FundSys
Log in

Privacy Policy

Last updated: 2 July 2026

This Privacy Policy describes how FundSys LLC ("FundSys", "we") processes personal data when you use our platform for building US financial infrastructure. We treat your data confidentially and in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

1. Data Controller

FundSys LLC is the controller responsible for the processing of your personal data. For any privacy-related enquiries, contact us at hello@fundsys.us.

Postal address: FundSys LLC, 2031 Harrison St, Hollywood, FL 33020, USA.

2. Data We Process

We process the following categories of personal data to the extent necessary to provide our services:

  • Account and profile data: name, email address, phone number.
  • Identity and verification data: passport details, date of birth, home and business address, tax identification numbers.
  • Company data: information about your entity (e.g. legal name, registration details, business activity).
  • Financial account data: details of linked bank and payment accounts and associated transaction and balance information.
  • Documents: evidence and files you upload.
  • Usage and technical data: log data, device and connection information generated when operating the platform.
  • Communications data: the content of your requests and our correspondence with you.

3. Purposes and Legal Bases

We process your data to provide our services (including entity formation, applying for tax identification numbers, setting up banking infrastructure, and compliance support), to meet legal obligations, and to keep the platform secure.

The legal bases are performance of our contract with you (Art. 6(1)(b) GDPR), compliance with legal obligations (lit. c), your consent (lit. a) where given, and our legitimate interests in a secure and functional service (lit. f).

4. Consent

Where processing relies on your consent, we obtain it during onboarding. You may withdraw consent at any time with effect for the future; this does not affect the lawfulness of processing carried out before the withdrawal.

5. Sharing With Third Parties and Service Providers

We share personal data only where necessary to provide our services or where a legal basis exists. Service providers process data on our behalf and on our instructions. Categories of recipients:

  • Providers of cloud infrastructure, database and storage hosting (processed within the EU).
  • Providers for secure financial-account connectivity. To connect your bank accounts we use Plaid Inc. Plaid processes the account data you provide in accordance with its own privacy policy: https://plaid.com/legal/#end-user-privacy-policy.
  • Providers of email delivery and communication features.
  • Authorities and financial institutions, where required to carry out the services you request (e.g. registrations, account openings).

We do not sell your personal data.

When you choose to connect a financial account through Plaid, FundSys receives and processes only the financial account data required for the FundSys service features you use, such as account identifiers, balances, transactions, and account metadata. FundSys does not sell Plaid-derived data and does not use it for purposes unrelated to the service without your authorization.

6. International Data Transfers

Our core infrastructure operates within the European Union. In the course of providing US-related services (e.g. account openings, connecting US financial services), a transfer to the United States may be necessary. Such transfers are carried out on the basis of appropriate safeguards under the GDPR.

7. Retention and Deletion

We retain personal data and financial data only for as long as necessary to provide the FundSys services, maintain platform security, comply with legal, tax, accounting, contractual, and regulatory obligations, resolve disputes, and maintain required audit records.

FundSys maintains a documented Data Retention and Deletion Policy that defines retention periods and deletion triggers by data category, including account data, identity and verification data, uploaded documents, financial account data, Plaid-related tokens and identifiers, transaction and balance data, consent records, security logs, audit logs, and backups.

Account and profile data, identity and verification data, and documents you upload are, as a rule, retained for the life of your account and deleted on account closure or a valid erasure request, unless a legal retention obligation applies. Shorter periods apply to specific categories; for example, access data for linked financial accounts is deleted when the respective account is disconnected.

Deletion may be triggered by account closure, withdrawal of consent, bank-account disconnection, expiry of the relevant service purpose, a valid deletion request, or expiry of applicable legal retention periods. Where deletion is not immediately possible because of legal retention obligations, security obligations, backup integrity, dispute preservation, or legal hold, we restrict further processing and delete or anonymise the data when the relevant obligation expires.

Backup data is retained for a limited recovery period and expires through scheduled backup rotation. Data deleted from active systems is not restored from backups except where necessary for security, legal, or disaster-recovery purposes.

Our retention and deletion practices are reviewed at least annually and whenever there is a material change to our systems, data flows, third-party providers, or applicable data privacy laws.

8. Data Security

We apply technical and organisational measures to protect your data, including encryption in transit (TLS), encryption at rest, additional encryption of particularly sensitive fields, strict least-privilege access controls, and logging of security-relevant access.

Plaid access tokens and other sensitive financial identifiers are encrypted and access-restricted. Access to financial data is limited to authorized personnel and systems with a legitimate business need.

9. Your Rights

Under the GDPR you have the right to access, rectification, erasure, restriction of processing, and data portability, as well as the right to object to processing and to withdraw any consent given. To exercise these rights, contact us at hello@fundsys.us. You also have the right to lodge a complaint with a data protection supervisory authority.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in legal or operational requirements. The current version is always available on this page.

11. Contact

For questions about this Privacy Policy or the processing of your data, contact us at hello@fundsys.us.

FundSys
Imprint Privacy Terms