Legal
Privacy Policy
This policy explains, in a layered format, how we handle personal data. The summary below covers the essentials; the sections that follow give the detail required by the GDPR.
Effective from · version 2026-07-06
Summary
- FintechMall is a fintech-provider directory. It is not a bank, EMI, payment institution or crypto-asset service provider.
- We collect only what we need to run the directory, respond to you, process submissions and keep profiles accurate.
- Saved providers, comparisons and preferences are stored in your own browser, not sent to us.
- We do not sell personal data, and we do not currently run advertising, analytics or third-party tracking.
- You have rights over your data and can contact us at privacy@fintechmall.com.
Who is responsible
The data controller for the personal data described here is the operator of the FintechMall website — the individual or entity currently operating the FintechMall website, based in Lithuania.
Fintech Mall UAB is a planned UAB (private limited liability company) that is not yet incorporated. It is not currently the controller. When it is incorporated and takes over operating the service, we will update this policy with its registration details and confirm the controller.
Privacy contact: privacy@fintechmall.com. We have not appointed a data protection officer, because we are not required to; you can raise any privacy matter with us using the contact above.
Scope
This policy covers visitors to the website, business contacts, provider representatives, people who suggest corrections, people who submit listings, and people who request introductions.
Categories of personal data
Website and security data
IP address, request timestamps, browser and device information, user agent, referrer, requested URLs, error records, security and abuse-detection data, and cookie/consent identifiers.
Contact and introduction data
Name, work email, company, job title, message, product or project description, requested provider categories, selected providers, and correspondence and follow-up history.
Provider listing submissions
Contact name, work email, company, website, categories, regions, services, regulatory-status description, partnership interests, and submission correspondence.
Profile-update requests
Full name, corporate email, job title, company, LinkedIn URL, company contact-page URL, requested changes, supporting source URLs, notes, verification results, confirmation records, any uploaded logo and its file metadata, and review history and communications.
Correction suggestions
Name, email, correction description, supporting URLs, and notes and correspondence.
Public-source information
Where a profile or article identifies a founder, executive, contact or other individual, we may process personal data obtained from official provider sites, regulatory registers, company registers, public professional profiles, press releases or other public sources.
Browser-local data
Your saved providers, comparison selections and interface preferences are stored in your browser (via localStorage) and remain on your device. They are not transmitted to us. See the Cookie Policy.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the website functionality you use (browsing, search, filters). | Legitimate interests (Art. 6(1)(f)) — operating the directory. |
| Remembering saved providers, comparisons and preferences in your browser. | Your request for that functionality; stored on your device (see the Cookie Policy). |
| Responding to enquiries and introduction requests. | Steps at your request before a possible relationship (Art. 6(1)(b)); otherwise legitimate interests (Art. 6(1)(f)). |
| Processing listing submissions and profile-update requests. | Steps at your request (Art. 6(1)(b)) and legitimate interests in maintaining the directory (Art. 6(1)(f)). |
| Verifying a requester’s relationship with a provider. | Legitimate interests (Art. 6(1)(f)) — preventing impersonation and keeping profiles trustworthy. |
| Reviewing correction suggestions and maintaining editorial records. | Legitimate interests (Art. 6(1)(f)) — directory accuracy and an audit trail for disputes. |
| Making an introduction you requested to a selected provider. | Steps at your request (Art. 6(1)(b)) / your authorisation. |
| Preventing fraud, impersonation, spam and abuse, and securing the website. | Legitimate interests (Art. 6(1)(f)). |
| Establishing, exercising or defending legal claims. | Legitimate interests (Art. 6(1)(f)). |
| Complying with legal obligations. | Legal obligation (Art. 6(1)(c)). |
| Optional analytics or marketing (not currently used). | Consent (Art. 6(1)(a)) — only if introduced, and only where you opt in. |
We do not treat every activity as “consent”. In particular, we do not rely on a privacy checkbox as consent for processing that is necessary to handle your submission — that processing is based on your request and our legitimate interests. Any optional marketing would be a separate, unticked opt-in, and refusing it would not prevent you from submitting.
Legitimate interests
Where we rely on legitimate interests, those interests are:
- operating and improving a professional provider directory;
- maintaining accurate directory information;
- responding to business enquiries;
- verifying claims of provider authority;
- preventing misuse and impersonation;
- protecting the service and its users; and
- keeping an audit trail for disputed profile changes.
We balance these interests against your rights and freedoms, and you can object (see “Your rights”).
Sources of data
We obtain personal data from you, from your employer or organisation, from provider websites, public registers, public professional profiles, press releases and public documentation, and from other users who submit corrections. Where we obtain personal data about an individual from public sources rather than from that individual (GDPR Article 14), that person can ask us to correct or delete it using the contacts in this policy.
Required and optional data
On our forms, required fields are marked. We ask only for what we need to act on your request — for example, a name and work email so we can reply, and the details of the change you are asking for. If you do not provide required fields, we may be unable to handle your request. Optional fields (such as a LinkedIn URL) help us verify or respond faster but are not mandatory.
Recipients and processors
We share personal data only with the categories of recipient below, and only as needed:
| Recipient | Role | Data |
|---|---|---|
| To be confirmed | Website hosting / static file delivery and server request logs | IP address, request timestamps, requested URLs, user agent, referrer and error records contained in routine server logs. |
| To be confirmed | Email delivery and mailbox hosting for enquiry/submission correspondence | Any information contained in emails sent to FintechMall (e.g. contact enquiries, provider submissions, correction/update requests), including name, work email, company and message. |
| To be confirmed | Professional advisers (legal, accounting) engaged as needed | Only the personal data necessary to obtain advice or handle a dispute. |
| To be confirmed | Public authorities, regulators or courts, where legally required | Only what a valid legal obligation or lawful request requires. |
| To be confirmed | A provider selected for a requested introduction | Only the contact and project details necessary to make the introduction the user requested or authorised. |
We do not list vendors we do not use. We do not currently use analytics, advertising or error-monitoring services. Some specific vendors (for example the hosting and email providers) are being finalised and will be named here once confirmed.
Provider introductions
When you ask us to introduce you to a provider, we share the relevant contact and project details with the provider(s) you selected or authorised, so they can respond. We do not send the same enquiry indiscriminately to many providers.
International transfers
We aim to keep personal data within the European Economic Area (EEA). Some recipients or the providers you ask to be introduced to may be located outside the EEA. Where a transfer outside the EEA occurs, we rely on an appropriate safeguard — an adequacy decision, EU Standard Contractual Clauses, or another lawful transfer mechanism. Because the hosting and email vendors are still being finalised, the exact locations and safeguards will be confirmed in this policy once those vendors are set.
Retention
We keep personal data only as long as we need it. Our default periods are:
| Data | Retention |
|---|---|
| General enquiries and introduction requests | Up to 24 months after the last substantive interaction. |
| Listing submissions (contact data) | Up to 24 months after the submission is closed. Published, non-personal company information may remain while relevant. |
| Profile-update and correction requests | Requester and verification records up to 24 months after resolution. |
| Rejected logo uploads | Deleted within 30 days of the decision, unless needed for a dispute. |
| Accepted logos | Kept while displayed; removed from active storage after withdrawal or replacement, subject to limited backup retention. |
| Routine security logs | Normally no more than 90 days, unless needed for an incident, abuse investigation or legal claim. |
| Legal-claim records | For the applicable limitation period. |
| Consent preferences | Until withdrawn, invalidated by a policy/version change, or re-requested. |
Your rights
Subject to conditions in the law, you can ask to:
- access your personal data;
- rectify inaccurate data;
- erase data;
- restrict processing;
- object to processing based on legitimate interests;
- receive certain data in a portable format;
- withdraw consent, where processing is based on consent; and
- complain to a supervisory authority.
You can complain to the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) in Lithuania (https://vdai.lrv.lt/en/), or to the supervisory authority in your country of residence or work.
These rights are not absolute, and we may need to verify your identity before acting. To exercise a right, email privacy@fintechmall.com.
Automated decisions
We do not make decisions producing legal or similarly significant effects about you by automated means. Search sorting and spam filtering do not have such effects.
Children
FintechMall is a professional service that is not directed to children, and we do not knowingly solicit personal data from children.
Security
We apply proportionate organisational and technical measures to protect personal data — including access controls, transport encryption (HTTPS) and input validation. No service can be completely secure, and we do not promise absolute security.
Data breaches
If a personal-data breach occurs, we will assess it and notify the relevant supervisory authority and affected individuals where the law requires. We do not promise notification for every incident, only where legally required.
Changes to this policy
We may update this policy. The effective date at the top shows the current version, and we keep a record of material changes. We will not change the effective date dynamically on each visit.