GDPR Compliance
Last Updated: 19 March 2026
What is GDPR?
The General Data Protection Regulation (GDPR) is EU law on data protection and privacy for individuals within the European Union and European Economic Area. The UK has retained equivalent provisions under the UK GDPR and Data Protection Act 2018.
Our Commitment
FinaviHub is committed to handling your personal data responsibly and in line with the principles of GDPR and UK data protection law. We collect only what is necessary, use it only for the purposes described in our Privacy Policy, and do not sell your data to third parties.
We apply the following data protection principles:
- Lawfulness, fairness and transparency: We process data lawfully and transparently.
- Purpose limitation: Data is collected for specified, legitimate purposes only.
- Data minimisation: We collect only what is necessary for the service.
- Accuracy: We aim to keep data accurate and up to date.
- Storage limitation: We retain data only for as long as necessary.
- Integrity and confidentiality: We implement appropriate technical security measures.
Your Rights Under GDPR
If you are in the UK or EU, you have the following rights:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct inaccurate or incomplete data.
- Right to erasure: You can request that we delete your personal data.
- Right to restrict processing: You can ask us to limit how we use your data in certain circumstances.
- Right to data portability: You can request your data in a structured, machine-readable format.
- Right to object: You can object to certain types of processing, including profiling.
- Rights regarding automated decisions: You have the right not to be subject to decisions made solely by automated processing that significantly affect you.
To exercise any of these rights, contact us at contact@finavihub.com. We will respond within one month of receiving your request.
Data Transfers Outside the UK/EEA
FinaviHub uses the following US-based service providers to operate the platform:
- Replit — application hosting
- Neon Database — cloud database
- OpenAI — AI coaching features (your financial data is sent to OpenAI to generate responses; OpenAI does not use API data for model training)
These providers are based in the United States. By using FinaviHub, you acknowledge that your data may be processed in the US. We use providers with appropriate data protection commitments under their terms of service.
Data Breach Notification
In the event of a personal data breach that is likely to affect your rights and freedoms, we will notify you and (where required by law) the relevant supervisory authority without undue delay. Under GDPR, breaches that pose a risk must be reported to the supervisory authority within 72 hours of becoming aware.
Cookies
FinaviHub uses cookies necessary for the platform to function (such as keeping you logged in). A cookie consent notice is displayed when you first visit the site. You can manage cookies through your browser settings at any time.
Supervisory Authority
If you are in the UK and have concerns about how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk. If you are in the EU, you may contact your local supervisory authority. We would, however, appreciate the opportunity to address your concerns directly first.
Changes to This Statement
We may update this GDPR statement from time to time. The date at the top of this page reflects when it was last revised.
Contact
For any questions about our data practices or to exercise your rights, please contact us at:
Email: contact@finavihub.com