WWiseWallet

WiseWallet

Privacy Policy

Effective date: 30 July 2026 · Last updated: 30 July 2026

This Privacy Policy explains how WiseWallet collects, uses, stores, and shares personal data when you use our personal and shared budgeting service, including optional bank-account connectivity via regulated open-banking infrastructure.

Contents

  1. 1. Who we are
  2. 2. Controller and processors
  3. 3. Scope
  4. 4. Personal data we process
  5. 5. Why we process data (purposes and legal bases)
  6. 6. Bank connections and open banking
  7. 7. Who we share data with
  8. 8. International transfers
  9. 9. Retention and deletion
  10. 10. Backups after deletion
  11. 11. Security
  12. 12. Your rights
  13. 13. Cookies and similar technologies
  14. 14. Children
  15. 15. Changes

1. Who we are

Claudiu Andriesi, operating the WiseWallet service (“we”, “us”, “WiseWallet”) provides the WiseWallet web application available at https://budget.claudiuandriesi.com.

For questions about this policy or your personal data, contact us at claudiu.constantin.ac@gmail.com.

2. Controller and processors

For personal data processed in connection with your WiseWallet account and the budgeting features we provide, we act as the data controller under the GDPR.

We use service providers that process personal data on our instructions as data processors (for example hosting, email delivery, and open-banking technical connectivity). In some situations a provider may also act as an independent controller for certain processing of its own (for example where required by its regulatory role or own legal obligations).

Examples of processors or partners we may use include our hosting provider, our email delivery provider (currently Brevo or a successor), and Enable Banking for optional bank-account information connectivity.

3. Scope

This policy applies to the WiseWallet website and application, account registration and authentication, shared budgets and invitations, financial records you enter (income, expenses, savings, goals, debts, loans, recurring items), analytics and notifications inside the product, and optional bank connectivity features.

It does not apply to third-party websites or bank interfaces you may be redirected to during open-banking authentication.

4. Personal data we process

Depending on how you use WiseWallet, we may process the following categories of data:

  • Account data: name, email address, password (stored as a secure hash), language and display preferences, and account verification / password-reset tokens.
  • Budget collaboration data: budget membership, roles (for example owner/member), invitations, and identifiers of other members you share a budget with.
  • Financial records you create: descriptions, amounts, currencies, dates, categories/tags, contributors, goals, savings, debts, loans, recurring templates, and related metadata.
  • Usage and technical data: IP address, approximate device/browser information, timestamps, security logs, and diagnostic logs needed to operate and secure the service.
  • Open-banking data (only if you connect a bank): account metadata and transaction information retrieved through our Account Information Service Provider (AISP) technical partner, currently Enable Banking, for display, review, and optional conversion into WiseWallet records after your action.
  • Communications: emails we send for verification, password reset, invitations, and service notices.

5. Why we process data (purposes and legal bases)

We process personal data only where we have a valid legal basis under the GDPR / applicable EU/EEA and Romanian data-protection law, including:

  • Contract / steps prior to contract: creating and securing your account, providing budgeting features, shared budgets, and support.
  • Consent: optional bank connectivity and related retrieval of account/transaction data via open banking; you may withdraw consent by disconnecting the bank connection (where available) and/or deleting related data subject to retention rules.
  • Legitimate interests: securing the service, preventing abuse, improving reliability, and understanding aggregate product usage in a privacy-respecting way.
  • Legal obligation: where we must retain or disclose information to comply with law, regulation, or lawful requests.

6. Bank connections and open banking

If you choose to connect a bank account, WiseWallet uses Enable Banking (or a successor technical provider) as infrastructure to initiate consent with your bank (ASPSP) and retrieve account information and transactions (AISP use case). We do not initiate payments through this integration.

WiseWallet does not act as a bank, payment institution, or regulated financial institution. Banking services are provided solely by your bank and the regulated Account Information Service Provider.

You authenticate with your bank. We receive only the data necessary to show accounts/transactions in WiseWallet for review and budgeting. Bank credentials are not stored by WiseWallet.

Bank-sourced information may be incomplete, delayed, or incorrect. You remain responsible for verifying it before relying on it for budgeting decisions.

Sandbox/testing environments may use mock ASPSPs and synthetic data. Production connectivity depends on your selected environment, available ASPSPs, and successful consent.

7. Who we share data with

We do not sell your personal data. We share data only with processors and partners needed to run WiseWallet, under appropriate agreements, for example:

  • Hosting and infrastructure providers operating our application and database.
  • Email delivery providers used for verification, resets, and invitations.
  • Enable Banking (open-banking technical connectivity) when you use bank features.
  • Other budget members you invite or join with, to the extent required for shared budgeting.
  • Authorities or advisors when required by law or to protect rights, safety, and security.

8. International transfers

We aim to host and process primary application data in the EU/EEA. If a processor transfers data outside the EU/EEA, we rely on an appropriate transfer mechanism (such as adequacy decisions or Standard Contractual Clauses) where required.

9. Retention and deletion

We keep personal data only as long as needed for the purposes above:

  • Account and budget data: for the life of your account, and for a limited period afterward if needed for security, dispute handling, or legal obligations.
  • Auth tokens (verification, reset, invitations): until used, expired, or revoked.
  • Bank-connection and imported transaction data: while the connection/feature is active and thereafter according to your deletion requests and operational backups.
  • Logs: for a limited period needed for security and debugging.

10. Backups after deletion

When you delete information or close your account, we remove it from active systems subject to technical processing time. Deleted information may remain in encrypted backups for a limited period before being permanently removed.

Although we maintain backups and take reasonable measures to protect data, we do not guarantee that every item can always be restored after accidental deletion, corruption, or force majeure events. You remain responsible for keeping copies of information you consider important.

11. Security

We use technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS), hashed passwords, access controls, and least-privilege operations. No method of transmission or storage is perfectly secure.

Users are responsible for maintaining the confidentiality of their passwords, enabling available security features, and securing their own devices. Please use a strong unique password and protect access to your account.

12. Your rights

Subject to applicable law, you may have the right to access, rectify, erase, restrict, or object to certain processing, and the right to data portability. Where processing is based on consent, you may withdraw consent without affecting prior lawful processing.

To exercise rights, email claudiu.constantin.ac@gmail.com. You may also lodge a complaint with your local supervisory authority (in Romania, ANSPDCP).

13. Cookies and similar technologies

WiseWallet uses essential cookies or similar storage for authentication/session continuity and basic preferences (such as language). We do not use third-party advertising cookies in the core budgeting product.

14. Children

WiseWallet is intended for adults. We do not knowingly collect personal data from children under 16. If you believe a child provided data, contact us and we will take appropriate steps.

15. Changes

We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Continued use after an update means you acknowledge the revised policy, except where consent is required for a new purpose.

This policy is written for transparency and for registration with technical partners (including Enable Banking). It is not a substitute for independent legal advice. We may update it as the product evolves; material changes will be reflected by updating the date above and, where appropriate, notifying you in the product.

HomeTerms of Serviceclaudiu.constantin.ac@gmail.com