Legal
Privacy notice
Last updated 9 September 2026 · Applies to the aifredas.lt website and the Aifredas application
1. Who we are
Aifredas is operated by Primary MB, company code 307697149, Lithuania ("we", "us"). We are the data controller for this website and for the records we keep about our customers and their contacts. For financial and document data that a customer keeps in its own Aifredas deployment we act as a data processor on that customer's instructions, under a data processing agreement.
2. What data we process
On this website
- Server logs: IP address, requested page, browser type and time of request, kept for security and troubleshooting.
- What you send us by email when you get in touch: your name, email address, organisation and the content of your message.
In the Aifredas application
- Identity from your organisation's Microsoft directory: name, email address and group membership, used to sign you in and to decide what you may see.
- Documents your organisation places in its deployment, and the questions you ask the document assistant about them.
- Portfolio, investment, ownership and counterparty data your organisation enters or imports, which may include names and identifiers of natural persons such as owners, investors and representatives.
- Bank account information described in section 3.
- Technical logs and an audit trail of actions taken in the application: who signed in, what was read, exported, connected or changed, and when.
3. Bank account information
Where your organisation connects a bank account, balances and transactions are retrieved through Enable Banking Oy, a licensed account information service provider supervised by the Finnish Financial Supervisory Authority, after an authorised representative of your organisation gives consent at the bank using the bank's own strong customer authentication.
- Access is read-only. Aifredas cannot initiate payments or change anything at the bank.
- Aifredas never receives, asks for or stores online banking credentials.
- Consent can be withdrawn at any time in the application or at the bank. It also expires under the bank's rules unless renewed, after which no further data is retrieved.
- Bank data is used only to show balances and transactions to authorised finance users of your organisation, to categorise expenses and to reconcile payments. It is never sent to a language model.
- Full account numbers and payment descriptions are stored in masked and encrypted form. Access to them is limited to the finance group your organisation defines and is recorded in the audit trail.
4. Why and on what basis
- To provide the service under our contract with your organisation (performance of a contract, and the customer's instructions where we act as processor).
- To keep the service secure, detect misuse and investigate incidents (our legitimate interest in running a secure service).
- To answer your enquiries (our legitimate interest in responding to people who contact us, or steps taken before entering into a contract).
- To meet accounting, tax and other legal obligations (legal obligation).
We do not use personal data for profiling, advertising or automated decisions with legal effect, and we do not sell it.
5. Where data is stored
Each customer runs on a dedicated server in the European Union rented from a hosting provider chosen for that customer, currently OVH. The customer's data lives only on that server and its encrypted backups; we keep no copy elsewhere. Administrative access is limited to named operators over a private network, uses key-based authentication only, and is logged. This website is hosted on a server at Cherry Servers in the Netherlands.
6. Sub-processors
We use the following providers to deliver the service. We will update this list before adding a provider that processes customer data.
7. Retention
Customer data is held on the customer's own deployment, so the customer decides how long it is kept, within its statutory obligations; under Lithuanian accounting law that is ten years for accounting records. We do not keep separate copies.
- Bank consent records and the audit trail stay with the deployment for as long as it exists.
- When a customer contract ends, the deployment and its backups are deleted within 30 days and deletion is confirmed in writing, after the customer has exported its data.
- Website server logs are kept for 30 days.
- Email correspondence is kept for as long as needed to handle the enquiry or the customer relationship.
8. Your rights
You may ask for access to, correction of, or deletion of your personal data, object to processing, ask for it to be restricted, or receive it in a portable format. Where processing is based on consent you may withdraw it at any time. Requests concerning data held in a customer's deployment are handled together with that customer, which decides the purposes of that processing. You may also complain to the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija).
10. Changes to this notice
We will post changes on this page and update the date at the top. Material changes affecting customers are announced to them directly.
11. Contact
Data protection contact: primary.mazoji.bendrija@gmail.com
Primary MB, company code 307697149, Lithuania.