NestiFi
Platform▾
Solutions▾
Deployment▾
Resources▾
Trust
Book a demo
Explore NestiFi
Home›Trust centre›
Book a demo
NestiFi
Platform▾
Solutions▾
Deployment▾
Resources▾
Trust
Book a demo
Explore NestiFi
Home›Trust centre›
Book a demo
PRIVACY AND DATA

Privacy Notice

How NestiFi handles personal data across our Website, business relationships and institution-powered experiences.

Last updated 18 August 2026
On this page
  1. 01Who we are
  2. 02Laws that apply to this Notice
  3. 03Our role depends on the context
  4. 04Information collected through this Website
  5. 05Information in institution-deployed services
  6. 06Why we use personal data
  7. 07Seb and AI-assisted features
  8. 08Children’s data
  9. 09How information is shared
  10. 10Advertising, analytics and cookies
  11. 11International transfers
  12. 12Retention
  13. 13Security
  14. 14Your rights
  15. 15Exercising your rights and making a complaint
  16. 16Changes to this Notice
  17. 17Contact us

Who we are

This Privacy Notice explains how NestiFi Technologies Limited (“NestiFi”, “we”, “us” or “our”) handles personal data in connection with this Website, business enquiries and NestiFi-powered institutional experiences.

NestiFi Technologies Limited is an Irish company and is responsible for this Website and for the processing described in this Notice where NestiFi acts as controller.

Laws that apply to this Notice

NestiFi Technologies Limited is established in Ireland. Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), applies to personal data processed in the context of the activities of that establishment, irrespective of where the processing takes place and irrespective of the nationality or location of the individuals concerned. The Irish Data Protection Commission is NestiFi’s lead supervisory authority.

The GDPR also applies where NestiFi offers services to, or monitors the behaviour of, individuals located in the European Economic Area. Where NestiFi processes personal data relating to individuals in the United Kingdom, the equivalent obligations of the UK GDPR and the Data Protection Act 2018 apply.

In the United States, NestiFi generally acts as a service provider or processor to a participating institution. That institution remains responsible for its own obligations under laws such as the Gramm-Leach-Bliley Act, the Children’s Online Privacy Protection Act and applicable state privacy laws. NestiFi supports those obligations under its customer agreements and applies the standards described in this Notice to the personal data it handles, wherever the institution and its customers are located.

Our role depends on the context

For Website visitors, prospective customers, business contacts and people who contact us directly, NestiFi acts as controller and determines why and how that information is used.

For an institution-deployed service, the credit union, community bank, registered investment adviser, wealth firm or platform partner determines the purposes of processing. NestiFi processes the personal data required to provide and secure the platform on that institution’s documented instructions as its processor or service provider.

Where NestiFi acts as processor, that processing is governed by a written data processing agreement containing the terms required by Article 28 of the GDPR, including obligations on confidentiality, security, engagement of sub-processors, assistance with individual rights requests, breach notification, and return or deletion of data at the end of the engagement.

The applicable customer agreement and product-specific notice set out the responsibilities of NestiFi, the participating institution and any authorised provider. You should also read the privacy notice supplied by the institution through which you access the service.

Information collected through this Website

Depending on how you interact with us, we may collect:

  • business contact information, such as name, work email, organisation, job title and telephone number;
  • information included in demo requests, support messages, correspondence and meeting notes;
  • limited device, IP address, browser and security-log information generated by our hosting and security providers; and
  • information you choose to provide during a business relationship.

Information in institution-deployed services

In NestiFi-powered deployments, participating financial institutions and their approved regulated or identity-verification providers collect sensitive onboarding information such as Social Security numbers, dates of birth, bank details and know-your-customer documentation where that information is required.

NestiFi does not request that visitors submit that information through the public Website. In an institutional deployment, NestiFi processes only the information required to provide, support and secure the platform in accordance with the customer’s configuration, documented instructions and agreements.

Why we use personal data

We use personal data for the following purposes and legal bases:

  • to respond to enquiries, arrange demonstrations and take steps toward a contract;
  • to provide, administer, support and secure the Website and services, based on our legitimate interests and contractual obligations;
  • to manage customer and supplier relationships and maintain appropriate business records;
  • to detect, investigate and prevent misuse, security incidents and fraud;
  • to comply with legal, regulatory, accounting and reporting obligations; and
  • where required, for a purpose to which you have consented. You may withdraw consent at any time without affecting earlier lawful processing.

Seb and AI-assisted features

Seb is an AI-assisted educational and workflow tool. Seb does not make investment recommendations, choose financial products, provide financial advice, determine creditworthiness or make lending or underwriting decisions.

Prompts, responses and related context are processed only to provide the requested feature, maintain security, troubleshoot and evaluate quality in accordance with the relevant customer agreement and product notice. Users should avoid entering information that is not needed for the interaction.

We will not use institution customer or end-user content for unrelated general-purpose model training without appropriate authorisation and disclosure. External AI providers used to support the service are subject to contractual, access and data-protection controls appropriate to the service.

Children’s data

The public Website is intended for adults and institutional representatives and is not directed to children under 13. NestiFi-powered family and financial-literacy experiences may be made available to children through a participating institution.

Where required, appropriate parental or guardian authorisation, including verifiable parental consent for children under 13 in the United States, is obtained before personal data is processed. The institution’s child and family notice will explain the information used, parental choices and how deletion can be requested.

NestiFi and its customers should collect only the information reasonably necessary for the relevant child-facing feature and should not use children’s data for behavioural advertising.

How information is shared

We may share personal data only as reasonably necessary with:

  • the institution through which a NestiFi-powered service is offered;
  • hosting, cloud, security, communications, support and professional-service providers acting under appropriate obligations;
  • regulated or identity-verification partners identified by the institution where necessary for their separate services;
  • professional advisers, auditors, insurers and potential investors or acquirers subject to appropriate safeguards; and
  • courts, regulators, law-enforcement bodies or other parties where required by law or necessary to protect rights and security.

Advertising, analytics and cookies

NestiFi does not sell personal data or share it for cross-context behavioural advertising. We do not use advertising pixels, advertising networks, analytics cookies or newsletter cookies on the public Website, and we do not build marketing profiles of visitors or track them across other websites.

We do use a cookieless analytics measurement provided by Framer, the platform that hosts this Website. It records page views and basic technical context such as the page address, the referring page, browser language, time zone and IP address. It does not set cookies and does not store or read information on your device. We rely on our legitimate interests in understanding and improving the Website under Article 6(1)(f) of the GDPR, and you can object at any time using the contact details in this Notice.

The remaining technologies we use are strictly necessary to operate, secure and deliver the Website. Because the analytics measurement described above does not store or access information on your device, and the remaining technologies are strictly necessary to provide the service you have requested, neither requires consent under the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011), which implement the ePrivacy Directive in Ireland. No consent banner is therefore required.

If our use of cookies or similar technologies changes, we will update this Notice and introduce any consent choices required by those Regulations and by the GDPR before the change takes effect.

International transfers

NestiFi is based in Ireland and may use providers or support resources in other countries, including the United States. Where personal data is transferred outside the European Economic Area, we use an available lawful transfer mechanism, such as an adequacy decision or approved standard contractual clauses, together with supplementary safeguards where appropriate.

For transfers of personal data relating to individuals in the United Kingdom, we use the UK International Data Transfer Agreement, the UK Addendum to the standard contractual clauses, or another mechanism recognised under UK law. Where a transfer risk assessment is required, we carry one out before the transfer begins.

Further information about the safeguards applied to a particular transfer is available on request using the contact details in this Notice.

Retention

We retain personal data only for as long as needed for the purpose for which it was collected, including to meet contractual, security, legal, accounting and dispute-resolution requirements.

Retention depends on the relationship and data category. Business enquiries that do not progress may generally be retained for up to 24 months, while customer-contract and transaction-related records may be retained longer where law or legitimate business needs require. Institution-deployed data is retained and returned or deleted in accordance with the customer agreement and documented instructions.

Security

We use administrative, technical and organisational safeguards designed for the nature of the information and the risks involved, including access controls, environment separation, encryption and security monitoring where appropriate.

No method of transmission or storage can be guaranteed completely secure.

Your rights

Individuals in the European Economic Area and the United Kingdom have the following rights in relation to personal data for which NestiFi is the controller. Some rights apply only in particular circumstances, and we will explain the position if a right does not apply to a request you make.

  • access — to obtain confirmation of whether we process personal data about you, a copy of that data and information about how it is used (Article 15);
  • rectification — to have inaccurate personal data corrected and incomplete personal data completed (Article 16);
  • erasure — to have personal data deleted where one of the grounds in Article 17 applies;
  • restriction — to limit how personal data is used while its accuracy or the basis for processing is being resolved (Article 18);
  • portability — to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible (Article 20);
  • objection — to object to processing carried out on the basis of our legitimate interests, and to object at any time to processing for direct marketing (Article 21); and
  • withdrawal of consent — to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3)).

Exercising your rights and making a complaint

Requests can be sent using the contact details in this Notice. We will respond within one month of receiving a request, as required by Article 12(3) of the GDPR. That period may be extended by up to two further months where a request is complex or where we have received a number of requests, in which case we will tell you within the first month and explain the reason for the delay. We may need to verify your identity before acting on a request.

If you use NestiFi through an institution, please contact that institution first where it controls your information. It determines how the request is handled and NestiFi will assist it as required under the applicable data processing agreement.

Individuals in the European Economic Area may lodge a complaint with the Irish Data Protection Commission at dataprotection.ie, or with the supervisory authority in the country where they live or work. Individuals in the United Kingdom may complain to the Information Commissioner’s Office at ico.org.uk.

Residents of certain United States states have rights under applicable state privacy laws, which may include rights to access, delete, correct and obtain a copy of personal information, and to appeal a decision to refuse a request. NestiFi honours the rights that apply to its role and processing, and supports participating institutions in responding to requests they receive.

Changes to this Notice

We may update this Notice as our services, corporate structure, data practices or legal obligations change. We will post the revised version here and provide additional notice where required.

Contact us

Privacy questions, data protection enquiries and requests to exercise the rights described above can be sent to support@nestifi.money, marked for the attention of the Data Protection Contact, or by post to NestiFi Technologies Limited, 24A Baggot Street Upper, Dublin, D04 N528, Ireland. NestiFi Technologies Limited is registered in Ireland at the Companies Registration Office under company number 787023.

NestiFi keeps under review whether it is required to appoint a Data Protection Officer under Article 37 of the GDPR. If an appointment is made, those contact details will be published in this Notice.

NestiFi

White-label family finance for credit unions, community banks, wealth firms and platform partners.

sales@nestifi.money →
PlatformTeen cardsFamily investingPlanningSeb AIFinancial literacy
SolutionsCredit unionsCommunity banksRIAs and wealth managersPlatforms and partners
ExploreDeploymentTurnkey infrastructureTrust centreInsightsFAQBook a demo

NestiFi Technologies Limited, registered in Ireland at the Companies Registration Office under company number 787023, registered office 24A Baggot Street Upper, Dublin, D04 N528, Ireland, is a technology provider serving financial institutions. NestiFi provides software, educational tools and institution-controlled workflows. It does not hold customer funds or securities, execute transactions or make investment recommendations. Banking, brokerage, advisory, custodial and other regulated services available through a NestiFi-powered experience are provided by the participating institution or an appropriately authorised provider under its own agreements and disclosures. Deposit insurance and SIPC protection apply only where offered by an eligible provider, subject to applicable rules and limits, and do not protect against investment loss. Investments can lose value. Seb provides educational and workflow support, not financial advice. AI-generated content may be incomplete or inaccurate. Products and features vary by institution and jurisdiction.

PrivacyTermsFAQ© 2026 NestiFi