AtivaMoney AtivaMoney
  • Features
  • Security
  • Pricing
  • Blog
  • About us
  • PT · EN
Sign in Start free
Features Security Pricing Blog About us
PT · EN
Sign in Start free
Home › Privacy Policy

Privacy Policy

Last updated: 20 March 2026

Note: This is an English translation provided for your convenience. In case of discrepancy or legal dispute, the Portuguese version prevails.

Contents

1. Data Controller 2. Personal Data Collected 3. Purposes and Legal Bases 4. Banking Data 5. Data Sharing 6. International Transfers 7. Data Retention 8. Data Subject Rights (GDPR) 9. Security 10. Cookies
📅 Last updated: 20 March 2026

1. Data Controller

The controller of personal data collected through the AtivaMoney platform is:

Out4Success, Lda. — AtivaMoney
Registered address — to be completed
Tax ID (NIF) — to be completed
Data Protection Officer (DPO): [email protected] — to be completed

To exercise your rights or clarify any question relating to the processing of your personal data, you may contact us at the address indicated above.

2. Personal Data Collected

AtivaMoney collects and processes the following categories of personal data:

2.1 Registration Data

When creating an account, we collect: full name, email address and, optionally, mobile phone number (for multi-factor authentication). This data is necessary for the provision of the service.

2.2 Banking Data via Open Banking

With the express consent of the User and through a PSD2 connection via GoCardless, we collect: transaction information (amount, date, description, merchant), account balances and metadata associated with the authorised bank accounts. This data is used exclusively for the provision of PFM features.

2.3 Usage Data

We automatically collect data about the use of the platform, including: access logs, interface preferences, features used and interactions with the platform. This data is used to improve the service and ensure security.

2.4 Categorisation Data

When the User categorises, tags or corrects automatic categorisation suggestions for their transactions, those preference and correction data are processed to personalise and improve the AI categorisation model.

3. Purposes and Legal Bases

The processing of your personal data is carried out on the basis of the following purposes and respective legal bases, under the General Data Protection Regulation (GDPR — Reg. EU 2016/679):

Purpose Legal Basis
Provision of the PFM service (aggregation, categorisation, budgets) Performance of contract (Art. 6(1)(b) GDPR)
Security and fraud prevention Legitimate interest (Art. 6(1)(f) GDPR)
Service communications (alerts, transactional notifications) Performance of contract (Art. 6(1)(b) GDPR)
Newsletter and marketing communications Consent (Art. 6(1)(a) GDPR)
Compliance with legal obligations (tax, accounting) Legal obligation (Art. 6(1)(c) GDPR)

4. Banking Data — Special Handling

Banking data obtained via Open Banking is handled with particular care and subject to the following safeguards:

  • Exclusive use for PFM: Banking data is processed exclusively for the personal finance management purposes described in this Policy, never for different purposes;
  • Not sold: The User's banking data is not, under any circumstances, sold, transferred or shared with third parties for commercial or advertising purposes;
  • Not disclosed for commercial purposes: We do not use banking data to build commercial profiles, sell advertising or share information with competing financial institutions;
  • Access via GoCardless (PSD2): Access is carried out through an entity regulated by the FCA, under PSD2, with explicit authorisation from the User, and is revocable at any time as described in the Terms of Use.

5. Data Sharing

AtivaMoney shares personal data only with the sub-processors strictly necessary for the provision of the service, all bound by data processing agreements that are compliant with the GDPR:

  • GoCardless Ltd — Open Banking provider (PSD2). Headquartered in the United Kingdom, with operations in the European Economic Area. Authorised and regulated by the FCA.
  • Cloud infrastructure — to be completed
  • Transactional email service — to be completed

We do not share your personal data for third-party marketing purposes, behavioural advertising or any purpose not described in this Policy.

6. International Transfers

Whenever it is necessary to transfer personal data to countries outside the European Economic Area (EEA), in particular in the context of the provision of services by the sub-processors identified in Section 5, such transfer is carried out on the basis of adequate safeguard mechanisms, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, under Art. 46 GDPR;
  • Adequacy decisions of the European Commission, where applicable.

The User may request information on the specific safeguards applicable through the DPO contact indicated in Section 1.

7. Data Retention

Personal data is kept only for the time strictly necessary for the purposes for which it was collected:

  • During the contract: all data necessary for the provision of the service is kept while the account is active;
  • Following cancellation: data is deleted within a maximum period of 30 days after account cancellation;
  • Legal obligations: tax or accounting data may be retained for the period required by law (generally 10 years under Portuguese tax legislation), after which it is deleted;
  • Anonymised data: anonymised statistical data, with no possibility of identification, may be kept for an indefinite period for analysis and service improvement.

8. Data Subject Rights (GDPR)

Under the GDPR, the User has the following rights in respect of their personal data:

  • Access — Right to obtain confirmation as to whether your data is being processed and to access it;
  • Rectification — Right to correct incomplete or inaccurate data;
  • Erasure — Right to request deletion of your data ("right to be forgotten"), in the cases set out in the GDPR;
  • Portability — Right to receive your data in a structured, commonly used and machine-readable format, and to transmit it to another controller;
  • Restriction — Right to request the restriction of processing of your data in certain circumstances;
  • Objection — Right to object to processing based on legitimate interests or for direct marketing purposes;
  • Not subject to automated decision-making — Right not to be subject to decisions based solely on automated processing that produce legal or significant effects.

To exercise any of these rights, contact our Data Protection Officer:
Email: [email protected] — to be completed

The User also has the right to lodge a complaint with the competent supervisory authority: the Portuguese Data Protection Authority — Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt.

9. Security

AtivaMoney implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or destruction, including:

  • TLS 1.3 — All communication between the User and the platform is encrypted with TLS 1.3;
  • Encryption at rest — Stored data is encrypted at rest;
  • Multi-Factor Authentication (MFA) — MFA support for all user accounts;
  • Access auditing — Audit logs of all accesses to sensitive data;
  • 24/7 monitoring — Continuous monitoring of the infrastructure to detect anomalies and incidents;
  • OWASP Top 10 — Development and security testing guided by the OWASP Top 10 recommendations.

In the event of a personal data breach that may pose a risk to your rights and freedoms, AtivaMoney shall notify the CNPD within 72 hours and the affected Users without undue delay, as required by the GDPR.

10. Cookies

AtivaMoney uses cookies and similar technologies to ensure the operation of the platform, store User preferences and, with consent, analyse use of the service.

For detailed information on the types of cookies used, their purposes and how to manage your preferences, please consult our Cookie Policy.

AtivaMoney AtivaMoney

Know your money. Take control of your future.

Built in Portugal

Product

  • Features
  • Security
  • Pricing
  • Blog

Company

  • About us
  • Contact
  • Partners
  • Press

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy
  • Cookie Preferences

© 2026 AtivaMoney. All rights reserved. AtivaMoney is a brand of Out4Success. Built with care in Portugal.

This site uses essential cookies to function and optional cookies for usage analytics.

Learn more