Privacy Policy
Your data, protected. How GoodBreach collects, uses, stores, and shares your personal data.
Last updated: January 2026
1.Introduction
GoodBreach Technologies Ltd ("we", "our", or "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the GoodBreach waitlist, mobile application and related services (together, the "Services").
We operate in collaboration with Finexer Limited, a regulated Account Information Service Provider (AISP) under PSD2. Finexer holds the regulated AISP authorisation under the FCA, enabling GoodBreach to access your transaction data securely and lawfully once live integrations are enabled.
We comply with UK GDPR, the Data Protection Act 2018, and FCA Consumer Duty requirements. If you have questions about this policy, contact us at team@goodbreach.com.
2.Key privacy principles
- Transparency: we are clear about what data we collect and why.
- User control: you retain full control over your data and can withdraw consent anytime.
- Protection: we use industry-standard security to protect your information.
- Consumer Duty aligned: our data practices support proactive harm prevention.
3.Data we collect
A. Information you provide directly:
B. Information accessed via Open Banking (once live):
C. Automatically collected data:
- Account details: name, email address, phone number, and secure password
- Profile information: photo, username, savings goals, and preferences
- Feedback: responses to surveys, user testing, and support inquiries
- Account balance and transaction history (via our regulated Open Banking collaborator, Finexer)
- Merchant information and spending categories
- Frequency and amount of discretionary spending
- Device identifiers and IP address
- App usage metrics: feature interactions, session duration, and timestamps
- Crash and error logs to identify and fix technical issues
4.How we use your data
We will NEVER sell, rent, or trade your personal information to third parties.
- Deliver behavioural intercepts: timely, personalised reminders of your savings goals
- Generate financial insights: identify spending patterns and savings opportunities
- Measure intervention effectiveness: track which nudges help you achieve your goals
- Enable community features: challenges and aggregated community progress
- Communicate updates: product improvements and feedback opportunities
- Ensure compliance: meet regulatory obligations and prevent misuse
5.Legal bases for processing
- Consent: you explicitly consent to connect your bank account, share spending data, and receive personalised guidance. You can withdraw consent anytime.
- Contractual necessity: to provide the Services you signed up for, including account management and goal tracking.
- Legitimate interest: operating, improving, and securing the platform.
- Legal obligation: UK regulatory requirements, including AML/KYC obligations under the Money Laundering Regulations 2017. Related records are retained for 7 years after account closure.
6.Data sharing
We share your data only when necessary and under strict confidentiality agreements. Finexer Limited, our regulated AISP, receives Open Banking consent records and transaction data only to retrieve your account information. Amazon Web Services (AWS) securely hosts our encrypted data (TLS 1.3 in transit, AES-256-GCM at rest) in UK/EU data centres. Analytics and monitoring services (such as Sentry, PostHog and Firebase) receive hashed, anonymised usage data only.
All collaborators are required to comply with UK GDPR and execute Data Processing Agreements (DPAs) with us.
7.Data retention
- Raw transaction data from Open Banking: retained for 90 days, then anonymised
- Account registration data: retained while your account is active
- Behavioural effectiveness scores: anonymised and retained indefinitely for product improvement
- AML/KYC records: retained for 7 years after account closure (regulatory requirement)
8.Your data protection rights
Under UK GDPR, you have the right of access, to rectification, to erasure, to restrict processing, to data portability, to object, and to withdraw consent at any time.
To exercise any of these rights, contact us at team@goodbreach.com. We will respond within 30 days.
9.Security measures
- Encryption in transit (TLS 1.3) and at rest (AES-256-GCM)
- Role-based access controls on a need-to-know basis
- Multi-factor authentication for all staff accessing data systems
- Continuous security monitoring and quarterly external penetration testing
- Web application firewall protection against common vulnerabilities and DDoS attacks
10.Data breach notification
If we discover a data breach that affects your personal information, we will notify the Information Commissioner's Office (ICO) within 72 hours (as required by UK GDPR Article 33), notify you directly where there is a likely high risk to your rights and freedoms, and investigate and remediate the breach with updates on the resolution.
11.International data transfers
We primarily store and process your data within the United Kingdom and European Economic Area (EEA). Where international transfers occur, we use Standard Contractual Clauses (SCCs), encryption in transit and at rest, and strict need-to-know access.
12.Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy on our website, update the "Last updated" date, and request your consent if required by law.
13.Contact us
Email: team@goodbreach.com
Address: GoodBreach Ltd, 943, 12 Baltimore Wharf, London, E14 9FG, UK
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk.