Privacy Notice
Version 1.0 · effective 6 October 2026 · English is the authoritative version.
1. Who we are
CySo Solutions Ltd, Republic of Cyprus (EU), registration no. HE487195, registered office 7 Igerias Street, Limassol, Cyprus, runs the CySo Bank Connector at bank.cysosolutions.com. Privacy contact: legal@cysosolutions.com.
We have two roles:
- For your bank and payment data (balances, transactions, account names, IBANs), you, the customer, are the controller. We are your processor under our Data Processing Agreement. We use that data only to provide the Service to you.
- For your customer account (sign-in, billing, support), we are the controller. That data is described below.
2. The data we hold about you as a customer
| Data | Why | Legal basis | Kept |
|---|---|---|---|
| Email address; Google account ID if you sign in with Google | sign-in, service messages | contract (Art. 6(1)(b) GDPR) | while the account exists + 30 days |
| Company name and the details you give | to run your account | contract | while the account exists + 30 days |
| Subscription status, Stripe customer ID, payment history (no card numbers) | billing | contract; legal obligation (tax) for invoices | invoices: as tax law requires (Cyprus: at least 6 years) |
| Security log: time, type of action, which company and internal account ID (e.g. "bank connected", "key created"); no IP addresses, no bank values | security, abuse prevention, proving what happened | legitimate interest (Art. 6(1)(f)) | 12 months (deleted automatically) |
| IP address and browser details of each visit | processed by Cloudflare to deliver and protect the site; not stored by us | legitimate interest | Cloudflare's own retention |
| Messages you send to support; remote-help session notes | support | contract | 24 months after the case closes |
Giving this data is needed to have an account; without it we cannot provide the Service. We make no automated decisions with legal or similar effects about you.
We do not use advertising or tracking cookies or analytics. The web app uses one strictly necessary session cookie to keep you signed in.
3. Your bank and payment data (we process it for you)
- What: account name, IBAN, bank, currency; balances; transactions (date, amount, direction, description, counterparty name and IBAN where the bank gives them). Transactions can include personal data of others, for example customers, suppliers or employees (salary payments).
- How it is protected: every bank value (amounts, names, IBANs, descriptions, balances, session IDs) is encrypted (AES-256-GCM) with a key unique to your company before it is stored. Dates, internal IDs, your company name and status flags are not encrypted. Links and keys are stored only as one-way hashes, except the Viva notification address, which is stored encrypted so we can show it to you. The Service is read-only.
- Who can read it: you, and the people, accountant agents and AI assistants you give a reading key or connector. CySo is technically able to decrypt it, but does so only when you ask for help (and only what that help needs), or when the law requires it.
- Kept: while your subscription is active. Deleted 30 days after it ends, with recovery copies expiring within a further 30 days; or earlier when you forget an account or delete the whole company. A sign-up that never starts a trial is deleted after 90 days.
4. Who else is involved
Our processors (they work for us under contracts that protect your data):
| Processor | What for | Where |
|---|---|---|
| Cloudflare, Inc. | hosting the Service and its database | database located in Cloudflare's Western-Europe region; requests are processed on Cloudflare's global network, so data may pass through servers outside the EU; Cloudflare is a US company (EU Standard Contractual Clauses / EU-US Data Privacy Framework) |
| Stripe Payments Europe Ltd | subscriptions and payments; Stripe also acts as an independent controller for payment and anti-fraud duties | EU (Ireland), with transfers under Stripe's safeguards |
| Google (only if you choose "Sign in with Google") | sign-in | Google's terms |
| Resend (Plus Five Five, Inc.) | sending sign-in links and service emails (your email address and the message) | EU region (Ireland) for sending; US company (EU Standard Contractual Clauses) |
Services you choose and contract with yourself. These are not our processors. You send your data to them, or they send it to us, under your own agreement with them:
- Enable Banking Oy (Finland): your own account, used to read your banks.
- Viva.com: sends us notifications of movements in your Viva account.
- Your AI assistant's provider (e.g. Anthropic, OpenAI): receives whatever your assistant reads through the connector.
We never sell data and never use your financial data to train AI.
5. Your rights
You can ask to see, correct, receive a portable copy of, or delete your personal data, to restrict or object to its use, and to withdraw consent where we rely on it. Write to legal@cysosolutions.com. We answer within one month.
For bank data, the people in your transactions should contact you, as controller. We will help you answer them.
You can complain to the Commissioner for Personal Data Protection in Cyprus (dataprotection.gov.cy) or to the authority in your EU country.
6. Security incidents
If a security incident affects your data, we tell you without undue delay, and in any case within 48 hours of becoming aware of it, so that you can meet your own 72-hour duty to the authority.
7. Changes
We will post changes here and email customers about important ones at least 30 days before they apply.