Gegevensverwerking

Wat MyFina opslaat — en hoe het wordt verwijderd

Volledige per-feature matrix: entiteit, retentievenster, encryptiemethode, verwijderingsproces. Geen "enzovoort" — elke regel is verifieerbaar in de code.

Per-feature opslagmatrix

Deze pagina is een uitbreiding van het privacybeleid voor wie behoefte heeft aan concrete details. De AVG verplicht ons om datacategorieën en bewaartermijnen openbaar te maken; hier vindt u meer details dan de wet vereist, omdat we niets te verbergen hebben.

Per-feature opslagmatrix

EntiteitWat wordt opgeslagenBewaartermijnHoe wordt het verwijderdEncryptie
TransactionsAmount, currency, date, account, category, descriptionUntil account hard-delete or manual user removalCASCADE on user or account hard-deleteAt rest (DB), TLS in transit
AccountsName, type, currency, current balanceUntil manual user removalCASCADE removes linked transactionsAt rest, TLS
CategoriesName, type, icon, MCC codesUntil manual user removalCASCADE via user_idAt rest, TLS
Bank API tokensEncrypted token (Monobank Personal API, GoCardless consent)Until user revocation or PSD2 expiry (90 days)Disconnect in Settings → Banks = immediate removalAES-256-GCM (column-level), TLS
AI prompts (voice/receipt)Prompt text + Claude response (for usage log)30 days in `ai_usage_log`Cron cleanup after 30 days or admin manual purgeTLS in transit (Anthropic API); prompt removed from their infra per DPA
Audit logAction, target, IP, user-agent, source (web/mobile/cron)180 days (admin) / 30 days (user-level events)Cron prune after retention windowAt rest, TLS
Login attemptsIdentifier (masked in admin), IP, success/failure, timestamp30 days (for login throttling)Cron prune after 30 daysAt rest, TLS
Marketing leadsEmail, source, intent, IP, consent flagUntil admin processing or GDPR Art. 17 requestBest-effort erase-hook on account hard-delete by same emailAt rest, TLS
Push device tokens (FCM)FCM token, platform, locale, last-used timestampUntil unsubscribe or disabled_at (UNREGISTERED from FCM)CASCADE on user deletionAt rest, TLS
BackupsFull DB snapshot (encrypted)30-day rollingAutomatic removal per retention; manual purge availableAES-256 before upload to backup storage
Web analytics (site only)GTM container + GA4: anonymized IP, page, referrer. Clarity: heatmap clicks, masked DOM (no input text)GA4: 14 months (default). Clarity: 13 months. Reset — via cookie banner "Revoke consent".Cookie banner → "Essential only" stops collection immediately. On /legal/cookies the same toggle is persistent.TLS in transit; data processed by Google (GTM/GA4) and Microsoft (Clarity) per their DPAs

Uw AVG-rechten

Art. 15

Right of access

Request a full export of your data in Settings → Data. Returns CSV/XLSX/PDF with all transactions, accounts, and categories. For additional categories (audit log, bank tokens) — email support@my-fina.com.

Art. 17

Right to be forgotten

Hard-delete the account in Settings → Account → Delete account. Transactions, accounts, categories, currencies, tokens, push devices are cascade-removed. Marketing leads under the same email are also removed via best-effort hook.

Art. 20

Right to data portability

Export in Settings → Data formats data as CSV/XLSX (machine-readable). Structure is compatible with YNAB, Mint, and other ledger tools via a standard column set (date, account, category, amount, currency, note).

Hoe gebruikt u dit

  1. Open Instellingen → Gegevens (via het hoofdmenu).
  2. Kies een exportformaat: CSV (universeel), XLSX (Excel), PDF (afdrukken).
  3. Voor definitieve verwijdering — sectie "Account verwijderen" onderaan de pagina; vereist bevestiging met wachtwoord.
  4. Voor specifieke verzoeken over auditlog of bank-tokens — schrijf naar support@my-fina.com met als onderwerp "AVG art. 15".
← Terug naar BeveiligingLaatst bijgewerkt: 3 juni 2026