FINAP
01 Home02 Pricing03 Features04 Documentation05 Contacts
Sign inGet API key
Sign inGet API key
Legal / Privacy19 sections

PRIVACY POLICY

Last updated: 21.05.2026

Read document
Document index19
01WHO WE ARE02OUR ROLE AS CONTROLLER AND PROCESSOR03PERSONAL DATA WE COLLECT04HOW WE COLLECT PERSONAL DATA05PURPOSES AND LAWFUL BASES FOR PROCESSING06WEB INTELLIGENCE, DEVICE SIGNALS AND FINGERPRINTING07SHARING PERSONAL DATA08INTERNATIONAL DATA TRANSFERS09DATA RETENTION10SECURITY11YOUR DATA PROTECTION RIGHTS12AUTOMATED DECISION-MAKING AND PROFILING13CUSTOMER RESPONSIBILITIES14CHILDREN’S DATA15MARKETING COMMUNICATIONS16THIRD-PARTY LINKS AND SERVICES17CHANGES TO THIS PRIVACY POLICY18COMPLAINTS19CONTACT DETAILS

This Privacy Policy explains how FINAP LTD, a company registered in England and Wales under company number 17235755, with its registered office at Suite 7039, 128 Aldersgate Street, Barbican, London, EC1A 4AE, United Kingdom (“FINAP”, “we”, “us”, or “our”), collects, uses, stores, shares, and protects personal data when individuals access our website, create an account, use our platform, APIs, SDKs, playground tools, dashboards, documentation, support services, or otherwise interact with us.

FINAP provides software development, API infrastructure, data intelligence, validation, and technology services. FINAP is not a bank, payment institution, electronic money institution, investment firm, cryptocurrency exchange, custodian, money transmitter, or regulated financial services provider.

This Privacy Policy applies to:

1. visitors to our website;

2. users of our platform and dashboard;

3. customers and prospective customers;

4. developers and technical users integrating our APIs or SDKs;

5. representatives of business customers;

6. individuals who contact us by email, support channels, or other communication methods;

7. end users whose technical signals may be processed through FINAP services, including WEB Intelligence, where applicable.

This Privacy Policy should be read together with our Terms of Use and, where applicable, our Cookie Policy and any Data Processing Agreement entered into between FINAP and a customer.

1. WHO WE ARE

Data Controller:

FINAP LTD

Company number: 17235755

Registered in: England and Wales

Registered office: Suite 7039, 128 Aldersgate Street, Barbican, London, EC1A 4AE, United Kingdom

Website: www.finap.uk

Email: support@finap.uk

Phone: +44 7893 93 08 00

For privacy-related enquiries, you may contact us at: support@finap.uk

2. OUR ROLE AS CONTROLLER AND PROCESSOR

Depending on the circumstances, FINAP may act either as a data controller or as a data processor.

FINAP acts as a data controller when we determine the purposes and means of processing personal data, for example when we process account registration data, billing data, website usage data, customer communications, compliance records, security logs, and business contact information.

FINAP may act as a data processor where a business customer uses our APIs, SDKs, WEB Intelligence tools, or related services to process personal data relating to its own users, customers, visitors, or systems, and where the customer determines the purposes and means of such processing.

Where FINAP acts as a processor, the customer is responsible for ensuring that it has a lawful basis for processing personal data and for providing appropriate privacy notices and disclosures to its own users. In such cases, FINAP processes personal data in accordance with the customer’s instructions, our Terms of Use, this Privacy Policy, and any applicable Data Processing Agreement.

3. PERSONAL DATA WE COLLECT

We may collect and process the following categories of personal data.

3.1 Account and Registration Data

When you create an account or use our platform, we may collect:

• name;

• company name;

• job title or role;

• business email address;

• phone number;

• account login details;

• company registration information;

• billing details;

• account preferences;

• authentication and security settings;

• account status and usage history.

3.2 Business Customer and KYB Information

Where necessary for business verification, fraud prevention, compliance, sanctions screening, or customer acceptance procedures, we may collect:

• company name;

• company number;

• jurisdiction of incorporation;

• registered address;

• trading name;

• website;

• business activity description;

• director or beneficial owner information;

• proof of business registration;

• business contact details;

• supporting documents provided by the customer;

• information from public registers, sanctions lists, or compliance databases.

3.3 Billing and Payment Information

We may process billing and transaction-related information, including:

• invoice details;

• payment status;

• payment method metadata;

• transaction references;

• balance top-up records;

• API usage charges;

• account balance records;

• VAT or tax information where applicable.

FINAP does not store full card numbers or card security codes. Card or payment processing may be handled by third-party payment providers.

3.4 API Usage and Technical Data

When you use our APIs, SDKs, dashboard, playground, or platform, we may collect:

• API keys and token identifiers;

• API request metadata;

• timestamps;

• endpoint usage;

• request and response logs;

• IP addresses;

• user agent strings;

• device and browser information;

• error logs;

• diagnostic information;

• system performance data;

• integration activity;

• usage volume;

• account activity logs;

• authentication logs;

• security logs.

3.5 WEB Intelligence Data

Where WEB Intelligence services are used, FINAP may process technical and risk-related signals, which may include:

• IP address;

• geolocation information;

• browser name and version;

• operating system and version;

• device type and device model;

• user agent string;

• SDK version;

• URL or page context;

• visitor identifier;

• event identifier;

• timestamps;

• VPN and proxy indicators;

• bot detection indicators;

• incognito or privacy mode indicators;

• tampering indicators;

• developer tools indicators;

• virtual machine indicators;

• velocity metrics;

• repeated activity indicators;

• network information, including ASN and ISP data;

• risk scores and confidence indicators;

• other technical, security, and environmental signals.

WEB Intelligence outputs are intended to support fraud prevention, security, risk assessment, user identification, and technical analysis.

3.6 Communications and Support Data

When you contact us, we may collect:

• name;

• email address;

• company details;

• message content;

• support requests;

• attachments you provide;

• correspondence history;

• call or meeting notes where applicable;

• technical issue details.

3.7 Website and Analytics Data

When you visit our website, we may collect:

• IP address;

• browser type;

• device information;

• pages visited;

• referral source;

• session information;

• approximate location;

• interaction data;

• cookie and similar technology data.

Detailed information about cookies and similar technologies is provided in our separate Cookie Policy.

4. HOW WE COLLECT PERSONAL DATA

We may collect personal data:

1. directly from you when you create an account, contact us, use our platform, or submit information;

2. automatically when you use our website, APIs, SDKs, playground, dashboard, or services;

3. from business customers who use our services in relation to their own users;

4. from public sources such as company registers and public business websites;

5. from third-party service providers, compliance providers, analytics tools, infrastructure providers, and payment providers;

6. from security, fraud prevention, or sanctions screening sources where applicable.

5. PURPOSES AND LAWFUL BASES FOR PROCESSING

We process personal data only where we have a lawful basis to do so under applicable data protection laws.

5.1 Account Creation and Platform Access

Purpose: To create and manage user accounts, authenticate users, provide dashboard access, issue API keys, and enable use of our services.

Personal data: Account data, login information, business contact details, authentication data, API credentials.

Lawful basis: Performance of a contract; legitimate interests in providing secure access to our platform.

5.2 Provision of API and SaaS Services

Purpose: To deliver API services, process requests, generate responses, provide SDK functionality, maintain usage records, and operate the platform.

Personal data: API usage data, technical data, request metadata, device/browser/IP signals where applicable.

Lawful basis: Performance of a contract; legitimate interests in operating and improving our services.

5.3 WEB Intelligence, Security and Fraud Prevention

Purpose: To provide WEB Intelligence services, analyse device/browser/network signals, detect suspicious activity, support fraud prevention, identify security risks, and generate risk indicators.

Personal data: IP addresses, device and browser signals, geolocation, visitor identifiers, risk indicators, velocity metrics, VPN/proxy indicators, bot signals, tampering indicators.

Lawful basis: Legitimate interests in fraud prevention, security, risk assessment, and service protection. Where required by law, customer consent or another lawful basis may be required before using certain technologies.

5.4 Billing, Payments and Balance Management

Purpose: To process payments, issue invoices, maintain account balances, record usage charges, and manage billing records.

Personal data: Billing details, transaction references, payment metadata, invoice data, balance records.

Lawful basis: Performance of a contract; compliance with legal obligations; legitimate interests in maintaining accurate financial records.

5.5 Customer Support and Communications

Purpose: To respond to enquiries, provide technical support, resolve issues, maintain communication records, and improve customer experience.

Personal data: Contact details, support messages, attachments, correspondence history, technical issue data.

Lawful basis: Performance of a contract; legitimate interests in customer support and service improvement.

5.6 Compliance, Sanctions and Risk Management

Purpose: To conduct business verification, sanctions checks, fraud prevention, abuse monitoring, legal compliance, and enforcement of our Terms of Use.

Personal data: Business details, company information, beneficial ownership information, IP/geolocation data, account activity, public register data, sanctions screening data.

Lawful basis: Legal obligations; legitimate interests in preventing fraud, sanctions violations, abuse, and unlawful use of our services.

5.7 Service Improvement and Product Development

Purpose: To monitor performance, analyse usage, improve API accuracy, develop new features, enhance security, improve machine learning models, and optimise our platform.

Personal data: Usage data, technical logs, API metadata, aggregated or pseudonymised data, support feedback.

Lawful basis: Legitimate interests in improving and developing our services.

5.8 Marketing and Business Development

Purpose: To send business communications, product updates, service information, and marketing messages where permitted.

Personal data: Business contact details, communication preferences, company details.

Lawful basis: Legitimate interests in B2B marketing; consent where required.

You may opt out of marketing communications at any time.

5.9 Legal Claims and Enforcement

Purpose: To enforce our Terms of Use, protect our rights, resolve disputes, prevent misuse, respond to legal requests, and defend legal claims.

Personal data: Account data, logs, communications, billing records, technical records, compliance records.

Lawful basis: Legitimate interests; legal obligations; establishment, exercise, or defence of legal claims.

6. WEB INTELLIGENCE, DEVICE SIGNALS AND FINGERPRINTING

FINAP’s WEB Intelligence service may process technical signals from browsers, devices, networks, IP addresses, and online sessions in order to provide device intelligence, fraud prevention, risk assessment, bot detection, VPN/proxy detection, visitor recognition, and related security functions.

These technologies may involve the collection or analysis of information from a user’s device or browser. In the UK, the ICO confirms that PECR covers cookies and similar technologies used for storing or accessing information on a user’s equipment, including fingerprinting techniques, web storage, scripts and tags.

Where a customer uses FINAP’s WEB Intelligence SDK or similar technology on its own website, application, checkout, or platform, that customer is responsible for:

1. providing clear privacy information to its users;

2. obtaining consent where required by applicable law;

3. identifying the appropriate lawful basis for processing;

4. ensuring that its use of FINAP technology complies with UK GDPR, EU GDPR, PECR, ePrivacy rules, and other applicable laws;

5. explaining the use of device intelligence, browser signals, IP intelligence, geolocation, fraud prevention, and similar technologies in its own privacy and cookie notices.

FINAP does not authorise customers to use WEB Intelligence for unlawful surveillance, unlawful profiling, discriminatory decisions, or any purpose prohibited by our Terms of Use.

7. SHARING PERSONAL DATA

We may share personal data with the following categories of recipients:

1. cloud infrastructure providers;

2. hosting providers;

3. payment processors;

4. analytics and monitoring providers;

5. email and communication providers;

6. support and customer service tools;

7. security and fraud prevention providers;

8. sanctions and compliance screening providers;

9. professional advisers, including lawyers, accountants, and auditors;

10. public authorities, regulators, law enforcement, courts, or government bodies where required by law;

11. third-party API and data providers used to deliver our services;

12. business partners or service providers where necessary to operate our platform.

We do not sell personal data.

We may share aggregated, anonymised, or de-identified data that does not identify individuals for analytics, benchmarking, product development, and business purposes.

8. INTERNATIONAL DATA TRANSFERS

FINAP is incorporated in the United Kingdom, but we may use service providers, infrastructure, or technology suppliers located in other countries, including the European Economic Area, the United States, and other jurisdictions.

Where personal data is transferred outside the United Kingdom or European Economic Area, we take reasonable steps to ensure appropriate safeguards are in place, which may include:

1. adequacy regulations or adequacy decisions;

2. standard contractual clauses;

3. the UK International Data Transfer Agreement or UK Addendum;

4. contractual protections with service providers;

5. technical and organisational security measures.

9. DATA RETENTION

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, including to provide services, comply with legal obligations, resolve disputes, maintain security, prevent abuse, and enforce our Terms of Use.

Typical retention periods may include:

• account data: for the duration of the account and a reasonable period after closure;

• billing and transaction records: up to 6 years for accounting and tax purposes;

• API logs and technical logs: for a limited period necessary for security, debugging, fraud prevention, and service operation;

• support communications: for as long as necessary to resolve enquiries and maintain business records;

• compliance and sanctions records: for as long as necessary to comply with legal and risk management obligations;

• anonymised or aggregated data: may be retained indefinitely where it no longer identifies individuals.

We may retain data longer where required by law, legal claims, audits, fraud prevention, security investigations, or regulatory obligations.

10. SECURITY

FINAP implements reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction.

These measures may include:

1. encryption in transit;

2. access controls;

3. authentication mechanisms;

4. secure API key management;

5. monitoring and logging;

6. infrastructure security controls;

7. vulnerability management;

8. backup and recovery procedures;

9. restricted internal access;

10. incident response procedures.

No internet-based service can be guaranteed to be completely secure. Customers are responsible for securing their own systems, API keys, integrations, and user environments.

11. YOUR DATA PROTECTION RIGHTS

Depending on your location and applicable law, you may have the following rights:

1. the right to be informed about how your personal data is used;

2. the right of access to your personal data;

3. the right to rectification of inaccurate data;

4. the right to erasure;

5. the right to restrict processing;

6. the right to data portability;

7. the right to object to processing;

8. rights in relation to automated decision-making and profiling;

9. the right to withdraw consent where processing is based on consent;

10. the right to lodge a complaint with a supervisory authority.

To exercise your rights, contact us at: support@finap.uk

We may need to verify your identity before responding to a request.

12. AUTOMATED DECISION-MAKING AND PROFILING

FINAP’s services may generate technical indicators, risk signals, confidence scores, velocity metrics, device identifiers, and other intelligence outputs through automated analysis.

FINAP does not use these outputs to make final decisions about individuals on behalf of customers. Customers are responsible for how they use FINAP outputs in their own systems and decision-making processes.

Customers must not use FINAP outputs as the sole basis for decisions that have legal or similarly significant effects on individuals unless they have implemented appropriate safeguards and comply with applicable laws.

13. CUSTOMER RESPONSIBILITIES

Customers using FINAP services are responsible for:

1. ensuring that they have a lawful basis for processing personal data;

2. providing appropriate privacy notices to their users;

3. obtaining valid consent where required;

4. complying with cookie, ePrivacy, PECR, GDPR, and similar laws;

5. ensuring their use of FINAP services is lawful, fair, and transparent;

6. responding to data subject rights requests where they act as controller;

7. configuring integrations in a privacy-compliant manner;

8. not sending unnecessary or prohibited personal data to FINAP;

9. maintaining their own data protection records and policies.

14. CHILDREN’S DATA

FINAP services are intended for business and professional use and are not directed at children.

We do not knowingly collect personal data from children. Customers must not use FINAP services in relation to children unless they have a lawful basis and all required consents, notices, and safeguards under applicable law.

15. MARKETING COMMUNICATIONS

We may send marketing communications to business contacts where permitted by law.

You may opt out of marketing emails at any time by using the unsubscribe link where provided or by contacting us at: support@finap.uk

We will continue to send necessary service, security, billing, legal, and transactional communications even if you opt out of marketing messages.

16. THIRD-PARTY LINKS AND SERVICES

Our website, platform, or documentation may contain links to third-party websites, tools, services, or integrations.

We are not responsible for the privacy practices, security, content, or policies of third parties. You should review the privacy policies of any third-party services you access.

17. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, operational practices, or business activities.

The updated version will be published on our website with a revised “Last updated” date.

Where required by law, we may notify users of material changes.

Continued use of our services after changes are published means that you acknowledge the updated Privacy Policy.

18. COMPLAINTS

If you have concerns about how we process personal data, please contact us first at: support@finap.uk

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) or another competent data protection authority.

UK Information Commissioner’s Office:

www.ico.org.uk

19. CONTACT DETAILS

For questions, requests, or concerns regarding this Privacy Policy or our processing of personal data, please contact:

FINAP LTD

Company No. 17235755

Suite 7039, 128 Aldersgate Street, Barbican, London, EC1A 4AE, United Kingdom

Email: support@finap.uk

Website: www.finap.uk

FINAP

Financial data and web intelligence APIs for modern applications.

sales@finap.uk
Payment methods
VisaMastercardApple PayGoogle PaySEPABitcoin
ExploreHomeFeaturesPricingDocumentationContacts
Legal01Terms of use02Privacy policy03Cookie policy04Payments policy05Data processing agreement06Refund policy
FINAP LTD / COMPANY NUMBER: 17235755 / UK-REGISTERED SOFTWARE COMPANY
© 2026 FINAP LTD