Privacy Policy
This notice explains what personal data parallel45 collects, why we collect it, who we share it with, and the rights you have over it. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
Sections 4 to 6 of this notice describe processing that will take place once the application launches. Until then, the only processing we carry out is the website processing described in section 3.
1Who we are
The controller of the personal data described in this notice is:
Parallel 45 Technologies DOO Beograd
Bulevar Vojvode Mišića 17/2
11000 Belgrade, Serbia
Company registration number: 22319094
We provide the parallel45 application and this website.
For any question about this notice or about your personal data, write to office@parallel45.tech.
We have not appointed a Data Protection Officer. Requests sent to the address above reach the people responsible for data protection at parallel45.
Our representative in the European Union
We are established in Serbia, outside the European Union. Once we offer the parallel45 application to people in the EU, Article 27 GDPR requires us to designate a representative in the Union and to name that representative here.
That entity is currently being registered. We will publish its name, address and contact details in this section before the application is released, and you will then be able to address our representative on any matter relating to your personal data, instead of or in addition to contacting us directly.
Until that point the application is not available and, as section 3 describes, this website collects no personal data about you. Any question about your personal data in the meantime should come to office@parallel45.tech, and we will answer it.
2What this notice covers, and what it does not
This notice covers processing for which parallel45 decides the purposes and means — that is, processing for which we are the controller.
The parallel45 application opens two accounts for you in a single journey: a payment account at a partner bank and an investment account at a partner investment services provider. Those partners are separate organisations that decide, in their own right, how they process your data in order to meet their own regulatory obligations. They are controllers of that processing and they publish their own privacy notices. This notice does not speak for them, and you should read theirs alongside it. We identify them to you in the application before you provide any data.
The precise allocation of controller responsibilities between parallel45 and our partners is being finalised as part of the partnership agreements. If any of that processing turns out to be joint controllership within the meaning of Article 26 GDPR, we will publish the essence of the arrangement here and tell you where to exercise your rights. Whatever the outcome, you may always exercise your rights against us for the processing described in this notice.
3Visiting parallel45.tech
The website is deliberately minimal.
- We set no cookies and use no local or session storage. There is no cookie banner because there is nothing to consent to.
- We run no analytics — no measurement, profiling, advertising or tracking technology of any kind, first-party or third-party.
- We keep no access logs. Request logging is switched off on our content delivery network, so we do not retain a record of who visited which page.
- We operate no contact or sign-up form, so the site collects nothing you type.
Delivering any web page necessarily involves your device's IP address being processed in transit. The site is served from Amazon Web Services (Amazon CloudFront and Amazon S3), which processes connection metadata transiently in order to route and deliver the page and to protect the service against attack. AWS acts as our processor for this. We do not receive that metadata in a form that identifies you and we do not store it.
Every asset this site needs — styles, fonts and images — is served from our own domain. Reading these pages causes your browser to contact no one but us, so no font provider, no analytics service and no advertising network learns your IP address or that you were here.
4Personal data we process in the application
To open and operate your investment account we process the following categories of data. Most of it is collected during onboarding; some of it arises later, from your use of the service.
| Category | What it includes |
|---|---|
| Identity | First and last name, date of birth, place of birth, nationality, country of residence. |
| Contact details | Email address and mobile telephone number, each verified during onboarding. |
| Address | Residential address — street, city, postal code and country. |
| Tax status | Country or countries of tax residence and the corresponding tax identification numbers, and a self-certification of whether you are a US person. Required for automatic exchange of tax information. |
| Identity documents | Document type, number, issuing country and authority, issue and expiry dates, and the machine-readable zone; together with the images and the identity-verification video captured when your identity was checked. |
| Financial-crime screening | Whether you are a politically exposed person, your anti-money-laundering risk classification, and when the screening was performed. These outcomes are produced by a specialist provider; we record and retain them as regulatory evidence. |
| Knowledge and experience | Your answers to the appropriateness questionnaire, the version of the questionnaire you answered, the resulting outcome for each asset class, and your acknowledgement of any warning or cost disclosure shown to you. |
| Agreements and consents | Which terms and consents you accepted, the exact version of each document, and the moment you accepted it. |
| Account and transactions | Your investment account identifiers, holdings, orders and transaction history, and the preferences you set — such as your interface language. |
| Device and security data | Device model and operating system version, application version, and the security events needed to protect your account, such as sign-in attempts. |
| Educational content usage | Which articles and lessons in the in-app library you opened and how far you progressed, recorded against your account so we can continue where you left off and understand which material is useful. |
Biometrics stay on your device
If you unlock the application with Face ID, Touch ID or a fingerprint, that check is performed entirely by your phone. Your biometric data is never transmitted to us and we never store it. We only learn whether the check succeeded.
Where the data comes from
Most of it you give us directly in the application. The identity check, document capture and financial-crime screening are carried out during the onboarding journey by our partner bank and its service providers, and the results are passed to us so that we can open your investment account and hold the regulatory evidence for it. If you are already a customer of the partner bank, an identity verification the bank performed earlier may be reused instead of checking you again.
5Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Opening and operating your investment account, executing your instructions, and providing the application | Performance of a contract with you — Art. 6(1)(b) |
| Verifying your identity, screening against sanctions and politically-exposed-person lists, and retaining the evidence | Compliance with a legal obligation — Art. 6(1)(c), under anti-money-laundering legislation |
| Assessing whether an investment product is appropriate for you, and recording the assessment | Compliance with a legal obligation — Art. 6(1)(c), under investment-services legislation |
| Reporting your tax residence to the competent authorities | Compliance with a legal obligation — Art. 6(1)(c) |
| Transmitting your onboarding data to the investment services provider so that your investment account can be opened | Your consent — Art. 6(1)(a), given at the terms-acceptance step |
| Keeping the service secure, preventing and investigating fraud and abuse, and keeping the application working | Our legitimate interests — Art. 6(1)(f), in operating a secure financial service |
| Understanding which educational content is used, so we can improve it | Our legitimate interests — Art. 6(1)(f), in improving the service |
| Sending you marketing about our services | Your consent — Art. 6(1)(a). You may withdraw it at any time. |
Where we rely on your consent, you may withdraw it at any time by writing to office@parallel45.tech or through the application. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it. Note that where we hold data to satisfy a legal obligation — the anti-money-laundering evidence in particular — withdrawing consent does not remove that obligation, and we may have to keep the data for the statutory period.
6Who we share it with
- Our partner bank, as the regulated institution that carries out the customer due diligence and holds the payment account opened alongside your investment account.
- Our investment services provider, which opens and holds the investment account and executes your orders. We transmit your onboarding data to them on the consent you give at the terms-acceptance step.
- The provider that operates the onboarding journey on our behalf and on the bank's, including identity verification and document capture. It acts as a processor under contract and may not use your data for its own purposes.
- Cloud infrastructure providers, principally Amazon Web Services, which host the platform. They act as processors under contract.
- Public authorities, where we are legally required to disclose — tax authorities, financial supervisors, and law enforcement acting on a valid legal basis.
We do not sell your personal data, and we do not share it with advertising networks or data brokers.
Transfers outside the EEA
Your data is stored in the European Union. The platform runs in Amazon
Web Services data centres in Frankfurt (eu-central-1), and we design the
service so that personal data stays there.
We work on that data from Belgrade. Parallel 45 Technologies DOO is established in Serbia, so our own staff reach those records from outside the EEA. That is not a transfer to a third country — it is us processing data we are responsible for, by people who are part of our own organisation. The GDPR continues to apply to us in full under Article 3(2): European supervisory authorities can enforce it against us, and you keep every right described in section 9.
Data does reach us from partners inside the EU. When the partner bank, or the provider that operates the onboarding journey, passes your onboarding data to us in Serbia, that is a transfer to a third country — and Serbia is not covered by a European Commission adequacy decision. Those transfers are made under the European Commission's Standard Contractual Clauses, alongside the technical and organisational measures described in section 10.
You may ask us for a copy of the safeguards that apply to any transfer by writing to office@parallel45.tech.
7How long we keep it
We keep personal data only as long as we need it, and where the law fixes a period we keep it for that period. We serve Slovenia, Croatia and Serbia, and rather than varying the periods by market we apply the longest period that is lawful across all three. Where the law sets a maximum as well as a minimum, we respect the maximum and delete.
- Onboarding and customer due diligence evidence — identity documents, verification records, screening outcomes, consents and questionnaire answers — is held as a tamper-evident record for ten years after our relationship with you ends. Anti-money-laundering law sets five years as the standard period and permits an extension to a maximum of ten; we apply the full ten. The same law requires us to delete this evidence once the period expires, and we do — this is a ceiling, not a floor, and we do not keep due diligence evidence beyond it.
- Transaction and account records are retained for twenty years after the end of the financial year in which the transaction took place. Investment-services legislation requires five years, extended to seven at a supervisor's request, but accounting legislation requires considerably longer: we are a Serbian company, so our books are kept under Serbian accounting law, whose longest retention period is twenty years. We apply that single period to every market rather than keeping different records for different lengths of time.
- Educational content usage is kept while your account is open and deleted when it closes.
- Security and operational records are kept for as long as they are useful for detecting and investigating incidents, and then deleted.
When a retention period ends, we delete the data or irreversibly anonymise it.
8Automated processing
Two checks in the application produce an outcome without a person reviewing it first:
- An age eligibility check. If we cannot establish that you meet the minimum age, the check fails and access is refused rather than granted.
- The appropriateness assessment. Your questionnaire answers produce an outcome for each asset class, which may result in a warning being shown to you or a product not being offered.
Neither check profiles you or predicts your behaviour; both apply fixed rules that financial-services regulation requires us to apply. If a decision affects you and you disagree with it, write to office@parallel45.tech — you have the right to obtain human intervention, to express your point of view and to contest the decision.
9Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Rectify data that is inaccurate or incomplete.
- Erase your data, where we have no overriding legal obligation to keep it.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format, and have it transmitted to another controller where technically feasible.
- Object to processing based on our legitimate interests, and to object at any time to direct marketing.
- Withdraw consent at any time, where processing rests on consent.
To exercise any of these, write to office@parallel45.tech. We answer within one month, and will tell you if we need longer because the request is complex. We may need to verify your identity first — we will not disclose personal data to someone who cannot show they are entitled to it.
Because your data is also processed by our partner bank and the investment services provider as controllers in their own right, a request that concerns their processing may need to be raised with them. If you send it to us, we will tell you where it belongs rather than leave you to find out.
Complaints
If you think we have handled your personal data unlawfully, please raise it with us first — we would rather fix it. You also have the right to lodge a complaint with a data protection supervisory authority.
Because we are established outside the European Union, there is no single "lead" authority for us under the GDPR's one-stop-shop mechanism. You should complain to the supervisory authority of the country where you live or work, or where you believe the infringement took place. For customers in Slovenia that is the Information Commissioner (Informacijski pooblaščenec); in Croatia, the Personal Data Protection Agency (AZOP). You may also contact our EU representative named in section 1.
We are also subject to the Serbian Personal Data Protection Act. Complaints may be addressed to the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11000 Belgrade, Serbia.
10How we protect your data
Data is encrypted in transit and at rest. Access to production systems is limited to named individuals who need it, is authenticated with multiple factors, and is logged. The platform is monitored continuously for security events, and our providers are held to contractual security obligations. Onboarding evidence is stored so that it cannot be altered or deleted once written.
No system is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and the supervisory authority within 72 hours as the GDPR requires.
11Children
The service is for adults. We do not knowingly offer it to, or collect data from, anyone below the minimum age for opening an investment account in their country. The age check described in section 8 refuses access rather than granting it where age cannot be established.
12Changes to this notice
We will update this notice when what we do with personal data changes. The version number and effective date at the top always tell you which version you are reading. If a change materially affects you, we will tell you in the application or by email before it takes effect — we will not rely on you noticing a silent edit.
13Contact
Parallel 45 Technologies DOO Beograd
Bulevar Vojvode Mišića 17/2
11000 Belgrade, Serbia
Company registration number: 22319094
Email: office@parallel45.tech