Privacy Policy

Applies to
The parallel45 mobile application and the parallel45.tech website
Version
1.0
Effective
14 August 2026
Last updated
14 August 2026

This notice explains what personal data parallel45 collects, why we collect it, who we share it with, and the rights you have over it. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

The parallel45 application is not yet publicly available

Sections 4 to 6 of this notice describe processing that will take place once the application launches. Until then, the only processing we carry out is the website processing described in section 3.

1Who we are

The controller of the personal data described in this notice is:

Parallel 45 Technologies DOO Beograd
Bulevar Vojvode Mišića 17/2
11000 Belgrade, Serbia
Company registration number: 22319094

We provide the parallel45 application and this website.

For any question about this notice or about your personal data, write to office@parallel45.tech.

We have not appointed a Data Protection Officer. Requests sent to the address above reach the people responsible for data protection at parallel45.

Our representative in the European Union

We are established in Serbia, outside the European Union. Once we offer the parallel45 application to people in the EU, Article 27 GDPR requires us to designate a representative in the Union and to name that representative here.

That entity is currently being registered. We will publish its name, address and contact details in this section before the application is released, and you will then be able to address our representative on any matter relating to your personal data, instead of or in addition to contacting us directly.

Until that point the application is not available and, as section 3 describes, this website collects no personal data about you. Any question about your personal data in the meantime should come to office@parallel45.tech, and we will answer it.

2What this notice covers, and what it does not

This notice covers processing for which parallel45 decides the purposes and means — that is, processing for which we are the controller.

The parallel45 application opens two accounts for you in a single journey: a payment account at a partner bank and an investment account at a partner investment services provider. Those partners are separate organisations that decide, in their own right, how they process your data in order to meet their own regulatory obligations. They are controllers of that processing and they publish their own privacy notices. This notice does not speak for them, and you should read theirs alongside it. We identify them to you in the application before you provide any data.

Open point

The precise allocation of controller responsibilities between parallel45 and our partners is being finalised as part of the partnership agreements. If any of that processing turns out to be joint controllership within the meaning of Article 26 GDPR, we will publish the essence of the arrangement here and tell you where to exercise your rights. Whatever the outcome, you may always exercise your rights against us for the processing described in this notice.

3Visiting parallel45.tech

The website is deliberately minimal.

Delivering any web page necessarily involves your device's IP address being processed in transit. The site is served from Amazon Web Services (Amazon CloudFront and Amazon S3), which processes connection metadata transiently in order to route and deliver the page and to protect the service against attack. AWS acts as our processor for this. We do not receive that metadata in a form that identifies you and we do not store it.

No third-party requests

Every asset this site needs — styles, fonts and images — is served from our own domain. Reading these pages causes your browser to contact no one but us, so no font provider, no analytics service and no advertising network learns your IP address or that you were here.

4Personal data we process in the application

To open and operate your investment account we process the following categories of data. Most of it is collected during onboarding; some of it arises later, from your use of the service.

Category What it includes
Identity First and last name, date of birth, place of birth, nationality, country of residence.
Contact details Email address and mobile telephone number, each verified during onboarding.
Address Residential address — street, city, postal code and country.
Tax status Country or countries of tax residence and the corresponding tax identification numbers, and a self-certification of whether you are a US person. Required for automatic exchange of tax information.
Identity documents Document type, number, issuing country and authority, issue and expiry dates, and the machine-readable zone; together with the images and the identity-verification video captured when your identity was checked.
Financial-crime screening Whether you are a politically exposed person, your anti-money-laundering risk classification, and when the screening was performed. These outcomes are produced by a specialist provider; we record and retain them as regulatory evidence.
Knowledge and experience Your answers to the appropriateness questionnaire, the version of the questionnaire you answered, the resulting outcome for each asset class, and your acknowledgement of any warning or cost disclosure shown to you.
Agreements and consents Which terms and consents you accepted, the exact version of each document, and the moment you accepted it.
Account and transactions Your investment account identifiers, holdings, orders and transaction history, and the preferences you set — such as your interface language.
Device and security data Device model and operating system version, application version, and the security events needed to protect your account, such as sign-in attempts.
Educational content usage Which articles and lessons in the in-app library you opened and how far you progressed, recorded against your account so we can continue where you left off and understand which material is useful.

Biometrics stay on your device

If you unlock the application with Face ID, Touch ID or a fingerprint, that check is performed entirely by your phone. Your biometric data is never transmitted to us and we never store it. We only learn whether the check succeeded.

Where the data comes from

Most of it you give us directly in the application. The identity check, document capture and financial-crime screening are carried out during the onboarding journey by our partner bank and its service providers, and the results are passed to us so that we can open your investment account and hold the regulatory evidence for it. If you are already a customer of the partner bank, an identity verification the bank performed earlier may be reused instead of checking you again.

5Why we process it, and on what legal basis

Purpose Legal basis (GDPR Art. 6)
Opening and operating your investment account, executing your instructions, and providing the application Performance of a contract with you — Art. 6(1)(b)
Verifying your identity, screening against sanctions and politically-exposed-person lists, and retaining the evidence Compliance with a legal obligation — Art. 6(1)(c), under anti-money-laundering legislation
Assessing whether an investment product is appropriate for you, and recording the assessment Compliance with a legal obligation — Art. 6(1)(c), under investment-services legislation
Reporting your tax residence to the competent authorities Compliance with a legal obligation — Art. 6(1)(c)
Transmitting your onboarding data to the investment services provider so that your investment account can be opened Your consent — Art. 6(1)(a), given at the terms-acceptance step
Keeping the service secure, preventing and investigating fraud and abuse, and keeping the application working Our legitimate interests — Art. 6(1)(f), in operating a secure financial service
Understanding which educational content is used, so we can improve it Our legitimate interests — Art. 6(1)(f), in improving the service
Sending you marketing about our services Your consent — Art. 6(1)(a). You may withdraw it at any time.

Where we rely on your consent, you may withdraw it at any time by writing to office@parallel45.tech or through the application. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it. Note that where we hold data to satisfy a legal obligation — the anti-money-laundering evidence in particular — withdrawing consent does not remove that obligation, and we may have to keep the data for the statutory period.

6Who we share it with

We do not sell your personal data, and we do not share it with advertising networks or data brokers.

Transfers outside the EEA

Your data is stored in the European Union. The platform runs in Amazon Web Services data centres in Frankfurt (eu-central-1), and we design the service so that personal data stays there.

We work on that data from Belgrade. Parallel 45 Technologies DOO is established in Serbia, so our own staff reach those records from outside the EEA. That is not a transfer to a third country — it is us processing data we are responsible for, by people who are part of our own organisation. The GDPR continues to apply to us in full under Article 3(2): European supervisory authorities can enforce it against us, and you keep every right described in section 9.

Data does reach us from partners inside the EU. When the partner bank, or the provider that operates the onboarding journey, passes your onboarding data to us in Serbia, that is a transfer to a third country — and Serbia is not covered by a European Commission adequacy decision. Those transfers are made under the European Commission's Standard Contractual Clauses, alongside the technical and organisational measures described in section 10.

You may ask us for a copy of the safeguards that apply to any transfer by writing to office@parallel45.tech.

7How long we keep it

We keep personal data only as long as we need it, and where the law fixes a period we keep it for that period. We serve Slovenia, Croatia and Serbia, and rather than varying the periods by market we apply the longest period that is lawful across all three. Where the law sets a maximum as well as a minimum, we respect the maximum and delete.

When a retention period ends, we delete the data or irreversibly anonymise it.

8Automated processing

Two checks in the application produce an outcome without a person reviewing it first:

Neither check profiles you or predicts your behaviour; both apply fixed rules that financial-services regulation requires us to apply. If a decision affects you and you disagree with it, write to office@parallel45.tech — you have the right to obtain human intervention, to express your point of view and to contest the decision.

9Your rights

Under the GDPR you have the right to:

To exercise any of these, write to office@parallel45.tech. We answer within one month, and will tell you if we need longer because the request is complex. We may need to verify your identity first — we will not disclose personal data to someone who cannot show they are entitled to it.

Because your data is also processed by our partner bank and the investment services provider as controllers in their own right, a request that concerns their processing may need to be raised with them. If you send it to us, we will tell you where it belongs rather than leave you to find out.

Complaints

If you think we have handled your personal data unlawfully, please raise it with us first — we would rather fix it. You also have the right to lodge a complaint with a data protection supervisory authority.

Because we are established outside the European Union, there is no single "lead" authority for us under the GDPR's one-stop-shop mechanism. You should complain to the supervisory authority of the country where you live or work, or where you believe the infringement took place. For customers in Slovenia that is the Information Commissioner (Informacijski pooblaščenec); in Croatia, the Personal Data Protection Agency (AZOP). You may also contact our EU representative named in section 1.

We are also subject to the Serbian Personal Data Protection Act. Complaints may be addressed to the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11000 Belgrade, Serbia.

10How we protect your data

Data is encrypted in transit and at rest. Access to production systems is limited to named individuals who need it, is authenticated with multiple factors, and is logged. The platform is monitored continuously for security events, and our providers are held to contractual security obligations. Onboarding evidence is stored so that it cannot be altered or deleted once written.

No system is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and the supervisory authority within 72 hours as the GDPR requires.

11Children

The service is for adults. We do not knowingly offer it to, or collect data from, anyone below the minimum age for opening an investment account in their country. The age check described in section 8 refuses access rather than granting it where age cannot be established.

12Changes to this notice

We will update this notice when what we do with personal data changes. The version number and effective date at the top always tell you which version you are reading. If a change materially affects you, we will tell you in the application or by email before it takes effect — we will not rely on you noticing a silent edit.

13Contact

Parallel 45 Technologies DOO Beograd
Bulevar Vojvode Mišića 17/2
11000 Belgrade, Serbia
Company registration number: 22319094

Email: office@parallel45.tech