Refresh

This website www.exirio.com/privacy-policy/ is currently offline. Cloudflare's Always Online™ shows a snapshot of this web page from the Internet Archive's Wayback Machine. To check for the live version, click Refresh.

Privacy Policy

Effective date: July 1, 2025

Our commitment to your privacy

The privacy and security of your data is our highest priority. In this Privacy Policy, we lay out what data we collect and why, how your data is handled and protected, and how you have full control over it. Our guiding principles are:

  • We only collect the data we absolutely need to provide our service.
  • We believe you should always be in control of your own data.

This policy applies to all services provided by Exirio LLC.

  1. Data Controller

For the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, the entity responsible for your data is: Exirio LLC, 8 The Green, Dover, Delaware 19901, USA.

As the provider of the service, we act as the Data Controller for your personal data.

  1. What personal data we collect and why

We collect the following information to provide our services to you:

  • Identity: When you sign up for Exirio, we collect your name and email address. We use this to create and secure your account, personalize your experience, and send you essential service updates.
  • Financial data (processed via our aggregation partners, or uploaded manually by you): To provide our wealth tracking service, we process financial data retrieved on your behalf from your connected accounts. This is always done with your explicit consent and on a “read-only” basis. We cannot and will not ever be able to move money or execute transactions. The data includes:
    • Account metadata: Institution name, account name and type, account numbers (e.g., IBAN), and currency.
    • Account balances: Current and available balances.
    • Investment holdings: Ticker symbols, ISINs (if applicable), number of units for your securities (stocks, ETFs, funds) and Crypto.
    • Transaction history: Dates, amounts, and other details of past transactions.
  • Technical & usage data: We log access by IP address to protect your account from unauthorized access. We may also collect anonymous data about your interactions with our website and application (like browser version and pages visited) to help us improve our service and troubleshoot issues.
  • Voluntary correspondence: When you contact our support team, we keep a record of the correspondence to provide you with the best possible service.
  1. Data sharing and our service providers (Data Processors)

To provide our automated service, we use specialized, secure third-party providers (“Data Processors”) to handle the connection to your financial institutions. We have legally binding Data Processing Addendums (DPAs) with all our processors to ensure your data is protected.

Besides these core partners, we may use other processors for services like cloud hosting, customer support, and analytics. We will never share your data for any purpose other than providing and improving our service to you.

  1. Data security

We are committed to securing your data with industry-best practices. Please refer to Exirio’s Security Policy here

  1. Your rights under GDPR

At Exirio, we apply the same data rights to all our users, globally. You have the right to:

  • Know and access: Know what personal information is collected and access a copy of it.
  • Correction: Request correction of any inaccurate personal information.
  • Erasure (“Right to be forgotten”): Request that your personal information be erased from our systems. Fulfilling this request will result in the permanent closure of your account.
  • Complain: Make a complaint regarding our handling of your personal information with your local data protection authority.
  • Restrict processing: Request a restriction on how your personal information is used.
  • Object: Object to how your personal information is processed.
  • Portability: Receive your personal information in a simple, machine-readable format to transmit it to another party.

You can exercise many of these rights directly from within your Exirio account settings. For anything else, please contact our support team.

  1. Data retention & deletion

You are in full control. When you delete data or close your account, it is permanently removed from our active systems. This data may remain in our secure, encrypted backups for a limited period (typically a few weeks for disaster recovery purposes) before being permanently erased. We will only retain data beyond this period if required to do so by applicable law.

  1. Location of site and international data transfers

Exirio is a US-based company and our Services operate on a global infrastructure. Your information may be transferred to and stored in a jurisdiction different from your own. When your Personal Data is transferred out of the European Economic Area (EEA) to countries like the United States, we ensure it receives a similar degree of protection by implementing legal safeguards such as the Standard Contractual Clauses (SCCs) approved by the European Commission.

  1. Changes & questions

We may update this Privacy Policy from time to time to comply with relevant regulations and reflect any new practices. The latest version will always be available on our website.

Have any questions, comments, or concerns? Please send us an email at: [email protected]