Legal

Privacy Policy

Last updated: February 2026

Contents
Section 01

Introduction

Bibiis ("we", "us", or "our") is a personal finance management platform operated by NVP Tech Srls, a company registered in Italy. Bibiis provides account aggregation, budgeting, financial analytics, and AI-powered financial coaching services through our mobile application and web platform at bibiis.ch.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our services. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the revised Payment Services Directive (PSD2), and all applicable data protection laws.

By using Bibiis, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.

Section 02

Data Controller

The data controller responsible for your personal data is:

NVP Tech Srls
Email: privacy@bibiis.ch
Website: bibiis.ch

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at the email address above.

Section 03

Data We Collect

We collect and process the following categories of personal data:

3.1 Account Information

When you register for Bibiis, we collect:

3.2 Financial Data

When you connect your bank accounts through our open banking integration, we access:

Financial data is accessed through licensed Account Information Service Providers (AISPs) in compliance with PSD2 regulations. We only access your data with your explicit consent, and you can revoke access at any time.

3.3 Usage Data

We automatically collect certain technical and usage information:

3.4 AI Interaction Data

When you use our AI-powered financial coaching features, we process:

Section 04

How We Use Your Data

We process your personal data for the following purposes:

Section 06

Third-Party Service Providers

We work with carefully selected third-party providers to deliver our services. These providers process data on our behalf under strict contractual obligations:

6.1 Open Banking Providers

We use licensed Account Information Service Providers (AISPs) such as Tink and/or Salt Edge to securely connect to your bank accounts. These providers are regulated under PSD2 and access your financial data only with your explicit consent. They act as data processors and are contractually bound to process your data solely for the purpose of providing account information services to Bibiis.

6.2 Cloud Infrastructure

We use Supabase for our backend infrastructure, including database hosting and authentication services. Data is stored in secure, GDPR-compliant data centers within the European Economic Area (EEA).

6.3 AI Services

We use OpenAI to power our AI financial coaching features. When you interact with our AI assistant, relevant financial context may be sent to OpenAI's API to generate responses. We minimize the data shared and do not send full account credentials or sensitive authentication data. OpenAI processes this data as a data processor under our instructions and does not use it to train their models.

6.4 Analytics

We may use analytics services to understand how users interact with our platform. Any analytics data is aggregated and anonymized where possible.

Section 07

Data Sharing and Transfers

We do not sell, rent, or trade your personal data to third parties for marketing purposes.

We may share your data in the following limited circumstances:

Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or adequacy decisions.

Section 08

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:

You may request earlier deletion of your data at any time by contacting us at privacy@bibiis.ch.

Section 09

Data Security

We implement robust technical and organizational measures to protect your personal data, including encryption of data in transit (TLS/SSL) and at rest, secure authentication with hashed passwords and support for multi-factor authentication, regular security assessments and monitoring, access controls ensuring only authorized personnel can access personal data, and secure API communications with our banking and AI service providers.

While we take every reasonable precaution, no system is completely secure. We encourage you to use strong, unique passwords and to contact us immediately if you suspect unauthorized access to your account.

Section 10

Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

To exercise any of these rights, please contact us at privacy@bibiis.ch. We will respond to your request within 30 days.

You also have the right to lodge a complaint with your local data protection authority. In Italy, this is the Garante per la protezione dei dati personali.

Section 11

Open Banking and PSD2 Compliance

Bibiis accesses your bank account data through licensed AISPs regulated under the revised Payment Services Directive (PSD2). Key principles of our open banking practices:

Section 12

Cookies and Tracking Technologies

Our website (bibiis.ch) may use essential cookies to ensure proper functionality. We do not use advertising or tracking cookies. If we introduce non-essential cookies in the future, we will update this policy and obtain your consent before placing them.

Section 13

Children's Privacy

Bibiis is designed for users aged 18 and older. We do not knowingly collect personal data from children under 18. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.

Section 14

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable laws. We will notify you of material changes through the app or by email. The "Last updated" date at the top of this policy indicates when it was last revised.

We encourage you to review this Privacy Policy periodically.

Section 15

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

NVP Tech Srls
Email: privacy@bibiis.ch
Website: bibiis.ch