> ## Documentation Index
> Fetch the complete documentation index at: https://docs.financialdatapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How Financial Data API handles personal data.

# Financial Data API — Privacy Policy

*Last updated: 26 June 2026.*

This Privacy Policy explains how Financial Data API ("we", "us")
handles personal data in connection with the Financial Data API and related tools
(the "Service"). It covers the people who request access to and use the Service
("you"). For data-protection purposes, we act as the controller of the personal data
described here.

## 1. Data we collect

* **Account and contact data.** When you request an API key or contact us, we collect
  the name, email address, and any organization details you provide.
* **API key metadata.** We store a one-way hash of each API key (never the key itself in
  readable form), plus a short non-secret prefix and fingerprint used to identify the key,
  and its status and lifecycle timestamps.
* **Usage data.** For each request we record operational metadata such as the timestamp,
  endpoint, HTTP method, response status, latency, the associated client identifier, and
  the request IP address. This supports security, rate limiting, billing, and debugging.
* **Communications.** Records of your support and access correspondence with us.

We do not intentionally collect special-category personal data, and the market and macro
data served by the Service is not personal data about you.

## 2. How and why we use data

We use personal data to:

* provision and authenticate API access, and operate and secure the Service;
* enforce rate limits and the Acceptable Use Policy, and detect and prevent abuse;
* meter usage and administer billing;
* provide support and respond to your requests; and
* comply with legal obligations.

Where the GDPR or similar laws apply, our legal bases are: performance of a contract
(providing the Service you requested), our legitimate interests (securing, operating, and
improving the Service, and preventing abuse), and compliance with legal obligations.

## 3. Sub-processors and hosting

The Service runs on Amazon Web Services (AWS) in the EU (London, `eu-west-2` region),
which processes hosting and storage data on our behalf. We may use additional processors
for email delivery, payments, and error monitoring; a current list is available on
request. We require processors to protect personal data under terms consistent with this
policy.

## 4. International transfers

Where personal data is transferred outside your jurisdiction, we rely on an appropriate
transfer mechanism (such as standard contractual clauses) where required by law.

## 5. Retention

We retain account and key metadata for as long as your account is active and as needed to
provide the Service. We retain usage logs for 12 months for
security, billing, and operational purposes, after which they are deleted or aggregated.
We retain records longer only where required for legal or accounting reasons.

## 6. Security

We hash API keys, restrict access to operational data, redact secret-like fields and raw
provider payloads from operational event logs, and apply encryption and access controls on
our infrastructure. No method of transmission or storage is completely secure, and we
cannot guarantee absolute security.

## 7. Your rights

Subject to applicable law, you may request access to, correction of, export of, or
deletion of your personal data, and may object to or restrict certain processing. To
exercise these rights, contact us at [support@financialdatapi.com](mailto:support@financialdatapi.com); we will respond within the
timeframe required by law. You also have the right to lodge a complaint with your data
protection authority.

## 8. Data breaches

If a personal-data breach occurs that is likely to result in a risk to your rights, we
will notify the relevant supervisory authority and affected users where and within the
timeframes required by applicable law.

## 9. Children

The Service is not directed to children and is intended for business and developer use.
We do not knowingly collect personal data from children.

## 10. Changes and contact

We may update this policy; material changes will be notified by a reasonable means and
take effect on the stated date. Questions or requests: [support@financialdatapi.com](mailto:support@financialdatapi.com).
