Privacy policy

Talda — talda.app. Last updated 29 July 2026.

The short version

Who is responsible for your data

The controller is Roni Saroniemi, a private individual in Finland, who operates the service under the name Talda.

Talda is a service name, not a legal entity — no company has been formed, so the controller is the individual named above rather than a business. If a company is established later, it will be named here in his place.

Contact: privacy@talda.app. That address reaches the one person who runs the service.

There is no data protection officer. Talda is far below the size at which the GDPR requires one, and appointing a fictional one would tell you nothing useful.

What Talda does

Talda connects to bank accounts in Finland and the United Kingdom through Enable Banking, a provider licensed to offer account information services. It reads your accounts, balances and transactions, works out which transfers between members of your household are internal so that they are not counted twice, and shows the household the resulting picture.

It is read-only. Talda cannot move money.

Talda holds account information access only. There is no payment initiation capability anywhere in it — not in the code, not in the credentials, not in the licence it operates under. It cannot make a payment, move a transfer, set up a direct debit or touch a card.

This is worth stating plainly because it sets a ceiling on what can go wrong. If Talda were completely compromised, the harm would be that someone sees your financial data. It would not be that someone takes your money. That is a real difference and we would rather say it than let you assume the worse case.

What we collect

From your bank, through Enable Banking

From you

From the service itself

About other people in your transactions

Transactions name people who paid you, or whom you paid. Those people are not Talda's users and have not agreed to anything. We keep that information because it arrives as part of the transaction record and accounts cannot be reconciled without it — but we do nothing else with it. It is not profiled, not marketed to, not enriched, not sold, and not used to identify anyone.

Talda deliberately does not match transfers on counterparty names, because family members share surnames and doing so misclassifies genuine payments between relatives. Names are stored, not used as logic.

Why we process it, and the lawful basis

Retrieving and showing your accounts, balances and transactions

To provide the service you asked for.

Performance of a contract — GDPR Article 6(1)(b).

Reconciling transfers between household members

Without it the same money is counted twice and every total is wrong. It is the core of what Talda is for.

Performance of a contract — GDPR Article 6(1)(b).

Data about other parties in your transactions

Inseparable from the transaction record, and needed to identify internal transfers.

Legitimate interests — GDPR Article 6(1)(f), limited by the safeguards described above.

Emails about your account

Sign-in, verification, a warning before your bank consent expires, and notice when a sync fails. Nothing else — there is no newsletter and no marketing.

Performance of a contract — GDPR Article 6(1)(b).

Keeping the service secure and preventing abuse

Rate limiting, error logging, detecting misuse.

Legitimate interests — GDPR Article 6(1)(f).

Sensitive detail that transactions can reveal

A payment can disclose a religious donation, a political contribution, a trade union subscription or medical treatment. Talda does not look for this, does not categorise on it and draws no inferences from it — but it is stored, because it is part of the transaction text your bank sends.

Explicit consent — GDPR Article 9(2)(a). You may withdraw it at any time, which means asking us to delete your data.

Separately from all of the above, PSD2 requires your explicit consent for account information access, which you give at your own bank when you authorise the connection (Article 67(2)(a)). That consent is what permits your bank to release the data. It is a different thing from the GDPR lawful bases listed here, and it does not replace them.

We do not process your financial data for anything else. No analytics, no advertising, no profiling, no model training, no "product improvement", no scoring. Under PSD2 any further purpose would need your separate, freely given consent — and we are not asking for one, because we do not want to do any of it.

Who else handles your data

That is the complete list. There are no advertising networks, no analytics providers, no data brokers, no AI services and no other recipients. Your data is not sold, rented, licensed or shared for anyone else's purposes.

We would disclose data if we were legally compelled to. Nothing like that has happened.

What the operator can see

The person who runs Talda has administrative access to the systems and can therefore read the data stored in them, including yours. There is no technical barrier that prevents this.

We say so because it is true. It is true of nearly every small service; it is only embarrassing when it is concealed. In practice, that access is used for one thing — investigating something that is broken.

Where your data is stored, and for how long

Your data is stored on Cloudflare's infrastructure, in a database provisioned in the European Union. Cloudflare is a company established in the United States operating a global network, so some processing — handling your requests, and the network layer in front of them — may take place outside the EEA; those transfers rely on the standard contractual clauses in Cloudflare's data protection terms. Transactional email is handled by Resend in the EU.

We keep your data for as long as the household keeps using Talda. During this beta nothing is deleted automatically: if you stop using it, or your bank consent lapses and is not renewed, the data stays until you ask us to delete it.

If you ask us to delete it, we do so within one month, as the GDPR requires.

Backups deserve a straight answer rather than a comfortable one. They are encrypted, dated copies, and we do not edit one person's data out of an old archive — not because we would rather not, but because we could not verify having done it properly, and a deletion we cannot verify is not worth promising. What we do instead is carry the record of your deletion request inside every backup we take. A restore can therefore never bring your data back without also bringing back the instruction to delete it, and anything a restore does bring back is deleted again. Backups are not kept forever; how long they are kept is being fixed and will be stated here.

Ending the connection at your bank stops any new data arriving immediately. It does not by itself delete what is already stored — ask us and we will delete it.

Your bank consent, and how long it lasts

Access to your accounts exists only because you explicitly authorised it at your own bank. For the banks Talda currently supports, that consent lasts at most 180 days. When it expires, access stops until you log in at your bank again and renew it yourself.

Talda never sees, receives or stores your bank credentials. Every authorisation and renewal is done by you, directly with your bank, using your bank's own security. Talda cannot renew a consent on your behalf, and cannot recover access without you.

You can withdraw the consent at your bank at any time, without giving a reason.

Your rights

Under the GDPR you can ask us to:

Email privacy@talda.app. We will answer within one month. Exercising any of these rights is free and we will not make it difficult.

Complaints

If you think we have handled your data wrongly, please tell us first — it is the fastest way to fix it, and the supervisory authority normally expects you to have asked the controller and been refused before it takes up a case about your rights.

You can complain to the Finnish supervisory authority regardless:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
PO Box 800, 00531 Helsinki, Finland
tietosuoja@om.fi · +358 29 566 6700
tietosuoja.fi/en/home

If you live in another EU or EEA country, you may complain to your own national data protection authority instead.

Automated decisions

There are none. Talda matches transfers and adds up numbers. It does not score you, rank you, judge you, or make any decision about you that has legal or similarly significant effects. Suggested transfer matches that the system is not confident about are shown to you for review rather than applied silently.

Security

No system is perfectly secure and we are not going to claim otherwise. If data were ever exposed, we would tell the people affected and the supervisory authority as the GDPR requires.

Children

Talda is not intended for children and accounts are not offered to them.

Changes to this policy

If this policy changes, the date at the top changes with it. If a change actually affects you, we will email you rather than rely on you noticing.