Privacy Notice (GDPR)
Monerise — Privacy-First Personal Finance For Users in the European Economic Area and United Kingdom
Effective date: July 31, 2026 Last updated: July 31, 2026
1. Introduction
ICI Tech Teknoloji A.Ş. processes your personal data in compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and, where applicable, the UK GDPR.
Monerise is not a bank, broker, payment service provider, tax advisor, or investment product. It does not transfer money, connect to bank accounts, or provide financial advice.
| Data Controller | ICI Tech Teknoloji A.Ş. |
| Website | https://monerise.app/ |
| app@icitech.com.tr | |
| Country of establishment | Republic of Turkey |
EU Representative (Article 27 GDPR): We are in the process of designating an EU representative per Article 27 GDPR. Updated details will be published at https://monerise.app/en/privacy once appointed.
Data Protection Officer: We do not currently meet the mandatory DPO threshold under Article 37 GDPR. Contact: app@icitech.com.tr.
2. Financial Data and Privacy Architecture
Financial data — income, expenses, balances, and budgets — is among the most sensitive categories of personal information. While financial data does not automatically qualify as special category data under GDPR Article 9, we treat it with the highest level of care.
Monerise's core design principle is that financial data stays on your device. We process server-side data only when you voluntarily enable cloud features. For most users in most scenarios, the only data we hold is an optional account credential and purchase receipt.
3. Data Flows — GDPR Clarity
| Data Type | GDPR Role | Legal Basis | Where processed |
|---|---|---|---|
| Account credentials (optional) | Controller | Art. 6(1)(b) | Our servers |
| Financial tracking data | Controller | Art. 6(1)(b) | Device only (default) / Our servers (if cloud enabled) |
| Exchange rate requests | Controller | Art. 6(1)(f) | Rate provider (no personal data sent) |
| Cloud backup data | Controller | Art. 6(1)(b) | Our servers (encrypted) |
| Purchase receipt | Controller | Art. 6(1)(b) | Apple / Google |
| Crash logs (anonymized) | Controller | Art. 6(1)(f) | Our servers |
4. Legal Bases (GDPR)
| Purpose | GDPR Legal Basis |
|---|---|
| Optional account creation | Art. 6(1)(b) — Performance of contract |
| Core tracking features (device-local) | Art. 6(1)(b) — Performance of contract |
| Exchange rate fetch (optional) | Art. 6(1)(f) — Legitimate interests |
| Optional cloud backup | Art. 6(1)(b) — Performance of contract |
| Crash analysis | Art. 6(1)(f) — Legitimate interests |
| Purchase verification | Art. 6(1)(b) — Performance of contract |
| Legal obligations | Art. 6(1)(c) — Legal obligation |
| Marketing | Art. 6(1)(a) — Consent |
Legitimate interests: For crash analysis and exchange rate requests, we have balanced our interests against your rights. You may object at any time.
5. What We Do Not Do
We do not sell financial data. We do not share financial data with advertising networks. We do not connect to bank accounts. We do not use financial data to profile users for advertising. We do not use advertising identifiers (IDFA/GAID). We do not use AI to analyze your financial data on our servers. We do not make automated decisions with legal or significantly significant effects based on your financial data (Art. 22 GDPR).
6. International Data Transfers
ICI Tech Teknoloji A.Ş. is established in Turkey. No adequacy decision exists for Turkey under GDPR Article 45. For EEA/UK transfers of cloud backup data, we rely on Standard Contractual Clauses (SCCs) and UK IDTAs where applicable. Exchange rate API requests carry no personal data — no transfer safeguards are needed for that call.
7. Your Rights Under GDPR
Right of access (Art. 15): Request a copy of data we hold about you — most financial data is on your device only.
Right to rectification (Art. 16): Correct data in-app or contact us.
Right to erasure (Art. 17): Delete financial data in-app; delete account via Settings → Account → Delete Account.
Right to restriction (Art. 18): Disable cloud backup in Settings to restrict server-side processing.
Right to data portability (Art. 20): Export your data in-app (Settings → Export).
Right to object (Art. 21): Object to legitimate interest processing — contact app@icitech.com.tr.
Right to withdraw consent (Art. 7(3)): Withdraw marketing consent in Settings → Privacy → Marketing Preferences.
Right not to be subject to automated decisions with significant effects (Art. 22): We do not make such decisions.
Right to lodge a complaint (Art. 77): Contact your national supervisory authority.
Email app@icitech.com.tr — subject "GDPR Data Subject Request — Monerise". Response within one month.
8. Right to Lodge a Complaint
| Country | Authority | Website |
|---|---|---|
| 🇫🇷 France | CNIL | https://www.cnil.fr |
| 🇩🇪 Germany | BfDI + state DPAs | https://www.bfdi.bund.de |
| 🇪🇸 Spain | AEPD | https://www.aepd.es |
| 🇬🇧 United Kingdom | ICO | https://ico.org.uk |
| Other EEA | Your national DPA | https://edpb.europa.eu/about-edpb/about-edpb/members_en |
9. Data Retention
Device-local financial data: retained until you delete it or uninstall the app. Cloud backup data: duration of account plus 30 days after deletion. Purchase records: 10 years (Turkish commercial law). Crash logs: 12 months. Support communications: 3 years.
10. Security
AES-256 encryption at rest on device. TLS 1.2+ for network calls. Cloud backup encrypted in transit and at rest. Breach notification: Supervisory authority within 72 hours (Art. 33); users notified without undue delay for high-risk breaches (Art. 34).
11. Children's Privacy
Monerise is for users 18 and older. Contact app@icitech.com.tr for immediate deletion if a child has submitted data.
12. Changes
Material changes notified 14 days in advance. Current version: https://monerise.app/en/privacy/gdpr.
13. Contact Us
Email: app@icitech.com.tr Subject: "GDPR Data Subject Request — Monerise" Website: https://monerise.app/
Acknowledge within 5 business days, resolve within one month.