Privacy Policy
This Privacy Policy explains how Wallymanager collects, uses, and protects your personal information.
1. Introduction
Welcome to Wallymanager. We are committed to protecting your privacy and handling your personal data in an open and transparent manner. This Privacy Policy outlines our practices concerning the information we collect from you or that you provide to us through our application (the "Service"). Wallymanager is operated by Wallymanager, a company registered in the Republic of Bulgaria, which acts as the Data Controller for your personal data under the General Data Protection Regulation (GDPR).
2. Information We Collect
We collect several types of information to provide and improve our Service: a) Personal Identification Information: Your name, email address, and profile picture. b) Financial Information: Transaction details, account balances, budget categories, savings goals, and connected financial account information (securely handled by our trusted third-party data aggregators). We do not store your bank login credentials. c) Technical Information: IP address, device type, operating system, browser type, and application usage data (e.g., feature interaction, crash reports). d) Third-Party Authentication Information: If you register using a third-party service like Google, we receive your name and email address from that service.
3. How We Use Your Information
We use your information for the following purposes: a) To Provide and Maintain the Service: To create and manage your account, process your financial data to generate insights, and enable application features. b) To Improve the Service: To analyze usage patterns, identify trends, and improve application functionality and user experience. c) To Communicate with You: To send you service-related notifications, security alerts, and support messages. d) For Security and Fraud Prevention: To protect our systems, prevent fraudulent activity, and enforce our Terms of Use. e) To Fulfill Legal Obligations: To comply with applicable laws, regulations, and legal requests.
4. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds: a) Performance of a Contract: We process your data to fulfill our contractual obligations to you when you use our Service (as outlined in our Terms of Use). b) Legitimate Interests: We process data for our legitimate interests, such as improving our Service and ensuring its security, provided that these interests are not overridden by your rights and interests. c) Consent: For certain processing activities, such as sending marketing communications, we will rely on your explicit consent. You can withdraw your consent at any time. d) Legal Obligation: We may be required to process your data to comply with a legal or regulatory obligation.
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with the following trusted third parties: a) Service Providers: Companies that provide services on our behalf, such as cloud hosting (e.g., AWS, Google Cloud), payment processing, and data aggregation. These providers are contractually obligated to protect your data and use it only for the purposes for which it was disclosed. b) Legal and Regulatory Authorities: We may disclose your information if required by law, such as in response to a court order, subpoena, or other legal process. c) Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction, subject to the commitments made in this Privacy Policy. d) AI Provider: When you enable AI features such as spending insights and receipt scanning, the financial data needed to deliver those features is shared with a third-party AI provider that processes it on our behalf. This sharing takes place only with your explicit consent, which you can withdraw at any time, and the provider is contractually bound to process your data solely to provide these features and not for its own purposes.
6. Data Security
We implement robust technical and organizational security measures to protect your personal and financial data from unauthorized access, alteration, disclosure, or destruction. These measures include: a) Encryption: Your data is encrypted both in transit (using TLS) and at rest. b) Access Controls: We enforce strict access controls to ensure that only authorized personnel have access to your data on a need-to-know basis. c) Regular Audits: We conduct regular security audits and vulnerability scanning to identify and remediate potential threats. d) Secure Infrastructure: We use secure, industry-leading cloud infrastructure to host our services.
7. Data Retention & Deletion
We retain your personal data for as long as your account is active or as needed to provide you with the Service. If you choose to deactivate your account, we will securely delete or anonymize your personal information in accordance with our data retention policies and legal obligations, typically within 90 days. You can request account deactivation at any time through the application's settings: Settings → Account → Deactivate Account.
8. Your Rights Under GDPR
As a user in the European Union, you have the following rights regarding your personal data: a) Right of Access: You can request a copy of the personal data we hold about you. b) Right to Rectification: You can request that we correct any inaccurate or incomplete data. c) Right to Erasure ('Right to be Forgotten'): You can request that we delete your personal data. d) Right to Restrict Processing: You can request that we limit the processing of your data. e) Right to Data Portability: You can request a copy of your data in a machine-readable format. f) Right to Object: You can object to our processing of your data for certain purposes (e.g., direct marketing). To exercise any of these rights, please contact our Data Protection Officer at [email protected].
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own, where our service providers are located. We ensure that any such transfers comply with GDPR and other applicable data protection laws by using appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your data. Where you choose to enable AI features, this may include the processing of your financial data by our third-party AI provider, which may be located outside the European Economic Area. Such transfers are protected by the same safeguards described above, including Standard Contractual Clauses, and occur only with your consent.
10. Children's Privacy
Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected such information, we will take steps to delete it as soon as possible. If you are a parent or guardian and believe your child has provided us with personal data, please contact us.
11. Changes to This Policy & Contact Information
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and, where appropriate, through other channels such as email or in-app notifications. For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at [email protected] or our Data Protection Officer at [email protected].
For any privacy-related inquiries, please contact our Data Protection Officer at [email protected].