WiseWallet
Privacy Policy
Effective date: 30 July 2026 · Last updated: 30 July 2026
This Privacy Policy explains how WiseWallet collects, uses, stores, and shares personal data when you use our personal and shared budgeting service, including optional bank-account connectivity via regulated open-banking infrastructure.
1. Who we are
Claudiu Andriesi, operating the WiseWallet service (“we”, “us”, “WiseWallet”) provides the WiseWallet web application available at https://budget.claudiuandriesi.com.
For questions about this policy or your personal data, contact us at claudiu.constantin.ac@gmail.com.
2. Controller and processors
For personal data processed in connection with your WiseWallet account and the budgeting features we provide, we act as the data controller under the GDPR.
We use service providers that process personal data on our instructions as data processors (for example hosting, email delivery, and open-banking technical connectivity). In some situations a provider may also act as an independent controller for certain processing of its own (for example where required by its regulatory role or own legal obligations).
Examples of processors or partners we may use include our hosting provider, our email delivery provider (currently Brevo or a successor), and Enable Banking for optional bank-account information connectivity.
3. Scope
This policy applies to the WiseWallet website and application, account registration and authentication, shared budgets and invitations, financial records you enter (income, expenses, savings, goals, debts, loans, recurring items), analytics and notifications inside the product, and optional bank connectivity features.
It does not apply to third-party websites or bank interfaces you may be redirected to during open-banking authentication.
4. Personal data we process
Depending on how you use WiseWallet, we may process the following categories of data:
- Account data: name, email address, password (stored as a secure hash), language and display preferences, and account verification / password-reset tokens.
- Budget collaboration data: budget membership, roles (for example owner/member), invitations, and identifiers of other members you share a budget with.
- Financial records you create: descriptions, amounts, currencies, dates, categories/tags, contributors, goals, savings, debts, loans, recurring templates, and related metadata.
- Usage and technical data: IP address, approximate device/browser information, timestamps, security logs, and diagnostic logs needed to operate and secure the service.
- Open-banking data (only if you connect a bank): account metadata and transaction information retrieved through our Account Information Service Provider (AISP) technical partner, currently Enable Banking, for display, review, and optional conversion into WiseWallet records after your action.
- Communications: emails we send for verification, password reset, invitations, and service notices.
5. Why we process data (purposes and legal bases)
We process personal data only where we have a valid legal basis under the GDPR / applicable EU/EEA and Romanian data-protection law, including:
- Contract / steps prior to contract: creating and securing your account, providing budgeting features, shared budgets, and support.
- Consent: optional bank connectivity and related retrieval of account/transaction data via open banking; you may withdraw consent by disconnecting the bank connection (where available) and/or deleting related data subject to retention rules.
- Legitimate interests: securing the service, preventing abuse, improving reliability, and understanding aggregate product usage in a privacy-respecting way.
- Legal obligation: where we must retain or disclose information to comply with law, regulation, or lawful requests.
6. Bank connections and open banking
If you choose to connect a bank account, WiseWallet uses Enable Banking (or a successor technical provider) as infrastructure to initiate consent with your bank (ASPSP) and retrieve account information and transactions (AISP use case). We do not initiate payments through this integration.
WiseWallet does not act as a bank, payment institution, or regulated financial institution. Banking services are provided solely by your bank and the regulated Account Information Service Provider.
You authenticate with your bank. We receive only the data necessary to show accounts/transactions in WiseWallet for review and budgeting. Bank credentials are not stored by WiseWallet.
Bank-sourced information may be incomplete, delayed, or incorrect. You remain responsible for verifying it before relying on it for budgeting decisions.
Sandbox/testing environments may use mock ASPSPs and synthetic data. Production connectivity depends on your selected environment, available ASPSPs, and successful consent.
8. International transfers
We aim to host and process primary application data in the EU/EEA. If a processor transfers data outside the EU/EEA, we rely on an appropriate transfer mechanism (such as adequacy decisions or Standard Contractual Clauses) where required.
9. Retention and deletion
We keep personal data only as long as needed for the purposes above:
- Account and budget data: for the life of your account, and for a limited period afterward if needed for security, dispute handling, or legal obligations.
- Auth tokens (verification, reset, invitations): until used, expired, or revoked.
- Bank-connection and imported transaction data: while the connection/feature is active and thereafter according to your deletion requests and operational backups.
- Logs: for a limited period needed for security and debugging.
10. Backups after deletion
When you delete information or close your account, we remove it from active systems subject to technical processing time. Deleted information may remain in encrypted backups for a limited period before being permanently removed.
Although we maintain backups and take reasonable measures to protect data, we do not guarantee that every item can always be restored after accidental deletion, corruption, or force majeure events. You remain responsible for keeping copies of information you consider important.
11. Security
We use technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS), hashed passwords, access controls, and least-privilege operations. No method of transmission or storage is perfectly secure.
Users are responsible for maintaining the confidentiality of their passwords, enabling available security features, and securing their own devices. Please use a strong unique password and protect access to your account.
12. Your rights
Subject to applicable law, you may have the right to access, rectify, erase, restrict, or object to certain processing, and the right to data portability. Where processing is based on consent, you may withdraw consent without affecting prior lawful processing.
To exercise rights, email claudiu.constantin.ac@gmail.com. You may also lodge a complaint with your local supervisory authority (in Romania, ANSPDCP).
14. Children
WiseWallet is intended for adults. We do not knowingly collect personal data from children under 16. If you believe a child provided data, contact us and we will take appropriate steps.
15. Changes
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Continued use after an update means you acknowledge the revised policy, except where consent is required for a new purpose.