Privacy Policy
1Who we are
BankConnector ApS, Denmark. Contact: privacy@bankconnector.com.
2What we process, why, and on what legal basis
| Context | Data | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Account users | Name, work email, role, password hash, optional TOTP enrolment, session data | Providing login and the service; account security | Art. 6(1)(b) contract; Art. 6(1)(f) security |
| Activity and audit logs | User id, actions taken, timestamps | Tamper-evident audit trail; security; abuse prevention | Art. 6(1)(f); Art. 6(1)(c) where record-keeping is required |
| Usage events | Coarse product actions (e.g. "payment sent") and tenant/user ids, never payment content | Service operation and improvement | Art. 6(1)(f) |
| Sandbox users | IP address, request logs, temporary sandbox provisioning and rate-limit data; never real payment content | Providing the no-signup test sandbox; rate-limiting; security and abuse prevention | Art. 6(1)(f) |
| Website analytics & session recording | Aggregated, non-identifying traffic analytics; a sampled subset (about 10%) of website sessions recorded via session-replay technology, with typed input masked | Understanding and improving the website | Art. 6(1)(a) consent |
| Support and contact | Correspondence, contact details | Answering enquiries, providing support | Art. 6(1)(b)/(f) |
| Prospects | Business contact details you give us | Following up on your interest | Art. 6(1)(f) |
| Invoicing | Billing contact and invoice records | Billing; bookkeeping | Art. 6(1)(b); Art. 6(1)(c) (Danish Bookkeeping Act) |
We do not use your data for automated decision-making with legal effect, and we do not sell personal data.
3The developer sandbox
We offer a public sandbox at sandbox.bankconnector.com that anyone can use without an account, so developers can try the API against a simulated bank. As described in the table above, we process a limited amount of data about your use of it (your IP address, request logs, and the technical data needed to provision a temporary test environment) on the basis of our legitimate interest in operating and securing the service (Art. 6(1)(f)). Sandbox environments and their data are temporary and are removed automatically after a period of inactivity.
The sandbox provisions a simulated bank and processes no real payments. It is not intended for real personal or payment data. Please use only the example and test values provided, and do not submit real names, account numbers, or other personal data belonging to you or anyone else. If you enter such data despite this notice, you are responsible for ensuring you have a lawful basis to do so; we process it only transiently to run the test, and it is removed with the sandbox.
4Cookies, analytics and session recording
We use strictly necessary cookies for login sessions and security (for example session and CSRF cookies); these do not require consent.
With your consent, we also use two things on our website: aggregated, non-identifying analytics from our hosting platform (which pages are read, and roughly where visits come from), and session-replay technology that records a sample (around 10%) of website sessions so we can see how the site is used and find interface problems. Typed input is masked in these recordings. We do not run advertising trackers, and we do not share website data with marketing third parties.
You can accept or decline analytics and session recording at any time through the consent notice on the website. Declining stops further recording on your device. To withdraw a consent you gave earlier, clear this site's storage in your browser, or write to privacy@bankconnector.com and we will help.
5Recipients and transfers
We share personal data only with: our hosting and infrastructure subprocessors (currently Amazon Web Services, EU regions; the current list is at bankconnector.com/legal); professional advisors under confidentiality; and authorities where required by law. Personal data is stored in the EU/EEA and is not transferred outside the EEA unless protected by a Chapter V GDPR mechanism.
6Retention
- Account data: for the life of the account, then deleted or anonymised per the wind-down and retention schedule in the Service Description.
- Audit records: 5 years.
- Usage events: 365 days.
- Sandbox data: removed automatically after 30 days of inactivity.
- Website analytics and session recordings: up to 12 months, then deleted.
- Support correspondence: up to 2 years after the case is closed.
- Invoicing records: 5 years (Danish Bookkeeping Act).
7Your rights
You have the right to access, rectify, erase, restrict, and receive a copy of your personal data, and to object to processing based on legitimate interest. Write to privacy@bankconnector.com. Where we act as processor for a customer's workspace, we will refer your request to the controller and assist them in answering it. You can complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).
8Changes
We update this policy as the service evolves; material changes are announced on the website and, for account holders, in the product. Superseded versions remain available at dated URLs.