Privacy Policy - Fortiqo Org Digital Bank
*Last Updated: August 14, 2025*
1. Introduction
Fortiqo Org Digital Bank ("we," "us," or "our") is committed to protecting your financial privacy. This policy outlines how we collect, use, disclose, and safeguard your personal and financial information in compliance with global banking regulations including GDPR, CCPA, and GLBA. By using our services at https://fortiqo.org, you consent to the practices described herein.
2. Company Information
Legal Entity: Fortiqo Org Limited
Registered Address: [Your Legal Address Here]
Licensing: Regulated to operate by EBA, NCAs, FDIC, OCC, CFPB
Data Protection Officer: security@fortiqo.org
3. Information We Collect
We collect data necessary for banking operations and regulatory compliance:
- Personal Identification: Full name, government IDs, date of birth
- Financial Data: Account numbers, transaction history, credit scores
- Contact Details: Email, phone number, physical address
- Technical Information: IP addresses, device IDs, browsing activity
- Biometric Data: (Where applicable) for authentication
4. How We Collect Data
- Directly From You: Account applications, transaction processing
- Automated Technologies: Website cookies, mobile app analytics
- Third Parties: Credit bureaus, identity verification services, payment networks
- Public Sources: Sanctions lists, fraud databases
5. Legal Basis for Processing (GDPR Compliance)
We process your data based on:
- Performance of banking contracts
- Legal obligations (KYC/AML)
- Legitimate interests (fraud prevention)
- Your explicit consent (for marketing)
6. How We Use Your Information
| Purpose | Examples |
|---------|----------|
| Account Services | Processing transactions, loan underwriting |
| Security Measures | Fraud monitoring, identity verification |
| Legal Compliance | AML checks, tax reporting |
| Service Improvement | Product development, UX optimization |
| Marketing* | Personalized offers (opt-in required) |
7. Data Sharing & Disclosure
We may share information with:
- Regulatory authorities (as legally required)
- Payment processors (Visa/Mastercard networks)
- Credit reference agencies
- Fraud prevention agencies
- Service providers (under strict NDAs)
We never sell customer data to third parties.
8. International Data Transfers
Data may be transferred globally using GDPR-compliant mechanisms (Standard Contractual Clauses) with safeguards including:
- End-to-end encryption
- Limited access protocols
- Regular security audits
9. Data Retention
We retain information:
- 7 years post-account closure (regulatory requirement)
- 10 years for transaction records (tax compliance)
- Until consent withdrawal for marketing data
10. Your Rights
You have the right to:
- Access your personal data
- Request correction of inaccuracies
- Delete non-essential data ("Right to be Forgotten")
- Restrict processing
- Data portability
- Withdraw consent
- Lodge complaints with supervisory authorities
Exercise rights at: security@fortiqo.org
11. Security Measures
We implement:
- 256-bit SSL encryption
- Multi-factor authentication
- Regular penetration testing
- SOC 2 Type II certified infrastructure
- $500K fraud protection guarantee
12. Cookies Policy
We use:
- Essential Cookies: Session management
- Analytics Cookies: Service optimization (opt-out available)
- Marketing Cookies: Only with explicit consent
Manage preferences via our Cookie Consent Banner.
13. Policy Updates
Material changes will be:
- Communicated via email 30 days in advance
- Posted prominently on our website
- Archived at fortigo.org/privacy-archive
Breach reporting: security@fortiqo.org (24/7)