FILIAR

Legal

Privacy policy

This policy describes only the processing that actually happens on this website.

PRIVACY-POLICY-v1.0 · 2026-08-28

1. Two separate layers

This policy covers the FILIAR website. It does not cover the operation of a FILIAR terminal.

The later privacy model of the terminal is part of the concept: session data is intended to be purged locally after use, while authentication and account data remain with the respective bank. That model is not implemented and creates no processing today.

2. Controller

The controller will be named in the imprint once the legal entity is confirmed. Until then, please use the contact route stated there.

3. Hosting and backend

The website is served through Lovable's hosting and backend infrastructure. Database, form processing and server functions run in a backend instance located in Europe (region eu-west-2).

When the site is requested, the infrastructure processes technically necessary connection data such as IP address, timestamp, requested resource, status code and user agent. These server logs serve operation, stability and security only and are deleted after a short period.

4. Appearance setting (local storage)

If you choose light or dark mode manually, your browser stores that choice locally under the key “filiar-theme”. Only the value “light” or “dark” is stored.

Without a manual choice we follow your device setting (prefers-color-scheme) and store nothing. No profile, identifier or audience measurement is created.

5. No cookies for analytics or advertising

This website uses no analytics, tracking, marketing or advertising technologies. No external media, maps, chat widgets or booking embeds are included. Fonts are served locally rather than from external CDNs.

That is why no cookie banner is shown: a choice without consent-relevant technologies would have no effect. Should optional technologies be introduced, they will be documented in advance, technically blocked until consent, and released through a consent dialogue.

6. Launch updates with double opt-in

If you sign up for FILIAR updates, we process your email address, an optional region, the displayed language and the time of your consent.

You then receive a confirmation email with a single-use, time-limited link. The confirmation token is stored as a hash only. The sign-up counts only after your confirmation.

The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time via the unsubscribe link; withdrawal takes effect immediately and is logged with its timestamp.

As proof we store purpose, language, text version and the hash of the consent text shown. No IP address is stored for this.

7. Partner enquiries

For an enquiry we process name, business email address, organisation, role, your message and optionally a phone number.

The legal basis is handling the enquiry you actively submitted and our legitimate interest in communicating with interested institutions (Art. 6(1)(b) and (f) GDPR). No separate consent is required and none is forced.

8. Whitepaper requests

For a document request we process name, business email address, organisation, position, the requested documents and your stated purpose.

Documents are not sent automatically. Every request is reviewed manually. After approval you receive a personal, time-limited access link that is not publicly indexed.

The concept acknowledgement is a factual acknowledgement, neither a privacy nor a marketing consent.

9. Email dispatch

Transactional emails (confirmation, receipt, approval) are sent through a central dispatch configuration. Production sending becomes active only once the final domain is verified and SPF, DKIM and DMARC are in place.

The email service provider will be named here once it is contractually engaged. Until then no dispatch to third parties takes place.

10. Recipients and processors

Personal data is never sold and never used for third-party advertising.

Recipients are limited to service providers required for operation, hosting, database and email dispatch, under data processing agreements. The backend instance is located in Europe; possible sub-processors and any third-country transfers will be listed here once they are determined.

11. Retention

  • Unconfirmed sign-ups are deleted automatically after a short period.
  • Confirmed sign-ups remain until withdrawal.
  • Withdrawn consent is kept only as proof of the withdrawal and then deleted.
  • Contact and whitepaper requests are deleted within a defined period after processing ends.
  • Technical logs and abuse-protection counters are deleted quickly.
  • The specific periods are configured and will be confirmed before public launch.

12. Your rights

  • Access to the data stored about you
  • Rectification of inaccurate data
  • Erasure
  • Restriction of processing
  • Data portability
  • Objection to processing based on legitimate interests
  • Withdrawal of consent with future effect
  • Complaint to a data protection supervisory authority

13. Version

Version PRIVACY-POLICY-v1.0. Earlier versions are retained and never overwritten.