Privacy Policy
How we collect, process, protect, and retain your data across Plenzo features.
Document details
- Last updated: 22/08/2026
- Controller: Plenzo sp. z o.o., Aleje Jerozolimskie 47/34, 00-697 Warszawa, Poland
- Register details: KRS: 0001193524 · NIP: 7011276933 · REGON: 542692449
- General: support@plenzo.app · Privacy: privacy@plenzo.app · Security: security@plenzo.app · DPO: none
- Supervisory authority: UODO, ul. Stawki 2, 00-193 Warszawa, Poland
We provide Plenzo as a personal wealth management tool for consumers in Poland (18+). Plenzo is informational only — not financial/investment/tax/legal advice.
Data we collect
Account & identity
- Email address (login, service communications)
- Country/language (localization & notices)
- Full name (optional, e.g., from Apple/Google)
- Avatar/profile photo (optional)
Financial data via open banking (read‑only)
- Account metadata (bank, type, currency, masked IDs)
- Balances
- Transactions (amount, date, description, merchant, category/MCC)
- Merchant enrichment (normalized names/logos where available)
- Your app artifacts (budgets, goals, notes, tags/splits)
We do not initiate payments using these connections.
Device & technical
- IP address; device & OS/app version
- Crash logs & performance events
Support
- Messages you send to support
- Attachments/screenshots you include
Marketing & comms
- Newsletter (opt‑in)
- Transactional/product emails
- Campaign/UTM tags on signup
Analytics (consent‑based)
- Product analytics for usage, quality and conversion (PostHog, EU Cloud)
- Aggregated funnels and cohorts, only after you opt in; no session recording or heatmaps
- A first‑party analytics identifier stored on your device once you consent
Special categories
- We do not intentionally collect special categories; transaction text may incidentally imply them; we do not profile on these.
Portability & deletion
- Data export (JSON/CSV for transactions, budgets, goals, tags) on request at privacy@plenzo.app
- Self-serve delete account in the app (irreversible; bank data purged after a short delay)
Why we process your data (purposes & legal bases)
- Provide the service (contract necessity): accounts, balances, transactions, categorization, analytics; account maintenance and transactional messages.
- Open‑banking connection & refresh (explicit consent + contract): you consent via Tink for access and 2–4× daily refresh; once retrieved, we process under contract necessity.
- Security & fraud prevention (legitimate interests).
- Analytics & product improvement (consent): PostHog loads only after you opt in via the cookie banner; you can withdraw anytime via “Cookie settings” in the footer. No advertising IDs.
- Marketing communications (consent): newsletters and non‑essential messages require opt‑in.
- Service reliability and abuse prevention (legitimate interests): short-term operational logs, 14 days.
How long we keep data (retention)
- Account data: kept while the account is active. On deletion your data is removed immediately; the control record for the deletion job is purged after 24 hours. Encrypted database backups roll off on a 14-day cycle.
- Connected-account data: fetching stops the moment you disconnect a bank. Transaction data is deleted together with the account, unless the law requires us to keep it longer.
- Support records: kept for as long as handling your case requires, and no longer than 24 months.
- Crash/diagnostics: operational logs 14 days. Product analytics (PostHog, consent only) up to 12 months.
- Legal/accounting records: per statutory retention.
Who processes your data (sharing & processors)
- Open-banking connectivity: Tink (AISP).
- Cloud hosting & database: Amazon Web Services, eu-north-1 (Stockholm, EEA).
- Transactional email: Resend.
- Push notifications: Apple Push Notification service (iOS) and Firebase Cloud Messaging (Android) — delivery only, no analytics.
- Product analytics: PostHog (PostHog EU Cloud, Frankfurt/Germany, EEA) — used only with your consent.
International data transfers
Where providers are outside the EEA/UK, we use approved safeguards (e.g., SCCs or the EU‑U.S. DPF where applicable) and perform transfer risk assessments.
Your rights
Access, rectify, delete, export (JSON/CSV), restrict/object (e.g., analytics), withdraw consent (e.g., disconnect bank accounts). For website analytics, use “Cookie settings” in the footer to withdraw your consent at any time. Use in‑app tools or contact privacy@plenzo.app. You can also complain to UODO.
Children
Plenzo is for users 18+. We do not knowingly collect data from minors.
Security
We encrypt in transit and protect at rest, enforce least‑privilege staff access, and monitor for abuse. For vulnerabilities, email security@plenzo.app (see /.well-known/security.txt).
Changes
We may update this Policy; we will post updates here and, if material, notify in‑app or by email. Effective date is at the top.