Privacy Policy
Last Updated: July 2026
Finstead ("the App") is a mobile application owned and operated by TECHKNOCK LIMITED ("we," "us," or "our"), a company registered in England and Wales under Company Number 14107787, with its registered office at 215A 650 Avebury Boulevard, Milton Keynes, MK9 3FQ, United Kingdom. TECHKNOCK LIMITED is the data controller for the personal data described in this policy and is registered with the UK Information Commissioner's Office (ICO) under registration number ZC162243.
We are committed to protecting and respecting your privacy in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For any privacy question or request, contact us at info@techknock.co.uk.
1. Information We Collect
To provide automated personal financial analytics and suggestions, the App processes the following:
- Account data: your email address and the authentication details used to create and secure your account.
- Financial data from a connected bank account: if you choose to connect a bank account, we receive your account details (such as the account name, type, currency and balance) and your transaction history (typically up to 24 months), including transaction dates, amounts, descriptions, merchant names and category information. This data is refreshed when you ask the App to update, and we store a secure connection token so you do not have to reconnect each time.
- Financial data you upload: if you upload a bank or card statement (PDF or CSV), we process and store the information it contains, including transaction details, account balances and account identifiers such as your account number, sort code or IBAN, and the name of your bank or provider. The uploaded statement file itself is also stored securely while it is held in your account.
- Usage and technical data: diagnostic logs and technical information used to keep the App secure, stable and performant.
We never ask for, see, or store your online banking username or password. When you connect a bank account, you authenticate directly with your bank through our regulated Open Banking provider (see Section 3), and the connection gives us read-only access: nothing in the App can move, spend or touch your money.
2. Why We Process Your Data (Lawful Basis)
We process your data only to provide the App's features: securely storing your financial data, categorising and analysing your spending, and generating personalised insights, comparisons and suggestions.
Our lawful bases under UK GDPR are:
- Performance of a contract (Art. 6(1)(b)) — to deliver the service you sign up for; and
- Consent (Art. 6(1)(a)) — given when you choose to connect a bank account or upload a statement for analysis. You may withdraw consent at any time (see Section 5).
3. How Your Data Is Processed and Shared
- Bank connections are provided by Plaid. When you connect a bank account, the connection is made through Plaid, a specialist Open Banking provider. You authenticate with your bank directly; Plaid then supplies us with the account and transaction data described in Section 1. Plaid processes your data in accordance with its own End User Privacy Policy, available at plaid.com/legal.
- Service providers (sub-processors): We use a small number of trusted providers to host our infrastructure and to perform the automated analysis that powers the App. They act only on our instructions under contract, and are not permitted to use your data for their own purposes or to train their own publicly available models. A current list of our sub-processors is available on request at the email above.
- No sale of data: We do not sell your personal data, and we do not share it for third-party advertising.
4. Data Storage and International Transfers
Our primary databases and file storage are located within the UK / European Economic Area (EEA).
Some automated processing is carried out by specialist providers that may be located outside the UK and EEA, including in the United States. Where your data is transferred outside the UK/EEA, we put in place the safeguards required by UK GDPR — such as the ICO's International Data Transfer Agreement (IDTA) or Standard Contractual Clauses — so that your data remains protected to an equivalent standard.
5. Data Retention and Your Control
We keep your personal data only for as long as your account is active, or as needed to provide the service and meet our legal obligations.
- You can permanently delete your account and all associated data — your bank connections, transactions, uploaded statements, goals and insights — at any time from within the App, under More → Delete account. This removes your data, including any stored bank connection tokens, from our active production systems.
- You can end a bank connection at any time by deleting your account in the App or by contacting info@techknock.co.uk. You can also withdraw the access you granted through your own bank.
- You can request deletion by contacting info@techknock.co.uk; we will action verified requests and erase your data from active production systems within 30 days.
- You can withdraw your consent to processing at any time; if you do, we may no longer be able to provide some or all of the App's features.
6. Your Rights
Under UK GDPR you have the right to: access your data; have inaccurate data corrected; have your data erased; restrict or object to processing; and data portability (receive your data in a commonly used, machine-readable format). To exercise any of these rights, contact us at info@techknock.co.uk.
You also have the right to lodge a complaint with the ICO (ico.org.uk, or 0303 123 1113) if you are unhappy with how we handle your data.
7. Children
The App is not intended for anyone under 18, and we do not knowingly collect personal data from children.
8. Changes to This Policy
We may update this policy from time to time. Where changes are material we will notify you in the App or by email, and we will always update the "Last Updated" date above.