Legal
Privacy Policy
Last updated 16 June 2026
This Privacy Policy explains what data iban2bic ("we", "us") processes when you use our website and IBAN → BIC conversion API, and the choices you have. We are based in the European Union and act as the data controller for your account data.
1. Data we collect
We keep data collection to the minimum required to run the service.
- Account data — your name, email address and a hashed password, created when our team provisions your account.
- Conversion input — the IBAN you send to the API, used solely to resolve its BIC and bank details.
- Usage metadata — timestamps, derived country code, outcome, latency and the API key used, for billing and analytics.
- Billing data — invoices, credit grants and balances.
2. How we handle IBANs
IBANs are sensitive. Every full IBAN you submit is encrypted at rest with AES-256-GCM and stored separately from analytics data; on the analytics path we keep only a masked form and the two-letter country code.
We never sell IBANs or any customer data, and we never use submitted IBANs for marketing.
3. Why we process your data (legal bases)
- Performance of a contract — to provide the API and your dashboard.
- Legitimate interests — to secure, debug, meter and improve the service.
- Legal obligation — to keep accounting and invoicing records.
4. Retention
We retain account and billing data for as long as your account is active and as required by law. Encrypted IBANs are retained only as long as needed for support and audit, then deleted. Aggregated, non-identifying analytics may be kept longer.
5. Sharing and sub-processors
We share data only with service providers that help us operate: cloud hosting, transactional email, and upstream banking-data providers used to resolve a BIC. All are bound by data-processing agreements.
6. International transfers
We process data within the EU/EEA wherever possible. Where a transfer outside the EEA is necessary, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
7. Your rights
Subject to applicable law (including the GDPR), you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing.
- Email [email protected] to exercise any of these rights.
- You may also lodge a complaint with your local data protection authority.
8. Security
We use encryption in transit (TLS) and at rest, hashed API keys, role-based access controls and least-privilege practices. No method of transmission or storage is perfectly secure, but we work hard to protect your data.
9. Cookies
Our app uses strictly necessary cookies for authentication and session management only. We do not use advertising or third-party tracking cookies.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above and, where appropriate, communicated to you directly.
11. Contact
Questions about this policy or your data? Email [email protected].