Privacy Policy

How personal data is processed, retained and protected on e-IBAN.net.

Last updated: 8 October 2026

1. Scope and controller

The operator of e-IBAN.net acts as the controller for personal data processed through this service. This notice applies to visitors, registered users, API users, contact-form users and people using public profile or IBAN-sharing features. Privacy and data-rights requests can be submitted through the form on the Contact page.

2. Data we process

  • Account data: name, email address, password hash and account preferences.
  • User-saved data: saved IBANs, labels, descriptions, profile information and user-uploaded images.
  • Contact data: name, email address, topic, category and message submitted through the contact form.
  • Technical/security data: session information, browser/device information, requested paths, error and security events. A one-way identifier/hash may be used instead of storing a raw IP address in security and abuse-prevention logs.
  • Usage data: query counts, page views, referrer domain and UTM parameters explicitly sent by the browser. Sensitive IBAN values are masked in query logs.

We do not ask for passwords, payment-card details, card PINs or one-time verification codes. Do not submit such information through the contact form.

3. Purposes

We process data to operate and personalize the service, manage accounts and saved content, provide IBAN/SWIFT features, answer support requests, prevent abuse and attacks, diagnose errors, comply with legal obligations and measure service performance.

4. Legal bases and collection

Data is collected electronically through forms, account actions, server requests and security logs. Depending on applicable law, processing may rely on contract performance, legal obligations, establishment/exercise/defence of legal claims, legitimate interests and consent where required.

5. Retention

  • Activity/security logs are generally removed after 60 days.
  • IBAN query logs are generally removed after 180 days.
  • Contact messages are kept for support and dispute tracking for up to 24 months, unless a longer period is legally required.
  • Account and user-saved data may be kept while the account/feature remains active or until a valid deletion request is completed.
  • Records subject to a legal hold or ongoing dispute may be retained for the required period.

6. Sharing

Personal data may be shared only as necessary with hosting, infrastructure, security, communication, analytics or advertising providers and with legally authorized public authorities. If third-party advertising or measurement services are enabled, applicable consent rules must be followed where required.

7. Public content

If a user enables a public profile, IBAN card or share link, fields deliberately made public may be visible to anyone with access to that page or link. e-IBAN.net does not verify account ownership on user-generated pages. Share links can be revoked by the user.

8. Security

We apply reasonable technical and organizational safeguards, including access controls, security headers, rate limiting, password hashing, limited logging and masking of sensitive values. No internet transmission or storage method can be guaranteed to be 100% secure.

9. Your rights

Depending on the law that applies to you, you may have rights to access, correct, delete or restrict your data, object to certain processing, obtain information about recipients and lodge a complaint with a competent authority. Submit a request through Contact using the “Privacy / data request” category. We may request reasonable information to verify that the request belongs to you.

10. Cookies

See the Cookie Policy for details about required and optional technologies.

11. Changes

This notice may be updated when the service or applicable law changes. The current version is always published on this page.