Privacy Policy
1. Controller and contact
Nicholas Perillo
c/o MotionLab
Bouchéstr. 12, Halle 20
12435 Berlin, Germany
Email: info@augmentl.com
2. Purpose and scope
Augmentl Finance Collector is a restricted, read-only tool used by the controller to retrieve and review information from accounts the controller owns or is authorised to access. It is not offered as a public banking service.
The collector uses Enable Banking’s account-information service to request account details, balances and transactions after an explicit bank-consent flow. It does not initiate payments, transfers or other account changes.
3. Data processed
Depending on what the bank provides, the collector may process bank and account identifiers; account type, currency and balance information; booked and pending transactions; transaction dates, amounts, counterparties, merchant information and remittance text; and technical consent, session and synchronisation metadata.
Bank-login credentials are entered only into the bank’s own authentication flow and are not collected or stored by Augmentl Finance Collector.
4. Legal basis
Bank data is accessed only after explicit authorisation through the relevant bank and Enable Banking. Where the GDPR applies, processing is based on the account holder’s consent under Article 6(1)(a) GDPR and, for internal business-account administration, the controller’s legitimate interest in accurate financial administration under Article 6(1)(f) GDPR.
Consent can be withdrawn through the bank or Enable Banking. Withdrawal stops future access but does not automatically erase records already stored for legitimate accounting, security or audit purposes.
5. Recipients and transfers
Enable Banking Oy and the relevant bank participate in the authorisation and account-information exchange. Their own privacy notices apply to their processing.
The collector stores retrieved data locally on systems controlled by the controller. Transaction data is not sold, used for advertising or intentionally sent to public AI services. No additional disclosure occurs unless required by law or deliberately configured later and disclosed in an updated policy.
This legal-information site is hosted by GitHub Pages. GitHub may process technical request data, such as IP address and browser metadata, when a visitor loads these pages. GitHub’s own privacy statement applies to that hosting activity. No bank-account or transaction data is published on this site.
6. Security
Application credentials and encryption keys are stored in the macOS Keychain. Retrieved bank payloads and session identifiers are encrypted at rest. Local files are restricted to the operating-system user, and the collector exposes only a temporary loopback callback during attended authorisation.
No internet-connected system can be guaranteed completely secure. Access should be revoked promptly if a device or application credential may have been compromised.
7. Retention
Consent and provider-session validity are limited by the bank and Enable Banking. Locally stored observations are retained only while needed for financial administration, reconciliation, security evidence or applicable legal obligations. They may be deleted or anonymised when those purposes no longer apply, subject to statutory accounting and tax-retention requirements.
8. Rights
Where the GDPR applies, data subjects may request access, correction, erasure, restriction, portability or objection, and may withdraw consent at any time. Requests can be sent to info@augmentl.com. A complaint may also be made to a competent data-protection authority, including the Berlin Commissioner for Data Protection and Freedom of Information.
9. Changes
This policy will be updated before the collector is offered to additional users, gains new recipients, or materially changes how financial data is processed.