Data Controller: Axiom Digital Systems Ltd (Co. 17031903). Modo Insight is a trading name of Axiom Digital
Systems Ltd. ICO Registration Number:ZC112218
Open Banking: Axiom Digital Systems Ltd provides regulated Open Banking account information services through an FCA-authorised Open Banking provider. Open Banking data is retrieved exclusively to deliver the financial management features of Modo Insight.
1. Introduction
Axiom Digital Systems Ltd ("we", "our", or "us") respects your privacy and is committed to protecting your
personal data. This policy explains how we collect and process data across our services, including our
technology consultancy and the Modo Insight application.
2. Data Collection & Processing
As a fintech service provider, we collect and process data under the following conditions:
Purpose of Ingestion (Modo Insight): We collect and process read-only financial data for
the express purpose of providing Open Banking Account Information Services. This data is
retrieved via our FCA-authorised Open Banking provider and is used solely to provide financial
analysis, categorisation, and insights. We do not facilitate financial transactions or have write-access to
your accounts.
Biometric Data: The Modo app utilizes your device's native biometric authentication
(TouchID/FaceID) for secure access. This data remains on your secure device enclave and is never transmitted
to or stored by our servers.
3. Legal Basis for Processing
We process your personal data based on the following legal grounds:
Contract: Processing is necessary to provide the Open Banking account information services you have requested.
Legitimate Interests: Necessary to provide our core services and maintain our
infrastructure.
Consent: For marketing communications and optional data features (which you may withdraw at
any time).
4. Data Retention
We adhere to strict data minimisation and retention policies:
Regulatory Purge: Upon revocation of consent, all associated financial data is permanently
purged from our active systems within 72 hours.
Re-Consent Cycle: We require active re-consent every 90 days to maintain continuous access
to your Open Banking data.
Account Deletion: Standard personal data is retained only for as long as your account is
active or as needed to provide services, unless a longer retention is mandated by UK law.
5. Security
Your financial data is protected by industry-leading security measures, including Bank-grade encryption (AES-256-GCM)
at rest and TLS 1.3 for all data in transit between your device, our servers, and our Open Banking partners.
Your data is stored in the United Kingdom: backend servers are hosted on Azure UK West and the database is hosted on Supabase (AWS London, eu-west-2). In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay.
6. Your Rights
Under the UK GDPR, you have the following rights:
Right to Access: Request a copy of the personal data we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete data.
Right to Erasure: Request deletion of your personal data ("right to be forgotten").
Right to Object: Object to processing of your personal data.
Right to Data Portability: Request your data in a machine-readable format.
Right to Restrict Processing: Request that we limit how we use your data.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
7. Compliance & Contact
Axiom Digital Systems Ltd is registered with the UK Information Commissioner's Office (ICO) under number ZC112218. If you wish to exercise your data rights or have questions about our privacy practices, please contact us:
Axiom Digital Systems Ltd (Co. 17031903)
167-169 Great Portland Street, 5th Floor
London, W1W 5PF
United Kingdom