Privacy statement
This privacy statement describes how Fynorvexa BV, established at Sint-Goriksplein 14, 1000 Brussels, processes personal data in connection with the crowdlending platform fynorvexa.com. We comply with the General Data Protection Regulation (GDPR), the Belgian Act of 30 July 2018 and the European Crowdfunding Regulation (EU) 2020/1503.
1. Who is the data controller
The data controller is Fynorvexa BV, KBO 0788.452.319. Our data protection officer can be reached at dpo@fynorvexa.com.
2. What data we process
Identification data (national register number, eID scan), financial data (IBAN, tax residence), KYC and AML data, contact details, technical data (IP, device, session time) and — only with your consent — analytics and marketing data through Google Consent Mode v2.
3. Purposes and legal basis
We process your data to manage your investor profile (contract performance), to meet KYC, AML and MiFID obligations (legal duty), to secure our platforms (legitimate interest) and to inform you about relevant projects (consent, which is revocable).
4. Retention periods
KYC files are kept for ten years after the end of the relationship in line with anti-money-laundering law. Log files are kept for eighteen months. Marketing preferences are kept until you withdraw your consent.
5. Recipients and transfers
We share data with our Belgian escrow bank, the Belgian tax authority (annual tax statement), our KYC vendor (located in the EEA) and Google Ireland Limited for Ads/GA4 if you provide consent. No transfer outside the EEA takes place without appropriate safeguards.
6. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection. You can withdraw consent for analytics and marketing at any time via 'Cookie settings'. Complaints can be filed with the Belgian Data Protection Authority (Drukpersstraat 35, 1000 Brussels).
7. Automated decision-making
Our risk grade (A–D) is partly computed automatically, but every decision to publish a project is finally validated by a Belgian analyst.
8. Security
We apply technical and organisational measures (TLS 1.3, AES-256 at rest, ISO 27001-aligned processes) to protect your data against unauthorised access or loss.
9. Changes
This statement may be updated. Material changes are announced by e-mail at least thirty days in advance. The applicable version is always available on this page.