Privacy Policy

Effective date: 10 August 2026

This Privacy Policy explains how FinikPay Inc. ("Finik", "we", "us", "our") collects, uses, stores, discloses, and otherwise handles your personal information when you visit our website at https://finik.ai, when you create an account, and when you use our platform, products, and services, including our digital asset wallet, crypto exchange, card programs, and related services.

Finik is a money services business registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC). Because our services are subject to Canadian anti-money laundering, counter-terrorist financing, and financial services laws, the collection and use of certain personal information is necessary for us to provide our services and to meet our legal and regulatory obligations.

Please read this policy carefully. By visiting our website, creating an account, or using our services, you acknowledge that you have read and understood how we handle your personal information, and, where consent is the applicable legal basis, you consent to the practices described in this policy. If you do not agree with this policy, please do not use our website or services.

FinikPay Inc. is the data controller and, under Quebec law, the person responsible for personal information processed in connection with our services. Our registered address is Suite 548, 1235 Bay Street, Toronto, ON, Canada M5R 3K4.

We may update this policy from time to time to reflect changes in our services, technology, or legal obligations. When we make material changes, we will notify you in accordance with applicable law.

1. Who This Policy Applies To

1.1 Scope

1.1.1 This policy applies to all individuals who interact with Finik, including:

  • visitors to our website at https://finik.ai;
  • prospective clients who apply to open an account;
  • individual account holders;
  • directors, beneficial owners, and authorised representatives of business account holders; and
  • anyone who contacts us by email, phone, or through our support channels.

1.1.2 This policy covers personal information — that is, any information that identifies you or could be used to identify you, directly or indirectly.

1.2 Applicable Privacy Laws

1.2.1 We comply with the following privacy laws depending on where you are located:

  • Canada (outside Quebec): the Personal Information Protection and Electronic Documents Act (PIPEDA);
  • Quebec: An Act respecting the protection of personal information in the private sector (Law 25);
  • European Economic Area and United Kingdom residents: the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR, to the extent we offer services to, or monitor the behaviour of, individuals located in the EEA or the UK;

1.2.2 Where these laws give you different rights or impose different requirements on us, we apply the most protective standard that applies to your situation.

1.3 Two Contexts of Data Collection

1.3.1 We collect personal information in two distinct contexts. It is important to understand the difference:

(a) Website visitors — https://finik.ai

If you visit our website without creating an account, we collect only limited technical data. Specifically:

  • Cookies — strictly necessary cookies required for the website to function (session management, security). If you consent, we may also use functional and analytics cookies. See our Cookie Policy for the full list.
  • Contact form — if you submit an enquiry through our website contact form, we collect your name and email address for the sole purpose of responding to your message.

We do not collect your financial information, identity documents, or any other sensitive data simply because you visit the website. Website data is not used for AML screening, transaction monitoring, or regulatory reporting.

(b) Platform clients — account holders

If you create an account and use our services, we collect a significantly broader set of information as described in Section 2. This includes identity verification documents, financial information, transaction data, and other data required by Canadian AML law. This is a separate and more extensive data collection context.

1.3.2 The remainder of this policy covers both contexts. Where a provision applies only to platform clients or only to website visitors, we say so.

2. Information We Collect

2.1 Information You Give Us Directly — Platform Clients

2.1.1 When you apply to open a personal account, we collect:

  • Identity information — your full first name and last name, date of birth, nationality/citizenship, country of residence, and government-issued identity document details (document type, number, expiry date and issuing country, captured during identity verification);
  • Contact information — email address, phone number (with country code) and residential address;
  • Tax information — your tax identification number (TIN) and tax-residency / US Person status;
  • Financial information — your occupation, source of funds, and expected monthly transaction volume; where enhanced due diligence applies, source of wealth and supporting documentation such as bank statements or pay slips;
  • Product information — the products and services you select (e.g. wallet, exchange, cards, crypto-to-equities);
  • Verification materials — a copy or scan of your government-issued photo ID (passport, residence permit or driver's licence), a live biometric selfie with liveness check, and proof of address (e.g. utility bill or bank statement);
  • Declaration information — your PEP self-declaration and US Person declaration.

2.1.2 When you apply to open a business account, we additionally collect:

  • Company information — legal name, trading name, registration number, business tax identification number (e.g. Canadian Business Number), jurisdiction and date of incorporation, registered (legal) address and operational address, industry / nature of business, business activity description, website, and any regulated- or licensed-activity details;
  • Financial and activity information — expected annual revenue, estimated monthly turnover, number of employees, source of funds, products selected, countries of operation, and counterparty countries;
  • Ownership and control information — the company's shareholder register and ownership/control structure, and for each director, beneficial owner (25% or more) and shareholder: full name (or company name for corporate shareholders), date of birth, nationality or country of incorporation, country of residence or business address, residential or registered address, ownership percentage, email and phone;
  • Verification materials — corporate documents: certificate / articles of incorporation (or registry record), articles / by-laws (corporate charter), registry extract / corporate registry record, certificate of good standing / compliance, shareholder register / ownership structure / org chart, proof of business address, and the director / signing-authority government ID together with proof of authority (board resolution or power of attorney); a beneficial-ownership declaration confirming that the listed beneficial owners are complete and accurate; and individual identity verification (government photo ID, biometric selfie and liveness check) for the director / authorised representative and each beneficial owner;
  • Declaration information — PEP self-declarations for the representative, beneficial owners and shareholders, a US Person declaration, and a beneficial-ownership declaration.

2.1.3 When you use our services, we also collect:

  • Transaction data — details of every transaction you make through the platform, including transaction amounts and currencies, the type of digital or fiat asset involved, originating and destination wallet or account addresses, transaction hashes and identifiers, network or blockchain used, counterparty information where available, timestamps, geolocation or IP associated with the transaction, transaction status, and any fees applied;
  • Card program data (where you use our card products) — card number (in masked or tokenised form), card status, merchant and point-of-sale details, transaction amounts and currencies, authorisation and decline records, and related spending activity;
  • Account activity — login history, authentication and session data, device and browser information, IP addresses, language and locale settings, access times, pages and features used, and actions taken within the platform (such as initiating transfers, updating settings, or submitting requests);
  • Communications — messages, attachments, and information you send us through support channels, email, chat, or in-app messaging, including the content of your enquiries, records of our correspondence with you, and, where calls are recorded, call recordings and notes;
  • Verification and monitoring data generated through use — risk scores, flags, alerts, and screening results produced by our transaction-monitoring, sanctions, and fraud-prevention systems in connection with your activity; and
  • Preferences — notification and communication settings, marketing preferences, security settings, and other account preferences you configure.

2.1.4 When you complete identity verification — whether as an individual or as a director or beneficial owner of a business — we collect and process the following additional category of personal information:

Biometric and identity verification data — a live biometric selfie with a three-pose liveness check, captured through our identity verification provider. This data is used solely to confirm that the identity document you submitted belongs to you and that you are a real person present at the time of verification. It is not used for any other purpose, is not shared with third parties other than our identity verification provider, and is not retained beyond the period necessary to complete verification.

Biometric data constitutes a special category of personal information under applicable privacy laws, including GDPR Article 9 and Quebec Law 25. We process it on the following legal bases:

  • Legal obligation — identity verification including biometric liveness checks is required under Canadian AML regulations (PCMLTFA and PCMLTFR) to confirm client identity before opening an account;
  • Substantial public interest — prevention of financial crime, fraud, and identity theft (GDPR Art. 9(2)(g)); and
  • Explicit consent — where required by applicable law, we obtain your explicit consent before initiating the biometric check. You may withdraw consent at any time, but withdrawal will prevent us from completing verification and opening your account.

2.2 Information You Give Us Directly — Website Visitors

2.2.1 If you submit an enquiry through the contact form on our website, we collect:

  • your name; and
  • your email address.

We use this information solely to respond to your enquiry. We do not use it for marketing purposes without your separate consent, and we do not add it to our client database unless you subsequently open an account.

2.3 Information We Collect Automatically

2.3.1 When you visit our website or use our platform, we automatically collect certain technical information:

  • Device information — device type, operating system and version, browser type and version;
  • Network information — IP address and approximate location derived from your IP address (country and region). IP addresses are logged in our server infrastructure and retained for 30 days;
  • Usage data — pages and screens visited, features used, time and date of access, and error logs and diagnostic data;
  • Authentication and security data — login attempts and history, session identifiers, and signals used for fraud prevention and detection of unauthorised activity; and
  • Cookies and similar technologies — see Section 10 for a summary and our full Cookie Policy.

2.3.2 This automatic collection applies to both website visitors and platform clients. For website visitors, the data collected is limited to the technical information listed above. For platform clients, this data is also used for fraud detection, security monitoring, and platform improvement.

2.3.3 You are responsible for ensuring that the personal information you provide to us is accurate and kept up to date. You can update your information at any time by contacting us at privacy@finik.ai or, where available, through your account settings.

2.4 Information About Other Individuals

2.4.1 In the course of our business relationship, you may provide us with personal information about other individuals — for example, directors, beneficial owners, and authorised representatives of your business. We process this information only for the purposes described in this policy and on a lawful basis.

2.4.2 Where required by applicable law, we will notify those individuals about how we process their personal information. By providing us with information about other individuals, you confirm that you are authorised to do so and that those individuals have been informed of, or will be informed of, this Privacy Policy.

2.5 Information We Receive From Third Parties

2.5.1 We receive information about you from our service providers and other third parties, including:

  • Identity verification results — the outcome of document authenticity checks, biometric matching, and liveness detection performed by our identity verification provider;
  • Screening results — PEP status, sanctions matches, and adverse media findings from our screening providers;
  • On-chain data — risk scores and risk indicators associated with wallet addresses and transactions, from our on-chain analytics provider; and
  • Travel Rule data — originator and beneficiary information transmitted to us by other virtual asset service providers in connection with incoming virtual currency transfers.

3. Why We Collect Your Information

3.1 Legal Basis for Processing

3.1.1 We process your personal information on the following legal bases:

(a) Performance of a contract — we need your information to open your account, verify your identity, and deliver the services you've signed up for. Without this information, we cannot provide our services.

(b) Legal obligation — we are required by law to collect, process, and in some cases share certain information. This includes our obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), the Retail Payment Activities Act (RPAA), sanctions legislation, and tax reporting requirements. We cannot opt out of these obligations.

(c) Legitimate interests — we process some information to pursue our legitimate business interests, where these are not overridden by your privacy interests. This includes fraud prevention, platform security, improving our services, and maintaining the integrity of the platform. Where we rely on this basis, you have the right to object — see Section 8.

(d) Consent — where required by law, we ask for your explicit consent before processing your information. In particular, Quebec residents consent to the transfer of their personal information outside Quebec by accepting our Terms of Service. You can withdraw consent at any time, but this may affect our ability to provide services to you.

3.2 Purposes of Processing

3.2.1 We use your personal information for the following purposes:

PurposeLegal basis
Opening and managing your accountContract
Verifying your identity (KYC/KYB)Legal obligation, Contract
Screening for sanctions, PEPs, and adverse mediaLegal obligation
On-chain AML monitoring and transaction screeningLegal obligation
Filing regulatory reports with FINTRACLegal obligation
Applying and complying with the Travel RuleLegal obligation
Detecting and preventing fraud and financial crimeLegal obligation, Legitimate interests
Delivering and improving our servicesContract, Legitimate interests
Communicating with you about your accountContract
Responding to your support requests and website enquiriesContract, Legitimate interests
Complying with court orders and regulatory requestsLegal obligation
Conducting periodic KYC refresh and re-verificationLegal obligation
Maintaining security of the platform and websiteLegitimate interests
Analysing platform and website usage to improve featuresLegitimate interests
Training and improving automated and machine-learning modelsLegitimate interests

4. Who We Share Your Information With

4.1 Our Service Providers

4.1.1 We share your personal information with third-party service providers who help us operate our business and deliver our services. These providers process your information only on our instructions and are bound by contractual confidentiality and data protection obligations.

4.1.2 Categories of service providers we use include:

  • Identity verification providers — who conduct document checks, biometric verification, and liveness detection during onboarding and re-verification;
  • Sanctions and screening providers — who screen clients and transactions against PEP databases, sanctions lists, and adverse media sources;
  • On-chain analytics providers — who assess the risk profile of wallet addresses and crypto transactions;
  • Travel Rule compliance providers — who facilitate the collection and transmission of originator and beneficiary data for qualifying transfers;
  • Card program partners — who issue and manage your Visa card under their Visa Principal Membership;
  • Digital asset custodians — who hold the private keys to wallets containing your crypto assets;
  • Cloud infrastructure providers — who host our platform and store our data;
  • Email and communications providers — who deliver transactional emails and notifications;
  • Group companies and affiliates — including our group of companies, for internal administration, compliance oversight, and shared services, subject to appropriate data transfer safeguards; and
  • Professional advisers — lawyers, auditors, accountants, and consultants who advise us on legal, regulatory, or business matters and are bound by confidentiality obligations.

4.1.3 Details of our current data processors — including their locations and the categories of data we share with them — are available on request to our Privacy Officer at privacy@finik.ai. We will notify you of any material changes in accordance with applicable law.

4.2 Regulatory and Law Enforcement Authorities

4.2.1 We are legally required or permitted to share your information with:

  • FINTRAC — for suspicious transaction reports, large virtual currency transaction reports, electronic funds transfer reports, terrorist property reports, and other reports required under the PCMLTFA;
  • Global Affairs Canada, the RCMP, and CSIS — in connection with sanctions compliance and terrorist financing;
  • Canada Revenue Agency — for tax reporting purposes;
  • Bank of Canada — in our capacity as a registered Payment Service Provider under the RPAA;
  • Courts and tribunals — in response to valid court orders or legal process; and
  • Law enforcement and other regulatory authorities — where required or permitted by applicable law.

4.2.2 Where the law permits, we will notify you before complying with such a request. In many cases — particularly in connection with FINTRAC reporting or sanctions matters — we are legally prohibited from telling you that we have shared information about you or your transactions.

4.3 Other Financial Institutions

4.3.1 Where permitted by applicable law and consistent with recognised financial crime information-sharing frameworks, we may share information about suspicious activity with other regulated financial institutions for the purpose of preventing and detecting financial crime.

4.4 Business Transfers

4.4.1 If Finik is involved in a merger, acquisition, reorganisation, or sale of all or substantially all of its business, your personal information may be transferred to the acquiring entity as part of that transaction. We will notify you of any such transfer and of any material changes to how your information is handled as a result.

4.5 What We Don't Do

4.5.1 We do not sell your personal information to third parties. We do not share your personal information for third-party marketing purposes without your explicit consent.

5. International Data Transfers

5.1 Where Your Data Goes

5.1.1 Your personal information is stored in Canada (see Section 7.1.2). Some of our service providers operate from, and may process your personal information in, other countries — currently Canada, the United States, the Netherlands, Switzerland. Where your personal information is processed outside your country of residence, we put in place the appropriate safeguards described below.

5.2 Transfers Outside Canada

5.2.1 Where we transfer personal information to a service provider located outside Canada, we remain accountable for that information. We require each such provider, by written contract, to protect your personal information to a standard comparable to the protection it would receive under this policy and applicable Canadian law, and to process it only on our instructions and for the purposes we specify. Before transferring personal information outside Québec, we conduct a privacy impact assessment as required by Law 25.

5.2.2 You can request a copy of the relevant transfer mechanism by contacting our Privacy Officer at privacy@finik.ai.

5.3 Transfers From Quebec

5.3.1 Where we transfer personal information outside Quebec, we conduct a privacy impact assessment (analyse d'impact relative à la vie privée) before doing so, as required by Law 25. By accepting our Terms of Service, you consent to the transfer of your personal information to the countries listed in Section 5.1 for the purposes described in this policy.

6. How Long We Keep Your Information

6.1 Retention Periods

6.1.1 We keep your personal information for as long as we need it to provide our services and to meet our legal obligations. The main retention periods that apply are:

CategoryRetention periodReason
KYC / identity verification records5 years from end of client relationshipPCMLTFA
Transaction records5 years from date of transactionPCMLTFA
FINTRAC reports5 years from date of filingPCMLTFA
Account information5 years from account closurePCMLTFA, RPAA
Communications and support records5 years from end of relationshipLegal obligation, Legitimate interests
Compliance and risk assessment records5 years from end of relationshipPCMLTFA, RPAA
Tax records7 yearsIncome Tax Act (Canada)
Website contact form data12 months from last contactLegitimate interests
Website usage and cookie data13 monthsLegitimate interests

6.1.2 The criteria we use to determine retention periods include:

  • the type of personal information and the purpose for which it was collected;
  • whether we are subject to a legal or regulatory obligation to keep the data — such as financial reporting, AML/CTF, or record-keeping requirements;
  • the limitation periods under applicable law within which legal claims may be brought; and
  • whether the data is still necessary to provide you with services or to maintain an ongoing relationship.

6.1.3 Where a longer retention period is required by a court order, regulatory direction, or ongoing legal proceedings, we will retain the relevant information until those proceedings are resolved and we are no longer required to retain it.

6.1.4 When we no longer need your information and have no legal obligation to retain it, we securely delete or anonymise it.

6.2 Anonymised Data

6.2.1 We may retain anonymised or aggregated data — from which you cannot be identified — indefinitely for analytical, statistical, and product development purposes.

6.2.2 This includes the training, testing and improvement of automated and machine-learning models used in our services. Data used for this purpose is anonymised or aggregated so that you cannot be identified from it. We do not use identifiable client account activity to train these models, and the models are not trained in a way that would allow your individual activity to be reconstructed from them.

7. How We Protect Your Information

7.1 Security Measures

7.1.1 We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, alteration, or disclosure. These include:

  • encryption of data in transit (TLS) and at rest;
  • access controls ensuring that only authorised personnel can access personal information;
  • multi-factor authentication for platform access;
  • regular security testing and vulnerability assessments;
  • audit logging of access to personal data;
  • data minimisation — we only collect what we actually need; and
  • staff training on data protection and security.

7.1.2 Our production systems and databases are hosted in Canada, in Google Cloud's Montréal, Québec region. Our database runs on Google Cloud SQL, a managed PostgreSQL service operated by Google as our data processor under its standard Data Processing Addendum. Personal information held in our database is stored in Québec and does not leave Québec, in compliance with our obligations under Law 25.

7.1.3 While we take reasonable precautions to protect your personal information, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee that our platform is invulnerable to security breaches, cyberattacks, or other unauthorised access beyond our control. You are responsible for keeping your account credentials confidential and for notifying us promptly if you suspect unauthorised access to your account.

7.2 Data Breaches

7.2.1 If we become aware of a security incident that affects your personal information, we will assess the risk and notify you and the relevant regulatory authorities as required by applicable law. Under PIPEDA, we are required to notify you of breaches that create a real risk of significant harm. Under Law 25, we are required to notify the Commission d'accès à l'information and affected individuals of certain incidents.

8. Your Privacy Rights

8.1 Rights Available to You

8.1.1 Depending on where you live and the laws that apply to you, you may have some or all of the following rights in relation to your personal information. We will not discriminate against you for exercising any of these rights.

  • Right of access — you can ask us to confirm whether we hold personal information about you, to provide you with a copy of that information, and to give you information about how and why we use it, who we share it with, and how long we keep it.
  • Right to correction — you can ask us to correct personal information that is inaccurate, out of date, or incomplete. Where appropriate, we will inform third parties to whom we have disclosed the information of any correction.
  • Right to deletion — in certain circumstances, you can ask us to delete your personal information, for example where it is no longer necessary for the purposes for which it was collected. This right is not absolute — we may need to retain certain information to comply with a legal or regulatory obligation (including our record-keeping obligations under Canadian anti-money laundering law), to establish, exercise, or defend legal claims, or to complete a transaction you have requested.
  • Right to data portability — where processing is based on consent or on the performance of a contract, you can ask us to provide your personal information in a structured, commonly used, machine-readable format, or to transmit it directly to another controller where technically feasible.
  • Right to object — you can object to processing based on our legitimate interests, including profiling. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or that the processing is required to establish, exercise, or defend legal claims. You have an absolute right to object at any time to the use of your personal information for direct marketing — see Section 11.
  • Right to restrict processing — in certain circumstances, you can ask us to restrict how we use your information, for example while a dispute about its accuracy or about our right to use it is being resolved.
  • Right to withdraw consent — where processing is based on your consent, you can withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal, and may affect our ability to provide some or all of our services to you.
  • Right to be informed of automated decision-making — where we use automated processing, including profiling, to make a decision that produces legal or similarly significant effects for you, you can ask to be informed of that processing and, where applicable, to request human review of the decision.
  • Right to designate a person / handling after death (Quebec residents) — under Quebec law, you may, in certain circumstances, request the de-indexing of information and exercise rights in relation to your personal information, and a person may exercise certain rights with respect to your information after your death.

8.1.2 Some of these rights apply only under specific laws or in specific circumstances, and certain exceptions and limitations apply. Where a right does not apply to your situation, we will explain why when we respond to your request.

8.2 How to Exercise Your Rights

8.2.1 To exercise any of your rights, contact our Privacy Officer at privacy@finik.ai. We will respond to your request within 30 days under PIPEDA and Law 25.

8.2.2 We may need to verify your identity before processing your request. We won't charge a fee for reasonable requests.

8.2.3 There are situations where we cannot fulfil a request — for example, where complying would interfere with a legal obligation, an ongoing FINTRAC investigation, or a court order. We'll explain why if we're able to.

8.3 Right to Lodge a Complaint

8.3.1 If you're not satisfied with how we handle your personal information, you have the right to complain to the relevant supervisory authority:

  • Canada (outside Quebec): Office of the Privacy Commissioner of Canada — www.priv.gc.ca
  • Quebec: Commission d'accès à l'information du Québec — www.cai.gouv.qc.ca

We'd appreciate the chance to address your concern directly first — please contact us at privacy@finik.ai before escalating to a supervisory authority.

9. Children's Privacy

9.1 Our services are not directed at individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal information from a minor, we will delete it promptly. If you believe we may have collected information about a minor, please contact us at privacy@finik.ai.

10. Cookies and Tracking Technologies

10.1 We use cookies and similar tracking technologies on our website. Our full Cookie Policy — including a description of each cookie category, which cookies we use, how long they last, and how to manage your preferences — is published separately.

10.2 In summary, we use strictly necessary cookies (required for the website to function and cannot be disabled) and, where you consent, functional and analytics cookies. We do not use advertising or targeting cookies for third-party marketing purposes.

10.3 You can manage your cookie preferences at any time through the cookie banner on our website or through your browser settings.

11. Direct Marketing

11.1 Marketing Communications

11.1.1 We will only send you marketing communications — such as information about new services, features, or promotions — where you have given us your explicit consent to do so.

11.1.2 You can withdraw your consent to receive marketing communications at any time by clicking "unsubscribe" in any marketing email, or by emailing us at privacy@finik.ai. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

11.1.3 You also have an absolute right to object at any time to the use of your personal information for direct marketing. If you object, we will stop using your information for this purpose immediately.

11.1.4 Withdrawing consent for marketing will not affect our ability to send you service-related communications — such as transaction confirmations, security alerts, or compliance notices — which we send on the basis of our contract with you or our legal obligations.

12. Automated Decision-Making

12.1 How We Use Automation

12.1.1 Some of our compliance and onboarding processes involve automated tools — including automated screening against sanctions lists and PEP databases, automated on-chain risk scoring, and automated approval of individual account applications where no risk signals are identified.

12.1.2 We do not make decisions that are based solely on automated processing. A qualified member of our compliance team is always involved in reviewing the results of automated checks before any final decision is made that significantly affects you — for example, whether to open an account, block a transaction, or request additional verification. This means you will not be subject to a decision based solely on automated processing within the meaning of applicable data protection law.

12.1.3 Where an automated check produces a result that is then reviewed by our team and leads to a decision that has a significant effect on you, you have the right to:

  • request human review of the decision;
  • express your point of view; and
  • contest the decision.

12.1.4 To request a review of any decision affecting your account, contact us at privacy@finik.ai or hi@finik.ai. We will respond within five Business Days.

12.2 Model Training

12.2.1 Where Finik uses data to train or improve automated and machine-learning models, it uses anonymised or aggregated data only, as described in Section 6.2. This is separate from the automated processing described in Section 12.1, which concerns decisions about your account. Where Finik relies on legitimate interests for this processing, you have the right to object, as set out in Section 8.

13.1 Our platform may contain links to third-party websites. We are not responsible for the privacy practices of those websites. This policy applies only to information collected by Finik. We encourage you to read the privacy policies of any third-party websites you visit.

14. Limitations on Your Rights

14.1 When We May Decline a Request

14.1.1 We may be required or permitted by applicable law to decline your request to exercise a privacy right. For example:

  • we may decline a deletion request where we are required to retain your personal information to comply with a legal obligation — such as PCMLTFA record-keeping requirements — or where the data is needed in connection with a legal claim;
  • we may decline an objection request and continue processing your personal information where we can demonstrate compelling legitimate grounds that override your rights and freedoms; and
  • we may decline an access request where complying would reveal information about another person, or where doing so could compromise a regulatory investigation, a FINTRAC filing, or a court order.

14.1.2 Where we decline a request, we will explain our reasons to the extent permitted by law.

15. Changes to This Policy

15.1 How We Update This Policy

15.1.1 We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make a material change, we will:

  • post the updated policy on the platform with a new "Effective date";
  • notify you by email or in-app notification; and
  • where required by law (including Law 25), seek your consent before the change takes effect.

15.1.2 Your continued use of our services after a policy update constitutes your acceptance of the updated policy, to the extent permitted by applicable law.

16. Contact Us

16.1 Privacy Officer

16.1.1 FinikPay Inc. has designated a Privacy Officer who is accountable for our compliance with this policy and applicable privacy laws.

If you have any questions about this policy, wish to exercise your rights, or have a concern about how we handle your personal information, please contact our Privacy Officer:

Emailprivacy@finik.ai
PostPrivacy Officer, FinikPay Inc., Suite 548, 1235 Bay Street, Toronto, ON, Canada M5R 3K4

16.1.2 We aim to respond to all privacy enquiries within five Business Days of receipt.

Back to top