Privacy Policy

Operated by Tecron · Last updated: 27 July 2026

This policy explains how we handle your personal data, including the bank account information you choose to connect. We designed this Service for personal and household budgeting; we never sell your data, and we never initiate payments.

1. Who we are (Data Controller)

The Service available at tecron.be (the “Service”) is operated by Tecron, a business established in Belgium (company / VAT number: BE0833267216; registered address: 2590 Berlaar). Tecron is the “data controller” for the personal data described here.

For any privacy question or to exercise your rights, contact us at admin@tecron.be.

2. What data we collect

CategoryExamples
Account & authenticationEmail address, hashed password, phone number, two-factor-authentication (2FA) secret (encrypted), API-key hash.
Bank account data (via Enable Banking)Account identifiers (IBAN), balances, and transactions (amount, date, description, counterparty name/IBAN, merchant) — read-only, for the accounts you choose to link.
Imported statementsTransaction data from CSV files you upload (e.g. KBC exports).
Budget dataThe budgets, categories and classifications you create.
Technical & usageLog data needed to operate and secure the Service (e.g. timestamps, error and access logs, rate-limiting counters).

3. How and why we use your data (legal bases)

PurposeLegal basis (GDPR Art. 6)
Provide the budgeting features you requestPerformance of a contract
Access your bank account informationYour explicit consent (and PSD2 account-information access)
Automatically categorise transactionsPerformance of a contract; see “Automated classification” below
Authenticate you and secure the ServiceLegitimate interest; legal obligation
Process subscription payments (if applicable)Performance of a contract

4. Bank account access (PSD2 / Account Information Service)

When you connect a bank account, you are authorising read-only access to your account information through Enable Banking, a licensed Account Information Service Provider (AISP), under the EU’s PSD2 framework. Key points:

5. Automated classification (transaction text sent to Anthropic)

To suggest budget categories, the text of your transactions (such as the description, merchant and counterparty name) may be sent to Anthropic (the provider of the “Claude” AI model) for classification. This processing produces a suggested category only; it is not used to make decisions with legal or similarly significant effects about you. We do not send your name, login credentials or full account numbers for this purpose beyond what appears in the transaction text itself.

6. Who we share data with (processors)

We do not sell your personal data. We share it only with service providers that process it on our behalf, under contract, to run the Service:

ProviderPurpose
Enable BankingConnecting to your bank and retrieving account information (AISP)
AnthropicAI-based transaction categorisation (see section 5)
StripeSubscription billing and payment processing (if you subscribe)
ResendSending transactional emails (e.g. verification, notifications)
TwilioSending 2FA codes by SMS
DigitalOceanCloud hosting infrastructure

Some of these providers (e.g. Anthropic, Stripe, Twilio) may process data outside the European Economic Area. Where that happens, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

7. How long we keep your data

We keep your account and financial data for as long as your account is active. If you close your account, we delete or anonymise your personal data within a reasonable period, except where we must retain certain records to comply with legal obligations. Temporary data (such as 2FA codes) is auto-expired within minutes.

8. How we protect your data

9. Your rights

Under the GDPR you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and to withdraw consent at any time (which does not affect processing already carried out). To exercise any of these, email admin@tecron.be.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), dataprotectionauthority.be.

10. Cookies and local storage

We use only the storage strictly necessary to operate the Service (for example, keeping you signed in and remembering your language preference). We do not use third-party advertising or tracking cookies.

11. Children

The Service is not intended for children under 16, and we do not knowingly collect their data.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notifying you.

13. Contact

Tecron — admin@tecron.be