Figena
How Figena collects, uses, and protects your data.
Operating entity
Figena is operated by Accentrust Inc. References to Figena, we, us, or our in this document refer to the Figena service and its operating entity, Accentrust Inc., unless the context says otherwise.
Figena is a comprehensive financial management platform designed to help individuals and businesses organize their finances across multiple devices and platforms. We provide secure financial tracking, analytics, account management, and business intelligence tools through our unified platform. This Privacy Policy explains how we collect, use, and safeguard your financial data when you use our services.
We collect different types of information to provide our financial management services, with strong privacy protections built into our data collection practices:
We apply data minimization, access controls, retention rules, and other safeguards appropriate to the data and service. We do not claim that all data is anonymous or inaccessible to authorized service operations.
We collect information through the following methods:
We process your information for these essential purposes:
We use administrative, technical, and organizational safeguards appropriate to the nature of the service and data. No storage or transmission method is completely secure, and our controls may evolve as the service changes.
We do not sell, rent, trade, or share your personal financial data with third parties for marketing purposes. We may only disclose information: (a) with your explicit consent, (b) to comply with legal obligations or court orders, (c) to protect our rights or prevent fraud, (d) to service providers who assist with technical operations under strict confidentiality agreements, or (e) in connection with a business merger or acquisition (with prior notice and opt-out rights).
You have comprehensive control over your data: Access and download your financial data through our export feature. Correct or update information directly within our platform. Delete specific transactions or entire account data. Control synchronization settings and authentication preferences. Opt out of usage analytics and marketing communications. Request data portability in standard formats. We respond to rights requests within 30 days and provide self-service options where possible.
Our platform uses cookies and similar technologies only as necessary for core functionality. Our web application may use essential cookies for functionality, security, session management, and user preferences. Our mobile applications use platform-native storage mechanisms. We do not use third-party advertising networks or behavioral tracking technologies. All analytics data is anonymized and aggregated to protect your privacy.
When synchronization is available and enabled, data is transferred and stored using safeguards appropriate to the service. Availability, controls, and retention behavior are described in current product and privacy documentation.
We retain your data only as long as necessary to provide services or as required by law. You can delete individual transactions, categories, or your entire account at any time through our platform. Deleted data is immediately removed from your local storage and synchronized deletions propagate across your connected devices according to our secure deletion protocols, typically within 30 days.
Your data may be processed on servers in different countries where our secure cloud infrastructure operates. We ensure appropriate data protection safeguards and compliance frameworks are in place for international data transfers. For users in the EU, we comply with GDPR requirements. Canadian and other international users benefit from similar privacy protections based on applicable local laws and international data protection standards.
Figena is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete it immediately. Parents who believe their child has provided information to us should contact our support team.
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated through the app or via email. Continued use of our services after changes constitutes acceptance of the updated policy. We maintain previous versions for your reference.
We process your personal data based on the following legal foundations: CONTRACTUAL NECESSITY: Processing required to provide our financial management services and honor our Terms of Service. LEGITIMATE INTERESTS: Improving our services, preventing fraud, ensuring security, and conducting analytics with appropriate safeguards. LEGAL COMPLIANCE: Meeting regulatory requirements, tax obligations, and responding to legal requests. CONSENT: Where you have explicitly agreed to specific processing activities, which you may withdraw at any time. We regularly assess our legal basis to ensure continued compliance with privacy laws.
Figena uses automated processing to enhance your financial management experience: TRANSACTION CATEGORIZATION: Machine learning algorithms automatically categorize transactions based on merchant data and spending patterns. FRAUD DETECTION: Automated systems monitor for unusual activity to protect your financial data. BUDGET INSIGHTS: Algorithms analyze your spending to provide personalized financial insights and recommendations. PERFORMANCE OPTIMIZATION: Automated systems optimize app performance and resource usage across devices. You have the right to request human review of automated decisions and can opt out of certain automated processing features through your privacy settings.
Where supported, Figena can request device-level biometric authentication. The operating system performs the biometric check and returns an authentication result; availability and behavior depend on the device and platform.
In the event of a merger, acquisition, or sale of assets: ADVANCE NOTICE: We will provide 30 days advance notice of any ownership changes that affect data processing. USER CHOICE: You will have the option to delete your data or opt out before any transfer. CONTINUED PROTECTION: The acquiring entity must commit to privacy protections at least as stringent as this policy. DATA MINIMIZATION: Only necessary data for service continuity will be transferred; all other data will be deleted. REGULATORY COMPLIANCE: All transfers will comply with applicable data protection laws and require appropriate legal safeguards.
International transfers, when required, use the legal mechanisms and safeguards described in this policy and applicable agreements. Data-residency commitments apply only when expressly agreed or legally required.
Our comprehensive incident response framework: DETECTION SYSTEMS: Continuous monitoring systems detect potential security incidents and data breaches. RAPID RESPONSE: Security incidents receive immediate priority assessment and containment efforts. REGULATORY NOTIFICATION: We comply with all applicable legal notification requirements to relevant authorities. USER NOTIFICATION: Affected users are promptly notified with clear information about incidents and recommended protective actions. FORENSIC INVESTIGATION: Independent security experts investigate incidents to strengthen our systems and prevent recurrence. TRANSPARENCY REPORTS: We publish regular transparency reports detailing security improvements and industry best practices.
Privacy is considered throughout product delivery through purpose limitation, access controls, retention practices, reviews, and privacy-conscious defaults. Specific practices are described in this policy and may evolve with the service.
When we work with service providers, your privacy remains protected: STRICT VETTING PROCESS: All service providers undergo comprehensive privacy and security assessments. DATA PROCESSING AGREEMENTS: Partners must sign detailed agreements limiting data use to specified purposes only. REGULAR AUDITS: We conduct regular audits of service providers to ensure compliance with privacy commitments. LIMITED ACCESS: Service providers receive only minimum necessary data to perform their specific functions. GEOGRAPHIC RESTRICTIONS: We specify where service providers can process data based on privacy requirements. IMMEDIATE TERMINATION: Contracts include immediate termination clauses for privacy violations.
If Figena conducts product research using customer information, it does so under the purposes, choices, safeguards, and legal bases described in this policy. We do not make blanket claims that research data is fully anonymous.
For privacy-related questions, data subject rights requests, or concerns about our privacy practices, contact us at privacy@figena.com or through our in-app support system. Our Data Protection Officer can be reached at dpo@figena.com for specific privacy compliance matters. We are committed to resolving privacy concerns promptly and transparently. This policy is effective as of January 2025.