The most sensitive document about you.
Your credit report says more about you than any reference. That is why security at FIAON is not a page in the legal notice but the blueprint: nothing without your authorisation, nothing without your approval, nothing longer than necessary.
Five principles
Authorisation: no report without your signature. Approval: no letter without you. Purpose limitation: your data serves your file, never advertising. Access: every access logged. Deletion: complete on request after the contract ends. Payments run by SEPA through a verified creditor; no card data at FIAON.
Under the bonnet
Servers in the EU with a GDPR data processing agreement, HTTPS with TLS 1.3 and HSTS, encrypted database and backups, documents stored separately from the profile, role-based staff access with logging, no customer data in the AI assistant, retention until the end of the contract plus 90 days.
Your rights
Access under Art. 15, rectification under Art. 16, erasure under Art. 17 GDPR — in the customer area or by e-mail, confirmed within 30 days.
- Privacy check: six questions on who may do what with your credit data
- No data used for AI training
- Data breach: notification within 72 hours (Art. 33, 34 GDPR)
Frequently asked questions
May a bank query my SCHUFA data without my knowledge?
Only with a legal basis — usually your consent in the application (SCHUFA clause) or a legitimate interest when a contract is being initiated. Every query appears as an enquiry in your data copy, with date and recipient.
May my landlord demand a credit report?
They may ask for it; you do not have to provide it — in practice it is common, though. Provide the credit report for landlords (without details), never the full data copy.
May a debt collector report my data to SCHUFA?
Only under the conditions of Section 31(2) BDSG: a due, undisputed claim, two reminders, a notice of the report. If one of these is missing, the report is unlawful.
May FIAON pass my report on to third parties?
No. FIAON passes data on only if you approve it for a specific purpose — for instance the documents for a card application to the card partner. Never for advertising, never sold.
May I demand the deletion of my data at FIAON?
At any time (Art. 17 GDPR). After the contract ends we delete report and documents; statutory retention obligations for invoices remain (ten years, accounting data only).
May a credit bureau use data from social networks?
Not under the credit bureaus' code of conduct; the draft scoring law (2024) is meant to prohibit it explicitly, as well as data on origin, health or address as a score criterion.
Does FIAON see my online banking?
No. You upload a bank statement as a photo or PDF. Account connection (open banking) is coming as an option — explicitly enabled by you, revocable at any time.
Who is responsible for data protection?
FIAON LTD, 128 City Road, London, EC1V 2NX, United Kingdom. Data protection requests to support@fiaon.com. Competent supervisory authority for customers in Germany: the state data protection authority of your place of residence.
Is my data used for AI training?
No. Personal data is not used to train models. Anonymised experience (which letters work) improves templates — without names, without references.
What happens in the event of a data breach?
Notification to the supervisory authority within 72 hours and information to those affected if there is a risk (Art. 33, 34 GDPR). There is a plan for that, not improvisation.
Can I use FIAON without uploading documents?
The report can be obtained with authorisation; the financial analysis needs the bank statement, account and card need your ID. What you do not upload stays out — and we tell you what then is not possible.