brand;
- job title, department, or professional role;
- country, jurisdiction, or business location;
- the subject and content of your inquiry;
- information contained in attachments;
- communication preferences;
- meeting availability;
- correspondence and communication history; and
- any other information you choose to provide.
5.2Business and relationship data
When you represent a customer, prospective customer, partner, supplier, investor, adviser, regulator, authority, service provider, or other organisation, we may collect:
- professional contact information;
- the nature of your relationship with the organisation;
- records of meetings, proposals, discussions, and negotiations;
- business requirements and requested services;
- technical, commercial, compliance, or jurisdictional requirements;
- due-diligence status;
- contract and account-management information;
- invoicing or payment-administration information;
- records of approvals and authorised representatives; and
- information necessary to establish, manage, or terminate the relationship.
5.3Recruitment data
If you apply for a role or send us professional information concerning employment, contracting, advisory work, or an internship, we may collect:
- name and contact details;
- curriculum vitae or résumé;
- employment and education history;
- qualifications, skills, and experience;
- professional profiles and portfolio links;
- language abilities;
- compensation and availability information;
- interview notes;
- references, where appropriate;
- right-to-work or location information; and
- other information you voluntarily provide.
A more specific recruitment privacy notice may be provided if FinDech introduces a formal recruitment platform or process.
5.4Technical and usage data
When you access the Website, FinDech and its hosting, network, or security providers may automatically process technical information such as:
- IP address;
- approximate location derived from an IP address;
- browser type and version;
- device type;
- operating system;
- language and time-zone settings;
- requested pages and files;
- date and time of requests;
- referring page or website;
- response status and technical errors;
- security events;
- session or request identifiers; and
- other server, hosting, network, or diagnostic information.
This information may be recorded in server, infrastructure, firewall, security, and error logs even where no cookie is stored on your device.
5.6Information from third parties
We may receive professional or business-related personal data from:
- your employer or organisation;
- a colleague or authorised representative;
- an existing customer, partner, supplier, or adviser;
- a portfolio company or portfolio brand;
- an event organiser;
- a professional networking platform;
- a recruitment agency or professional reference;
- a publicly accessible company website;
- a public business, corporate, professional, sanctions, or regulatory register; or
- another person who introduces or refers you to FinDech.
Where required, we will provide information about the processing within the applicable legal period.
5.7Publicly available information
For legitimate corporate, compliance, due-diligence, recruitment, or business-development purposes, we may review information that you have made publicly available in a professional or business context.
This may include:
- professional biographies;
- company websites;
- professional networking profiles;
- business-register information;
- regulatory-register information;
- published articles, conference materials, or interviews; and
- other public professional information relevant to a proposed relationship.
We do not use this provision as permission to collect unlimited personal information or to circumvent privacy settings or access restrictions.
06Sensitive personal data
The public Website and general contact channels are not intended for the collection of:
- health information;
- biometric or genetic data;
- information concerning racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- information concerning a person’s sex life or sexual orientation;
- criminal-conviction information;
- government identification documents;
- private cryptographic keys or recovery phrases;
- payment-card authentication data;
- passwords or security codes; or
- detailed personal financial account information.
Please do not send this information through a public contact form or ordinary email unless FinDech has specifically requested it through an appropriate secure process.
If you voluntarily provide sensitive information that is not required, we may delete it, restrict access to it, or process it only where a lawful basis and appropriate safeguards exist.
07Why we process personal data
We process personal data only where there is a lawful basis for doing so.
The applicable basis depends on the purpose and circumstances of the processing.
7.1Operating and securing the Website
We process technical and usage data to:
- deliver Website content;
- maintain Website availability;
- diagnose technical problems;
- prevent fraud, spam, attacks, and misuse;
- investigate security incidents;
- enforce our Terms & Conditions;
- protect FinDech, Website visitors, and third parties; and
- maintain appropriate records of security and operational events.
The legal basis is normally FinDech’s legitimate interest in operating a secure and reliable corporate website.
Processing may also be necessary to comply with a legal obligation.
7.2Responding to inquiries
We process contact and communication data to:
- receive and respond to inquiries;
- provide requested information;
- identify the appropriate FinDech team or portfolio contact;
- arrange calls and meetings;
- assess whether FinDech can provide a requested service;
- prepare proposals or preliminary commercial information; and
- take steps requested before entering into a contract.
The legal basis may be:
- taking steps at your request before entering into a contract;
- performing a contract;
- FinDech’s legitimate interest in responding to corporate inquiries and developing its business; or
- consent, where specifically requested or legally required.
7.3Managing commercial and professional relationships
We process relationship data to:
- manage customers, prospective customers, partners, suppliers, and advisers;
- administer contracts and statements of work;
- coordinate projects, integrations, and services;
- provide corporate support;
- manage authorised representatives;
- maintain business records;
- administer invoices and payments;
- conduct relationship reviews; and
- communicate about operational or contractual matters.
The legal basis may be:
- performance of a contract;
- taking steps before entering into a contract;
- compliance with legal obligations; or
- FinDech’s legitimate interest in managing its business and professional relationships.
7.4Business development
We may process limited professional contact information to:
- identify organisations that may have a legitimate interest in FinDech’s services;
- communicate with existing or prospective professional contacts;
- invite business contacts to relevant meetings or events;
- follow up on introductions;
- provide corporate or product updates; and
- develop partnerships.
The legal basis is normally FinDech’s legitimate interest in developing its B2B business, provided that this interest is not overridden by the individual’s rights and interests.
Where applicable law requires consent, we will rely on consent instead.
You may object to business-development or direct-marketing communications at any time.
7.5Marketing communications
We may send marketing or corporate communications where:
- you have requested them;
- you have given valid consent;
- the communication is permitted in the context of an existing business relationship; or
- another lawful basis permits the communication.
Marketing communications may include:
- company news;
- portfolio updates;
- event invitations;
- product announcements;
- research or industry materials; and
- information about FinDech services.
Every electronic marketing communication will provide a reasonable way to unsubscribe where required.
Withdrawing consent or unsubscribing does not affect service, security, legal, or other non-marketing communications that we may still need to send.
7.6Recruitment
We process recruitment data to:
- review applications;
- communicate with candidates;
- assess qualifications and suitability;
- arrange interviews;
- verify references where appropriate;
- make recruitment decisions;
- protect legal rights; and
- maintain records of the recruitment process.
The legal basis may be:
- taking steps at your request before entering into an employment or service contract;
- compliance with legal obligations;
- FinDech’s legitimate interest in managing recruitment; or
- consent for retaining information for future opportunities where consent is required.
7.7Compliance, due diligence, and risk management
Where relevant to a proposed or existing business relationship, we may process professional and identification-related data to:
- verify authority and corporate representation;
- perform supplier, customer, partner, or investor due diligence;
- assess conflicts of interest;
- perform sanctions or restricted-party checks;
- prevent fraud, corruption, money laundering, or other unlawful activity;
- comply with requests from competent authorities;
- meet accounting, tax, audit, corporate, or regulatory requirements; and
- protect FinDech and its partners from legal, regulatory, financial, security, or reputational risks.
The legal basis may be:
- compliance with legal obligations;
- performance of a contract;
- taking steps before entering into a contract; or
- FinDech’s legitimate interests in conducting appropriate due diligence and risk management.
The public Website itself does not perform regulated customer onboarding or financial-transaction monitoring.
Product-specific compliance processing must be described in the privacy notice applicable to the relevant product.
7.8Establishing and defending legal rights
We may process relevant data to:
- obtain legal advice;
- document decisions;
- enforce contracts;
- manage complaints and disputes;
- respond to legal claims;
- protect intellectual property;
- investigate misconduct; and
- establish, exercise, or defend legal rights.
The legal basis may be compliance with a legal obligation or FinDech’s legitimate interest in protecting its legal rights.
7.9Improving the Website and Corporate Services
We may use aggregated, statistical, or limited usage information to:
- understand Website performance;
- identify errors;
- evaluate how corporate content is used;
- improve navigation and accessibility;
- assess the effectiveness of forms and content; and
- plan future Website functionality.
Where this activity uses only essential technical information, the legal basis is normally legitimate interests.
Where non-essential cookies or similar tracking technologies are used, we will request consent where required.
7.10Corporate transactions and restructuring
Personal data may be processed where reasonably necessary in connection with:
- an investment;
- financing;
- merger;
- acquisition;
- sale of shares or assets;
- internal reorganisation;
- transfer of a business or Website;
- due diligence concerning such a transaction; or
- insolvency or similar proceedings.
The legal basis is normally FinDech’s legitimate interest in managing corporate transactions and its business structure, subject to appropriate confidentiality and data-protection safeguards.
08Our legitimate interests
Where we rely on legitimate interests, those interests may include:
- operating and securing the Website;
- preventing fraud and misuse;
- responding to inquiries;
- managing business relationships;
- developing products, partnerships, and commercial opportunities;
- communicating with professional contacts;
- improving Corporate Services;
- conducting proportionate due diligence;
- protecting confidential information and intellectual property;
- managing legal, regulatory, operational, and security risks; and
- establishing, exercising, or defending legal claims.
Before relying on legitimate interests, we consider:
- whether there is a legitimate purpose;
- whether the processing is reasonably necessary for that purpose; and
- whether your interests, rights, or reasonable expectations override FinDech’s interests.
You may object to processing based on legitimate interests as described in Section 18.
09Consent
Where we rely on consent:
- consent will be requested for a specific purpose;
- the request will be presented separately and in clear language;
- consent will not be assumed from silence or inactivity;
- you may refuse consent without unnecessary disadvantage; and
- you may withdraw consent at any time.
Withdrawal does not affect the lawfulness of processing performed before consent was withdrawn.
Where you withdraw consent, another lawful basis may still permit or require FinDech to retain or process certain information, for example to maintain suppression records, comply with law, or manage legal claims.
10Whether you must provide personal data
Providing personal data through the public Website is generally voluntary.
However, certain information may be necessary for FinDech to:
- respond to an inquiry;
- identify you or your organisation;
- arrange a meeting;
- assess a proposal;
- prepare or perform a contract;
- process an application;
- comply with law; or
- protect Website and information security.
If required information is not provided, FinDech may be unable to respond, assess the request, proceed with a relationship, or provide the requested Corporate Service.
We will not ask you to provide personal data that is not reasonably relevant to the stated purpose.
12No sale of personal data
FinDech does not sell personal data obtained through the Website.
FinDech does not use Website visitor data for cross-site behavioural advertising.
If FinDech’s practices change materially, this Privacy Policy and any required consent or opt-out mechanism will be updated before the new processing begins.
13International data transfers
FinDech is established in Lithuania and may use service providers, partners, affiliates, or advisers located in other countries.
As a result, personal data may be accessed from or transferred to a country outside the European Economic Area.
Where such a transfer is subject to the GDPR, FinDech will use an applicable transfer mechanism, such as:
- a European Commission adequacy decision;
- Standard Contractual Clauses approved by the European Commission;
- Binding Corporate Rules, where applicable;
- another legally recognised safeguard; or
- a specific derogation permitted by applicable law in limited circumstances.
Where required, FinDech will assess whether supplementary contractual, organisational, or technical measures are appropriate.
You may request information about the applicable transfer safeguards by contacting info@findech.com.
Commercially confidential information and information concerning other individuals may be redacted from copies of transfer documentation where legally permitted.
15Direct marketing
You have the right to object to the processing of your personal data for direct-marketing purposes at any time.
You may opt out by:
- using the unsubscribe mechanism provided in the communication; or
- emailing info@findech.com.
Once you object, we will stop using your personal data for the relevant direct-marketing purpose.
We may retain limited information, such as your email address and opt-out status, on a suppression list to ensure that your preference is respected.
Opting out of marketing does not prevent us from sending:
- responses to your inquiries;
- contractual or operational communications;
- security notices;
- legal notices; or
- other non-marketing communications that are necessary or permitted by law.
16How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods depend on:
- the purpose for which the information was collected;
- whether there is an active relationship;
- contractual requirements;
- applicable accounting, tax, corporate, employment, regulatory, or record-keeping laws;
- security requirements;
- limitation periods;
- actual or potential disputes;
- your consent or objection; and
- whether retention is necessary to establish, exercise, or defend legal claims.
Our general retention approach is as follows.
16.1General inquiries
An inquiry that does not result in a commercial or other continuing relationship will ordinarily be retained for up to three years after the last substantive communication.
It may be retained longer where necessary for a complaint, dispute, security investigation, legal obligation, or legal claim.
16.2Business relationships
Records relating to customers, partners, suppliers, advisers, negotiations, and contracts may be retained for the duration of the relationship and afterwards for the statutory accounting, tax, audit, corporate, regulatory, and legal limitation periods applicable to the relevant record.
16.3Marketing information
Marketing contact information is retained until you unsubscribe, withdraw consent, object, or the information is no longer reasonably needed.
Limited suppression information may be retained afterwards to prevent further marketing.
16.4Recruitment information
Information concerning an unsuccessful application will ordinarily be retained for up to six months after the recruitment process ends, unless:
- a longer period is required or permitted by law;
- a dispute or claim exists; or
- you agree that FinDech may retain it for future opportunities.
Where you agree to future-opportunity retention, the information may ordinarily be retained for up to two years, subject to renewal or earlier withdrawal.
16.5Technical and security logs
Routine Website, infrastructure, security, and diagnostic logs will ordinarily be retained for between 30 days and 12 months, depending on their purpose and the provider involved.
Relevant logs may be retained longer where they concern an incident, suspected abuse, legal obligation, or legal claim.
16.6Consent records
Records demonstrating consent and consent withdrawal may be retained for the duration of the processing and for a reasonable period afterwards, ordinarily up to three years, where necessary to demonstrate compliance or manage claims.
16.7Data-rights requests and complaints
Records concerning privacy requests and complaints may ordinarily be retained for up to three years after closure, or longer where necessary for a dispute, regulatory inquiry, or legal obligation.
16.8Anonymised information
FinDech may retain information that has been irreversibly anonymised so that it no longer identifies an individual.
This Privacy Policy does not apply to properly anonymised information.
17Data security
FinDech uses technical and organisational measures designed to protect personal data against:
- accidental or unlawful destruction;
- loss;
- alteration;
- unauthorised disclosure;
- unauthorised access; and
- other unlawful processing.
Depending on the risks and nature of the processing, measures may include:
- access restrictions;
- least-privilege controls;
- authentication controls;
- encryption in transit;
- secure infrastructure configuration;
- logging and monitoring;
- backups;
- software updates;
- vendor assessment;
- confidentiality obligations;
- incident-response procedures; and
- staff awareness measures.
No website, communication channel, storage system, or transmission method is completely secure.
You should not send passwords, private keys, recovery phrases, payment authentication data, or other highly sensitive credentials through an ordinary contact form or email.
If FinDech becomes aware of a personal-data breach, it will assess and address the incident and make notifications where required by law.
18Your data-protection rights
Subject to applicable law and relevant conditions, you may have the following rights.
18.1Right to information
You have the right to receive clear information about how your personal data is processed.
18.2Right of access
You may ask whether FinDech processes personal data about you and request access to that data and relevant processing information.
18.3Right to rectification
You may ask FinDech to correct inaccurate personal data and complete incomplete information.
18.4Right to erasure
You may ask FinDech to delete personal data in circumstances including where:
- the data is no longer necessary;
- consent has been withdrawn and no other legal basis applies;
- you validly object and no overriding ground applies;
- the processing is unlawful; or
- deletion is legally required.
The right to erasure is not absolute. FinDech may retain information where required or permitted for legal obligations, freedom of expression, public-interest purposes, or legal claims.
18.5Right to restriction
You may ask FinDech to restrict processing in circumstances including while accuracy, an objection, or the lawfulness of processing is being considered.
18.6Right to data portability
Where processing is based on consent or contract and carried out by automated means, you may have the right to receive personal data you provided in a structured, commonly used, machine-readable format.
Where technically feasible and legally applicable, you may ask for it to be transmitted to another controller.
18.7Right to object
You may object, on grounds relating to your particular situation, to processing based on legitimate interests.
FinDech will stop the relevant processing unless it demonstrates compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is required for legal claims.
18.8Right to object to direct marketing
You may object to direct marketing at any time.
Following an objection, your personal data will no longer be processed for the relevant direct-marketing purpose.
18.9Right to withdraw consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal does not affect processing performed lawfully before the withdrawal.
18.10Rights concerning automated decisions
You may have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects.
See Section 20 for FinDech’s current practices.
18.11Right to complain
You have the right to lodge a complaint with a competent data-protection supervisory authority.
You may generally complain in the country of:
- your habitual residence;
- your place of work; or
- the place where the alleged infringement occurred.
FinDech encourages you to contact us first so that we have an opportunity to consider and address the matter.
19Exercising your rights
To exercise a data-protection right, email info@findech.com.
Your request should explain:
- who you are;
- the right you wish to exercise;
- the processing or information concerned; and
- any information that may help us locate the relevant records.
We may request additional information where reasonably necessary to confirm your identity and protect personal data from unauthorised disclosure.
Do not send a full identification document unless FinDech specifically requests it and provides an appropriate method.
We will respond without undue delay and ordinarily within one month after receiving a valid request.
Where permitted by law, this period may be extended for a complex request or multiple requests. If an extension is necessary, we will inform you.
Rights are not absolute. A request may be limited or refused where permitted by law, including where it:
- adversely affects another person’s rights;
- concerns information protected by legal privilege;
- would reveal confidential information belonging to another person;
- is manifestly unfounded or excessive;
- conflicts with a legal obligation; or
- concerns data required for legal claims.
Where we refuse or limit a request, we will explain the reasons where required and inform you about available complaint or judicial remedies.
Requests are normally handled free of charge. A reasonable fee may be charged, or action may be refused, where permitted for manifestly unfounded, excessive, or repetitive requests.
20Automated decision-making and profiling
The public Website does not currently use solely automated decision-making that produces legal effects or similarly significantly affects Website visitors.
FinDech may use basic automated controls for:
- spam prevention;
- input validation;
- rate limiting;
- traffic management;
- cybersecurity;
- fraud detection; or
- technical error handling.
These controls do not ordinarily make significant legal or contractual decisions about Website visitors.
If FinDech introduces significant automated decision-making or profiling, the applicable privacy notice will explain:
- the nature of the decision;
- the legal basis;
- meaningful information about the logic involved;
- the expected consequences;
- available safeguards; and
- how to request human intervention or challenge the decision where applicable.
21Children
The Corporate Services are intended for adults and professional or business users.
The public Website is not directed at children, and FinDech does not knowingly use the Website to collect personal data from children for commercial services.
A person submitting a business, recruitment, or partnership inquiry should generally be at least 18 years old or otherwise legally able to make the communication.
If you believe a child has submitted personal data to FinDech without an appropriate legal basis, contact info@findech.com.
22Third-party websites and social media
The Website may link to:
- portfolio websites;
- partners;
- regulators;
- professional networks;
- social-media platforms;
- publications; and
- other third-party services.
FinDech does not control the privacy practices of those third parties.
When you follow an external link, the third party may collect information under its own privacy policy and cookie practices.
FinDech’s presence on a social-media or professional-networking platform is also subject to that platform’s rules and privacy practices.
Information that you publish publicly or submit directly through a third-party platform may be visible to the platform operator and other users.
23Confidential business information
This Privacy Policy concerns personal data. It does not govern all confidential or commercially sensitive business information.
A general contact form or ordinary email does not automatically create a confidentiality agreement.
Do not send source code, credentials, private keys, unreleased financial information, trade secrets, or highly confidential documentation unless an appropriate channel and confidentiality arrangement have been agreed.
Where business information also contains personal data, the relevant personal data will be handled in accordance with this Privacy Policy and applicable law.
24Changes to this Privacy Policy
FinDech may update this Privacy Policy to reflect changes in:
- the Website;
- Corporate Services;
- processing activities;
- service providers;
- portfolio structure;
- legal or regulatory requirements;
- security practices; or
- corporate operations.
The updated version will be published on this page with a revised “Last updated” date.
Where a change materially affects existing processing and additional notice or consent is legally required, FinDech will take appropriate steps before the new processing begins.
You should review this Privacy Policy periodically.
25Governing privacy laws
FinDech processes personal data in accordance with the GDPR and other applicable Lithuanian and European data-protection and electronic-communications laws.
Individuals outside the European Economic Area may have additional rights under the mandatory privacy laws applicable to them.
Nothing in this Privacy Policy limits a mandatory right that cannot lawfully be excluded.
27Contact us
For questions, concerns, objections, consent withdrawals, or requests concerning personal data, contact:
Privacy contact
FinDech UABCompany code: 307632436Architektų g. 56-101Vilnius, LT-04111Lithuaniainfo@findech.comFor general questions you can also use the contact page.
Please write “Privacy Request” in the email subject where appropriate.
Do not send passwords, private keys, recovery phrases, payment authentication codes, or other security credentials.