Privacy policy

Last updated: August 6, 2026

Fimento AB (“Fimento”) is a Swedish technology company that takes your privacy seriously. This Privacy Policy explains how we handle personal data in our product offerings, why we do it, and what rights you have. We believe transparency builds trust – so here’s exactly how we handle your data, in plain language.

Our Different Roles

We play different roles depending on how your data is used. In most cases we act on behalf of another company (a customer of ours). In some limited situations, we act on our own.

Most of the time: we work for another company

In the vast majority of cases, we process personal data on behalf of our customers, for example, banks or other companies. That company decides what data is used and why; we simply follow their instructions.

What this means for you: If you want to exercise your rights (for example, delete your data), please contact the company you have a relationship with. When they delete your data, it is automatically deleted from our systems as well.

Sometimes: we act on our own

There are a few narrow situations where Fimento decides on its own how your data is handled, always to protect you or to improve the service:

  • We automatically detect and remove sensitive information from transaction data before it is stored or forwarded to our customer. For example, payments to healthcare providers, religious organisations or trade unions.
  • We automatically detect and remove personal data about other people that may appear in your transactions, for example Swish recipients, employees or individual counterparties, so their privacy is protected.
  • We use data to train and improve our analytics models. Before we do this, we run the data through an automatic step that removes names, account numbers, contact details and other identifiers.

 

How we protect your privacy:

  • We separate training and development environments from production systems
  • Identifiable data is retained only for a limited period (maximum 12 months)
  • After this period, data is deleted or pseudonymised/anonymised permanently
  • Aggregated or fully anonymised data may be retained longer

 

Important information: Once data has been permanently anonymised, it can no longer be linked to you as an individual. This means we cannot delete it on an individual basis, simply because we can no longer identify whose data it is. This is a security measure that protects your privacy.

Pseudonymised data is handled with strict safeguards and retained only as long as necessary.

Information We Collect

Depending on how you use our services, we may process both personal data and other types of data.

Personal Data

Personal data is any information that can be linked to you as an individual. Depending on the service, this may include:

  • Contact information: name, email address, phone number
  • Financial data used in the service: bank account information, transactions and accounting data.
  • Technical logs: activity and access logs that can be linked to you.

 

Other Data (Non-Personal Data)

We also process data that is not personal data, including:

  • Aggregated and anonymised statistics that cannot be linked to any individual.
  • Technical system data such as performance metrics and error logs.

Why we use your data

Providing and operating our servicesWe only use your data when there is a clear reason to do so. Here is a plain-language overview of what we use it for and why:

What we use it forWhy we’re allowed to
Provide and operate our services To deliver what we’ve agreed to deliver to our customer.
Support and troubleshooting To provide the support included in our service agreements.
Keeping the service secure, stable and loggedWe have a genuine business interest in keeping our systems safe and reliable, and we’ve made sure this doesn’t override your rights.
Improving our analytics models (Fimento acts on its own here)We have a genuine business interest in improving the service. Before we use data for this, we automatically strip out names, account numbers and contact details. We keep the data for a maximum of 12 months.
Filtering sensitive and third-party data out of transactions (Fimento acts on its own here)To protect you and other individuals. Data is removed automatically before it reaches our customer.
Meeting legal requirementsFor example, accounting and financial-regulation rules.

Where we rely on a “genuine business interest” as the reason for using your data, we’ve carefully weighed our interest against your rights, and you can always object.

If you’re a private individual (consumer flow)

If you are a private individual using a service that runs on Fimento, our customer usually asks for your consent before collecting your bank and sometimes transaction data. In that case:

  • Our customer, not Fimento, decides why your data is being collected and how long it is kept. Their own privacy notice will explain the specifics.
  • Your consent is voluntary. You can withdraw it at any time by contacting the company that asked for it. Withdrawing your consent doesn’t change what has already happened, but it stops any further use of your data through Fimento.
  • The bank connection itself, including BankID sign-in and reading your account information, is handled by Enable Banking Oy, not by our customer or Fimento. They are separately responsible for that step.
  • The small amount of processing that Fimento does on its own (filtering out sensitive and third-party data, and improving our analytics models) is not based on your consent. It continues to be governed by this policy, and you can object separately by emailing privacy@fimento.com.

If the Service is used for a company (business flow)

When our customer uses Fimento to look at a company rather than a private individual:

  • A company itself does not have privacy rights under the GDPR, only individuals do. So company balance and transaction history are treated as business data, not personal data.
  • The authorised signatory (the person who logs in with BankID for the company) is a private individual. Their name and personal identity number are used by Enable Banking to confirm identity. In normal flows, that information does not reach our customer or Fimento.
  • The company’s transactions may still contain personal data about individuals, for example salary payments, Swish recipients, sole traders or other counterparties. Fimento removes this data automatically before it is stored.
  • The rest of Fimento’s own processing (filtering and analytics improvement) works the same way as in the consumer flow.

Data Sharing

We never sell personal data.

We may share data with:

  • Our customers (the companies you have a relationship with).
  • Trusted suppliers who help us run the service, for example cloud hosting, communication tools and AI providers.
  • Enable Banking Oy, when the service needs access to your bank. Enable Banking acts on their own account, not as our supplier.
  • Authorities, when required by law.

Data Security

We use appropriate security measures to protect personal data and continuously work to improve our security. Data is encrypted both in transit and at rest, and we use role-based access control to ensure that only authorized personnel have access to data.

Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct information that is inaccurate.
  • Have your data deleted.
  • Restrict how your data is used.
  • Move your data to another provider (data portability).
  • Object to how your data is used.
  • Withdraw your consent at any time, if your data is being used on the basis of consent. Withdrawal doesn’t undo what has already happened, but stops any further use.
  • Ask for a human to review any decision made automatically about you that has a significant effect, and to challenge that decision.
  • Complain to the Swedish Authority for Privacy Protection (IMY) if you think your rights aren’t being respected.

How to exercise your rights

If your data was processed through one of our customers (which is the most common scenario), the customer is responsible for handling your request. You should contact them directly.

If you contact Fimento, we will guide you to the correct organization where applicable. For anything that concerns what Fimento does on its own (improving our analytics models, filtering out sensitive or third-party data), you can reach us directly at privacy@fimento.com. Questions about the bank connection itself should go to Enable Banking.

When data has been properly anonymized, it can no longer be linked to you as an individual, not by Fimento or anyone else. This is a privacy protection: your identity has been permanently separated from the data. As a result, individual deletion requests do not apply to anonymized data, since there is no way to determine whose data it is.

Our Commitment to
Protecting Your Data

Fimento is a Swedish company, and all our data processing is governed by the EU General Data Protection Regulation (GDPR). We continuously review and improve our privacy and security practices to ensure your data remains protected.

Updates to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available on our website.

Contact us

Don’t hesitate to reach out, we’re happy to answer any questions about how your data is handled.

Fimento AB

Organisation number: 559223-6896
Mäster Samuelsgatan 20
111 56, Stockholm
Sweden

For privacy-related questions, contact us at privacy@fimento.com

At the heart of finance and tech, we shape the future with precision-crafted solutions, infusing every line