Contents
- Article 1 - Definitions
- Article 2 - Regulatory framework
- Article 3 - The authorised provider
- Article 4 - Consent
- Article 5 - Banking credentials
- Article 6 - Categories of data retrieved
- Article 7 - Revocation of consent
- Article 8 - Accuracy and availability of data
- Article 9 - Roles and responsibilities
- Article 10 - Security
- Article 11 - Interruption of the aggregation service
- Article 12 - Complaints and remedies
- Article 13 - Amendments
The Noryo service (hereinafter the "Service") allows the User to connect their bank accounts in order to consult them and organise their finances. This connection is based on account aggregation, commonly referred to as "open banking", governed by the second Payment Services Directive, Directive (EU) 2015/2366 (PSD2), and its implementing texts. The purpose of this policy is to describe, in a complete and transparent manner, how this access operates, the role of each party involved, the data concerned and your rights.
Article 1 - Definitions
Definitions
- Aggregation provider
- the authorised account information service provider (AISP) providing technical access to the accounts.
- Account information service
- a service consisting of providing consolidated information on one or more accounts held by the User.
- Access consent
- the explicit authorisation given by the User for access to their accounts.
- Strong customer authentication (SCA)
- a customer authentication procedure based on at least two independent factors, required by PSD2.
- Account servicing provider
- the banking institution with which the User holds their accounts.
Article 2 - Regulatory framework
2.1 Principle
Access to payment accounts, at the User's request, constitutes an account information service subject to authorisation. This access is provided by an authorised provider, in compliance with the applicable requirements, in particular strong customer authentication and the security of exchanges.
2.2 Regulated nature
Aggregation is carried out within the limits set by the regulations: access is limited to information on payment accounts accessible online, to the exclusion of any payment initiation, and is subject to the User's consent.
Article 3 - The authorised provider
3.1 Identity
Aggregation is provided by The ID Co. Limited (trading under the atto.co brand), a company registered in Scotland under number SC400459, whose registered office is located at 83 Princes Street, Edinburgh, EH2 2ER, United Kingdom.
3.2 Authorisation
This provider is authorised by the Financial Conduct Authority under the Payment Services Regulations 2017, under reference number FRN 798579, in its capacity as an account information service provider, and is registered with the Open Banking Directory.
3.3 Role of Evorax Technologies
Evorax Technologies uses the services of this provider in order to present to the User their account information within the Service and to offer its financial organisation features.
3.4 Absence of its own authorisation
Evorax Technologies is not itself an account information service provider, nor a credit or payment institution, and does not present itself as such.
Article 4 - Consent
4.1 Collection
Access to accounts requires the User's explicit consent, collected by the provider through its secure interface, for each connection established.
4.2 Read-only
The consent covers access strictly limited to consultation. No payment transaction can be initiated by the Service or by the provider under this service.
4.3 Duration and renewal
In accordance with PSD2, consent is limited in time and must be renewed at most every ninety days. As the expiry date approaches, the User is invited to renew their consent in order to keep the data up to date.
4.4 Strong customer authentication
The establishment and renewal of the connection require strong customer authentication of the User with their account servicing provider, in accordance with the procedures defined by the latter.
Article 5 - Banking credentials
Online banking credentials are entered directly in the provider's or the bank's interface, by means of a secure redirection. They are never disclosed to Evorax Technologies, nor stored or retained by it. Evorax Technologies has access to no means of initiating a transaction on your accounts.
Article 6 - Categories of data retrieved
With the User's consent, the following are retrieved, for the sole purpose of feeding the financial organisation features of the Service:
- account information (account identifiers, IBAN, account type, currency);
- account balances;
- transaction history (date, amount, direction, label, counterparty where applicable);
- information relating to the account servicing institutions.
The processing of this data by Evorax Technologies is described in the Privacy Policy.
Article 7 - Revocation of consent
7.1 Procedures
The User may withdraw their consent and disconnect an account at any time, from the Service, with the provider or directly with their account servicing provider.
7.2 Effects
Revocation interrupts access to new data for the account concerned. Processing already carried out remains lawful. The data already retrieved is kept and deleted under the conditions provided for in the Privacy Policy.
Article 8 - Accuracy and availability of data
Banking information is provided by third parties, in particular your account servicing providers, and presented through the provider. It is not guaranteed to be accurate, complete, continuous or up to date. The availability of aggregation depends in particular on the interfaces made available by the banks, over which Evorax Technologies has no control.
Article 9 - Roles and responsibilities
As regards the shared account data, the provider and Evorax Technologies each act as a separate data controller, within the framework of a data sharing agreement determining their respective obligations. Each party is responsible for complying with its own obligations under the regulations applicable to data protection.
Article 10 - Security
Exchanges between the Service, the provider and the banks are secured and authenticated. The security measures implemented by Evorax Technologies are described in the Security Policy.
Article 11 - Interruption of the aggregation service
Aggregation may be temporarily unavailable, in particular in the event of maintenance, changes to banking interfaces or expiry of consent. Such unavailability does not affect access to data already presented and cannot, in itself, give rise to liability on the part of Evorax Technologies.
Article 12 - Complaints and remedies
Any complaint relating to the banking connection may be addressed to legal@noryo.app. Depending on the nature of the complaint, the User may also contact the authorised provider, their account servicing provider, or the competent authorities. The consumer User also has access to the mediation channels described in the General Terms and Conditions of Sale.
Article 13 - Amendments
This policy may be updated to take account of regulatory, technical or provider-related changes. The applicable version is the one in force at the time the Service is used.