Catego
CategorizationOpen Banking
Categorization LoginAIS Portal
← Back to Home

Privacy Notice

SIA Catego, Reg. No. 40203507934, Ausekļa prospekts 18, Ogre, Latvia, LV-5001

This Privacy Notice explains how SIA Catego ("Catego") processes personal data when you use Catego's Account Information Service ("AIS") under Directive (EU) 2015/2366 ("PSD2").

1. Who We Are

SIA Catego is authorised to provide Account Information Services as a licensed Account Information Service Provider ("AISP") under PSD2 and applicable Latvian legislation.

Catego is supervised by Latvijas Banka. Licence No. 27-55/2026/2.

Catego processes personal data in different capacities depending on the particular processing activity.

For personal data processed by Catego on behalf of the business or organisation ("Client") you have selected in connection with the provision of the AIS, Catego acts as a Data Processor and the Client acts as the Data Controller.

Catego may also process certain personal data independently where necessary to comply with its own legal and regulatory obligations as a licensed AISP, including obligations relating to security, regulatory records, audit, prevention of misuse and demonstrating compliance with applicable law.

2. What Data We Process

2.1 Account and Transaction Data

Catego does not request or store your online banking passwords or personalised security credentials.

Authentication is performed directly with your ASPSP using its authentication procedures, including Strong Customer Authentication where required.

  • account holder information;
  • account identifiers, including IBAN;
  • account type and currency;
  • current and available balances;
  • transaction information, including amounts, dates, descriptions and counterparty details; and
  • additional information made available by your ASPSP through its PSD2 interface.

2.2 Consent and Authorisation Records

  • the scope of your authorisation;
  • the account(s) covered by the authorisation;
  • the date and time of authorisation;
  • expiration or revocation information;
  • records of AIS sessions and data access; and
  • information necessary to demonstrate compliance with PSD2 and applicable regulatory requirements.

2.3 Technical and Security Data

  • IP address;
  • device and browser information where available;
  • API request and response metadata;
  • error and performance information; and
  • access and security logs.

2.4 Scope of AIS Access

The specific account information accessed through the AIS, including the accounts covered, categories of data, transaction history period and duration of access, is determined by the service requested and the authorisation provided by you.

The applicable scope, purpose(s) and duration are displayed to you before you authorise access.

These parameters may vary depending on the business on whose behalf the AIS is provided.

3. Why We Process Your Data

We do not use AIS account and transaction data for advertising, profiling or marketing, and we do not use such data to make automated decisions about you for Catego's own purposes.

  • Providing the AIS: To retrieve the account information you have authorised and provide it to the Client you have selected.
  • PSD2 and regulatory compliance: To maintain records and evidence required by applicable payment services and regulatory requirements.
  • Security and prevention of misuse: To protect the AIS, detect and prevent unauthorised access, fraud, misuse and security incidents.
  • Service operation and support: To operate the AIS, investigate technical problems and provide support concerning the AIS.

4. Legal Bases for Processing

The applicable legal basis depends on the particular processing activity.

Where Catego processes personal data on behalf of the Client for provision of the AIS, the Client determines the purposes and applicable legal basis for that processing, and Catego processes the data in accordance with the Client's documented instructions and the applicable contractual arrangements.

  • to comply with a legal obligation applicable to Catego;
  • to pursue Catego's legitimate interests in maintaining secure and reliable AIS infrastructure, preventing misuse and protecting its services, where such interests are not overridden by your rights and freedoms; or
  • where otherwise permitted or required by applicable law.

Your PSD2 authorisation is required for Catego to access your payment account information. PSD2 authorisation is distinct from the legal basis for processing personal data under the GDPR.

5. How Long We Keep Your Data

Following the applicable retention period, AIS personal data is automatically deleted or anonymised.

Catego may retain information for longer where required by applicable law, regulatory requirements, security, audit or dispute-resolution requirements.

Consent, authorisation and regulatory records may be retained for the period required by applicable law or regulatory requirements.

  • for a one-time authorisation, the applicable retention period begins following completion of the retrieval;
  • for an ongoing authorisation, AIS data may be retained for the duration of the authorisation, with the applicable retention period beginning following its expiration or revocation;
  • the default retention period is 3 days; and
  • the Client may configure the retention period up to a maximum of 7 days.

6. Who Receives Your Data

  • The Client you selected: The Client receives the AIS data you have authorised to be retrieved. The Client is responsible for its own subsequent processing of that data, including its use for lending, creditworthiness assessment or other purposes.
  • Catego's service providers: Catego may use EEA-based IT, cloud hosting and other service providers to operate the AIS. Where such providers process personal data on Catego's behalf, they are subject to appropriate contractual and security requirements.
  • Authorities and supervisory bodies: Information may be disclosed where required by applicable law or requested by a competent authority or supervisory body.

Catego does not sell, rent or otherwise monetise your personal data.

7. International Transfers

Catego currently processes AIS data within the EEA.

If personal data is transferred outside the EEA in the future, Catego will ensure that the transfer is carried out in accordance with GDPR and that an appropriate legal transfer mechanism and safeguards are in place.

8. Security

Catego implements appropriate technical and organisational measures to protect personal data, including:

  • encryption in transit and at rest;
  • secure EEA-based cloud infrastructure;
  • access controls based on the principle of least privilege;
  • multi-factor authentication and role-based access controls;
  • logging and monitoring of access and security events; and
  • regular review and testing of security controls.

9. Your Rights

Depending on the particular processing activity and applicable legal basis, you may have rights under the GDPR including:

  • access to your personal data;
  • rectification of inaccurate data;
  • erasure;
  • restriction of processing;
  • objection to processing;
  • data portability; and
  • withdrawal of consent where processing is based on consent.

Where Catego processes personal data on behalf of the Client, requests concerning the Client's processing may need to be addressed to the Client as the Data Controller. You may contact Catego at: info@catego.app

10. Withdrawing AIS Authorisation

You may withdraw your AIS authorisation at any time through the relevant functionality provided by your ASPSP or, where applicable, through the AIS interface provided by Catego.

After withdrawal or expiration of an authorisation, Catego will stop further retrieval of account information under that authorisation.

Withdrawal of PSD2 authorisation does not necessarily require Catego or other parties to immediately delete records that must be retained under applicable law or regulatory requirements.

11. Complaints

If you have concerns about Catego's processing of your personal data or the provision of the AIS, please contact: complaints@catego.app

You may also lodge a complaint with the competent supervisory authority.

For data protection matters in Latvia: Datu valsts inspekcija www.dvi.gov.lv

12. Changes to This Privacy Notice

Catego may update this Privacy Notice where necessary to reflect changes in applicable law, regulatory requirements, the AIS or Catego's processing activities.

Where required, material changes will be communicated through appropriate means.

13. Contact Details

SIA Catego, Reg. No. 40203507934, Ausekļa prospekts 18, Ogre, Latvia, LV-5001. Email: info@catego.app

Catego

Banking Data Intelligence

LinkedIn
services
CategorizationOpen Banking
Legal
Privacy NoticeTerms of ServiceCookie PolicyComplaints
Client Portals
Categorization CabinetAIS PortalCategorization API DocsAIS API Docs

@ 2023-2026 SIA Catego. All rights reserved.

SIA Catego · Reg. No. 40203507934 · Ausekļa prospekts 18, Ogre, Latvia, LV-5001

Licensed AISP under PSD2 · Supervised by Latvijas Banka