Privacy Policy

    Effective date: February 1, 2026

    This Privacy Policy explains how SAHL FINTECH SARL (commercial name: Sahl Financial) ("Sahl", "we", "us") collects, uses, shares, and protects Personal Data when you visit our website, use our Services, or interact with us. We build Open Banking infrastructure in a way that prioritizes consent, transparency, minimization, and security. If you have questions or requests, contact contact@sahlfinancial.com.

    1) Roles: Controller vs Processor

    Depending on context: For our website, marketing, and direct communications, Sahl generally acts as a data controller. For many enterprise integrations, Sahl acts as a data processor processing Personal Data on documented instructions from the Customer (the controller). Where needed, the applicable Enterprise Agreement and/or Data Processing Addendum governs processor obligations.

    2) Personal Data We Collect

    We may collect the following categories depending on how you use the Services: (A) Website and Communications: Identity and contact data (name, email, phone, company, role/title); Communications content (messages, requests, feedback); Technical data (IP address, device identifiers, browser type, pages visited, timestamps); Preference data (language, settings, marketing preferences). (B) Platform and Product Usage Data: Account identifiers (user IDs, organization IDs); Authentication and session data (login events, device/session metadata); Usage data (features used, API calls, performance diagnostics); Support-related data (tickets, error logs provided by you). (C) Open Banking / Financial Data (Where Authorized): Account metadata (institution, account type, masked identifiers); Balances and transaction history (time range limited to the approved scope); Identity/verification-related data (where relevant to onboarding/KYC flows); Derived data and insights (e.g., categorizations, summaries, affordability indicators) where contractually authorized. We do not intentionally collect sensitive categories unless required for a lawful use-case and protected by appropriate safeguards.

    3) How We Collect Data

    We collect data: directly from you (forms, onboarding, support); from your organization (if you are an admin/user under a Customer account); from financial institutions or their interfaces where you explicitly authorize access; from service providers that support infrastructure (e.g., hosting, monitoring). How we collect account data: Where you authorize access, we collect account data directly from financial institutions or their interfaces using secure methods appropriate to the available connectivity. We collect only the data needed for the stated purpose, keep access auditable, and apply retention rules described in this Trust Center and/or the applicable contract.

    4) Purposes of Processing

    We use Personal Data to: provide, operate, and maintain the Services; enable authorized connectivity and deliver requested outputs/features; authenticate users and prevent fraud, abuse, and security threats; provide customer support and troubleshoot issues; improve product performance and reliability (limited and proportionate); comply with legal obligations and enforce agreements; communicate service updates, security notices, and administrative messages; send marketing communications where permitted (with opt-out and consent where required). We do not sell Personal Data.

    5) Legal Bases (GDPR-Style Principle Mapping)

    Depending on context and jurisdiction, processing may be based on: performance of a contract (providing the Services); legitimate interests (security, fraud prevention, service improvement); compliance with legal obligations; consent (e.g., certain marketing and certain data-access flows where required). Where Moroccan CNDP Law 09-08 applies, processing follows applicable CNDP requirements, declarations, and transfer governance, and is carried out for declared/authorized purposes.

    6) Sharing and Disclosure

    We may share Personal Data with: Sub-processors (hosting, monitoring, communications) under contract and confidentiality; Customers/partners where necessary to provide the Services and as instructed (processor context); Professional advisers (legal, audit) under confidentiality; Authorities where required by law or to protect rights, safety, and security. We limit sharing to what is necessary and consistent with the purpose.

    7) International Transfers

    Where Personal Data is transferred across borders, we implement safeguards appropriate to the jurisdiction and risk, such as contractual protections, access controls, encryption in transit, and vendor governance. Where transfers from Morocco apply, we follow CNDP transfer governance and associated formalities.

    8) Security

    We implement technical and organizational measures designed to protect Personal Data, including access controls, least privilege, encryption in transit, monitoring, secure development practices, and incident response procedures. No system is 100% secure, but we work continuously to reduce risk and improve controls.

    9) Retention

    We retain Personal Data only as long as necessary for the purposes described above, including legal, compliance, and security needs. Retention periods may vary by: data type; product configuration; partner/customer requirements; and applicable law. Where feasible, we delete or anonymize data when it is no longer needed.

    10) Your Rights

    Subject to applicable law, you may have rights to: access your Personal Data; rectify inaccurate data; object/oppose certain processing; request deletion where applicable; withdraw consent where processing is based on consent; receive information about processing and transfers. If Sahl is acting as a processor, we will route your request to the relevant controller (our Customer) and assist as required. To exercise rights: contact@sahlfinancial.com (we may verify identity before fulfilling requests).

    11) Cookies and Similar Technologies

    We use cookies and similar technologies for essential website functions and, where enabled, analytics. You can manage cookies via browser settings. Disabling certain cookies may impact functionality.

    12) Marketing Preferences

    You can opt out of marketing messages at any time via the unsubscribe link or by contacting us. Service/administrative messages (e.g., security notices) may still be sent where necessary.

    13) Automated Decision-Making

    Sahl may generate summaries or indicators as part of the Services. Customers are responsible for how they use outputs in decision-making and for meeting legal requirements applicable to automated decisions in their jurisdiction.

    14) Children

    The Services are not directed to children. We do not knowingly collect Personal Data from children without appropriate authorization.

    15) Changes to This Privacy Policy

    We may update this Privacy Policy from time to time. We will post the updated version with a new effective date.

    16) Contact

    Privacy requests and questions: contact@sahlfinancial.com

    We value your privacy

    We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking 'Accept All', you consent to our use of cookies. Learn more