English
DanskPrivacy Policy – PSD2
Last updated: 14 February 2025
You are in safe hands with Subaio
When you give your consent, we help your bank get an overview of your finances. We do this by retrieving your account data directly from your bank – securely and only with your permission.
Here is the most important thing to know:
- We only use your data for the credit assessment
- We do not share your information with others
- Your data is stored securely in Denmark
- We automatically delete your data as agreed with the bank
- You can always withdraw your consent
You do not need to do anything else – we handle everything for you in the background, and you can withdraw your consent at any time.
1. Where do we receive your information from?
This privacy policy applies when you consent to Subaio ApS, CVR no. 37766585, Gasvaerksvej 26B, 1st floor, 9000 Aalborg, Denmark processing your information. Subaio is authorised as an Account Information Service Provider (AISP) under the supervision of the Danish Financial Supervisory Authority.
Subaio is the data controller for the personal data processed in connection with the Service. We are committed to complying with applicable legislation, including the General Data Protection Regulation (GDPR).
2. What are the sources of personal data?
You give us permission to extract your bank account information from your bank.
3. What information does Subaio collect and process about you?
As part of the request from your potential lender, Subaio collects:
- Bank account data – name, accounts, transaction data and details from accounts you have granted access to
- Technical information – information about your use of the Service, such as browser version and actions
- Sensitive information – transactions are categorised neutrally (e.g. "payments to associations")
4. Why does Subaio process your information?
Subaio processes your personal data for the following purposes:
- Delivery of the Service, including preparation and sharing of the budget
- Fulfilment of legal obligations
- Legitimate interest in operating and improving services
| Purpose | Legal basis | Types of information |
|---|---|---|
| Delivery of the Service | Consent | Bank account data and transaction data |
| Commercial and statistical purposes | Legitimate interest | Anonymised and aggregated data |
| Transfer to third countries | EU Standard Contractual Clauses | Data necessary for delivery |
5. Third parties
We share personal data with external data processors who assist with the Service. They may only use information where necessary and on instruction from Subaio. Data processors are subject to data protection legislation through written agreements.
Some data processors use cookies that are necessary for the secure handling of the user's session.
You can manage cookie preferences in your browser settings.
6. Joint applications
If you apply for credit together with another person (e.g. a spouse), the primary applicant will gain access to information about the co-applicant's financial circumstances. An applicant must be able to view and edit the joint budget before sharing.
7. Changes to the policy
Subaio reserves the right to amend this policy. Changes will be notified with reasonable notice via our website.
Changes will not have retroactive effect.
8. Data security
Subaio has implemented appropriate technical and organisational security measures to protect personal data against unauthorised access or deletion. The security level is regularly reassessed.
9. Retention period
Your information is only retained for as long as necessary to fulfil the purpose for which it was collected. As a general rule, all personal data is deleted no later than 30 days after the Service has been delivered.
10. Your rights
You have the right to:
- Request access to your personal data
- Have data corrected or deleted
- Have processing restricted
- Object to processing
- Receive your data in a structured format (data portability)
You have the right to exercise these rights free of charge. In the case of repeated or manifestly unfounded requests, a fee may be charged.
You may withdraw your consent with prospective effect.
Requests should be directed to: dpo@subaio.com
11. Contact
Subaio ApS
Gasvaerksvej 26B, 1st floor
9000 Aalborg, Denmark
Email: dpo@subaio.com
Complaints can be submitted to:
Datatilsynet (Danish Data Protection Agency)
Carl Jacobsens Vej 35
2500 Valby, Denmark