About this Privacy Statement

Flinks allows you to share your bank account details and transaction history, among other financial information, in order to receive financial or other related goods and services from our clients.  This Privacy Statement provides information as to Flinks and its affiliates’ (“Flinks”, “we”, or “us”) practices as it relates to the collection, use, disclosure, storage, or destruction (collectively referred to as “process” or “processing”) of personal information (i.e., identifiable information about you) Flinks receives in connection with your use of any of our clients’ services that use Flinks.  

This Privacy Statement has been divided into the following sections to explain:

  • Scope
  • Types of Personal Information We Process
  • Consent
  • How We Use Your Personal Information
  • Who We Share Your Personal Information With
  • Our Use of Service Providers
  • Your Rights and Making a Data Subject Request
  • Contacting Flinks’ Privacy Officer
  • Changes to This Privacy Statement

Scope 

This Privacy Statement applies to the processing of personal information by Flinks when you connect your bank or other financial account, using Flinks, with our clients’ services.  

The Flinks Services Privacy Statement applies to the following services:

This Privacy Statement does not apply to the following activities:

  • Personal Information subject to Flinks’ General Privacy Policy. If you are a visitor to Flinks’ website, a service provider to Flinks, an actual or prospective client, an attendee at one of Flinks’ events, or have attended Flinks’ offices, the General Privacy Statement is where you will find information related to Flinks’ practices with respect to the processing of your Personal Information.
  • Personal Information collected about you by our clients.  Our clients are responsible for implementing relevant procedures and determining how they process your personal information in order to provide their services, including how they use Flinks.  Should you wish to find out more about how our clients process your personal information, or to understand what other personal information they have in their possession related to you, we encourage you to visit their website or contact their data protection officer directly.  
  • Personal Information you provide to websites or services not controlled by Flinks.  Flinks may provide you with links to our clients’ website(s) or social media page(s) Flinks uses through our website. Flinks does not have any control over these websites, or the marketing or other technologies such websites may deploy.   Should you have any questions related to these websites, please contact Flinks’ Privacy Officer for how Flinks may use such information, or refer to such websites’ respective privacy policies for how they process your personal information.

Types of Personal Information We Process

Flinks processes the followingtypes of personal information when it provides its services to its clients:

Information you provide through Connectivity. When you connect your financial account(s), you will provide your login information required by your financial institution to access your account. Typically, this consists of a username and password, but it could also include answers to challenge questions (e.g., a family member’s name or maiden name, street you grew up on), or a security token (e.g., multi-factor authentication code or one-time pad (OTP)).  Information you provide may also consist of digital copies of bank statements, cheques, or other financial documents where you are sharing these types of documents through Flinks Connectivity with one of our clients.

Information obtained from your financial institution. When Flinks connects to your financial account for the purposes of our clients’ services, we retrieve information from such financial institution that maintains the account(s). The information we retrieve may vary depending on:

  1. The information required by our client in order to power their service; and
  2. The information made available by your financial institution.

Regardless of the types of information our clients require, the types of information we collect from your financial institutions will include, without limitation: 

  • Account information (e.g., financial institution name, account name, account type, and account and routing number);
  • Information about an account balance (e.g., current and available balance);
  • Information about credit accounts, (e.g., statement due dates and balances owed, payment amounts and dates, transaction history, and interest);
  • Information about loan accounts (e.g., including due dates, balances, payment amounts and dates, interest, loan type, payment plan, and term);
  • Information about the account owner(s) (e.g., name, email address, phone number, and address information); and
  • Information about account transactions (e.g., amount, date, type, and a description of the transaction).

Information from your payroll or paystub provider. In addition to the ability to connect to your financial institution through our Connectivity Service, Flinks also has the ability to connect to your payroll or paystub provider.  This allows Flinks to provide its clients with an up-to-date picture of your sources of income in addition to what is available from your financial institution.

Information you provide through Flinks Pay.  Whether accepting an Interac e-Transfer Request for Money or entering into a pre-authorized debit (PAD) agreement with one of our clients for electronic fund transfers (EFTs), you will be required to provide certain information, namely:

  1. For Interac e-Transfers: your name and e-mail address. 
  2. For EFTs: Your name, address, e-mail address, bank account number, routing number, institution number, and transit number.  

This information may be collected directly by our clients, or for EFTs, through our Connectivity Service to help populate a PAD agreement and signing an electronic or paper copy of the PAD agreement. 

Information from your devices. Our technology is integrated as part of  our clients’ services. Thus, when you use one of your devices to connect with a client service, we may receive information about this device, including without limitation the IP address, hardware model, operating system, and other technical information about the device. We may also use cookies or similar tracking technologies to collect usage statistics and to help us improve our services.  

Consent

As a service provider to our clients, Flinks has no direct relationship with you, the end-customer.  As such, our clients are responsible for obtaining the necessary consent(s) from you to process your personal information for the purposes associated with providing you with their goods or services, including your consent that authorizes Flinks to (i) collect Information you provide and (ii) collect and share Information from your financial institution with our clients, and (iii) collect and share Information you provide through Flinks Pay.  Flinks does have a consent screen available to clients through Flinks’ Connectivity service that takes steps ensure you understand who Flinks is and how we process your personal information.  For further information as to why you have been directed to Flinks, and for what purposes the personal information Flinks receives and provides to its clients will be used for, please refer to the privacy practices and policies of the business who uses our services.

Collection of Personal Information of Children

Flinks does not market or target its services towards children (individuals under the age of 16), or any individual for that matter.  Flinks is a business-to-business service provider, and as such, Flinks will not knowingly collect or ask for personal information belonging to children.  Should a child connect a financial account with one of the services of Flinks’ clients, Flinks relies on the steps taken by its clients to ensure that the proper consent(s) are obtained from a parent or guardian, as Flinks will have no direct customer relationship with the child.

How We Use Your Personal Information

When we receive personal information from you, or from your financial institution related to you, we use your information for the following purposes:

  • To operate, provide, and maintain our services;
  • To improve, enhance, modify, add to, and further develop our existing services;
  • To protect you, our clients’ services, and Flinks from actual or potential fraud, malicious activity, and other privacy and security-related concerns;
  • To provide support to our developers;
  • To respond to your inquiries related to this Services Privacy Statement, should you make a request under Your Rights;
  • To investigate any misuse of our service or our clients’ service(s), including violations of our security policies, criminal activity, or other unauthorized accesses.

Where our clients use Flinks’ Enrichment service, we will also use your personal information to derive certain insights or make certain inferences related to your financial position.  Through our Enrichment product, Flinks is able to derive insights and inferences from the Information from your financial institution in order to help our clients in gaining insights into things such as:

  • Fraud detection;
  • Credit risk analysis based on sources of income and transaction history;
  • Ability to pay a loan based on sources of income and transaction history;
  • Customer segmentation based on attributes selected by the client;
  • Insights into an individual’s overall account information (e.g., monthly income, monthly spend, account age, days with a negative balance, unusual transactions)

These insights only apply to those clients who use Enrichment.  If you are uncertain whether or not the service that directed you to Flinks uses Enrichment, please reach out to the company whose services you used that uses Flinks, or refer to their privacy policy to understand how they may be using Enrichment.

Who We Share your Personal Information With

When you use Flinks’ Connectivity service to share your financial information with our clients (i.e., the organization with whom you have a direct relationship with that uses Flinks), depending on the type of connection that needs to be made with your financial institution, you may be providing Flinks with your account credentials to access your bank account.  

As a starting point, your credentials are never shared.  With anyone.  

Due to the sensitive nature of the Information you provide and Information obtained from your financial institution, Flinks does not share any of your personal information with anyone other than our client whose service(s) you are using and have authorized to receive your financial information, with our service providers for the purposes of providing our clients with our services (as outlined in Our Use of Service Providers below), and as required or permitted by law (e.g., in the event Flinks must comply with a court order or is required to disclose information to protect an individual from serious or life threatening harm). In the event a part of Flinks, or all of Flinks is acquired or merged with another business, the license(s) or ownership associated with the services we use to process your personal and financial information, and any other such information Flinks processes, may be transferred to the new entity.  

For Flinks Pay, Flinks will share the Information you provide through Flinks Pay with the following organizations for the purpose(s) listed:

Organization

Purpose(s)

Peoples Group

  • Facilitating money transfers between your financial institution and Flinks’ deposit account, and/or the bank account of our client.

Interac

  • Facilitating Interac e-Transfers.

ComplyAdvantage

  • Fraud Detection; and
  • Know Your Business (KYB) / Know Your Client (KYC) checks.

Flinks’ Third Party Auditors

  • Review of suspicious transactions; and
  • Audit of policies and procedures related to Flinks Pay, including KYB/KYC practices.

Where Flinks has reason to believe that a suspicious or illegal transaction has occurred through Flinks Pay that may violate the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (Canada) or other applicable law(s), Flinks will report information about you and any associated transaction(s) to the Financial Transactions and Reports Analysis Centre of Canada (“FINTRAC”) and any other law enforcement or regulatory body as required, as well as Flinks’ parent company, National Bank of Canada (“National Bank”) as part of Flinks’ ongoing risk management and reporting obligations to National Bank.

Our Use of Service Providers

We will store the Information you provide and Information obtained from your financial institution for as long as it is necessary to provide our clients with our services.   Depending on our clients’ use case(s) for Flinks’ services, the duration for which we store your personal information may vary.  

Flinks uses industry leading service providers to process your personal information (also sometimes referred to as “subprocessors”). At no point will these service providers exercise any control over how personal information is used. With all of our service providers, contractual provisions and technical measures are in place to ensure that, among other things, your personal information is stored in secure environments, that the confidentiality of your personal information is maintained, and that no employees of our service providers may access the environments containing your personal information except with the express authorization from Flinks for the purposes of carrying out maintenance or support and under confidentiality terms equal to the confidentiality terms Flinks has entered into with its clients.  Flinks uses the following categories of service providers in the provision of its services:

  • Cloud-based infrastructure for the development and hosting of Flinks’ services and personal information;
  • Cloud-based identity management; and
  • Service providers that provide optical character recognition and document processing capabilities as part of Flinks Connect;
  • Other data aggregators who provide similar services to Flinks, who provide redundancies in the event of an outage, or access to financial institutions or data Flinks may not have connectivity with.

For residents of the Province of Québec, this may mean that your personal information is stored in data centres located outside of the province.  Should you wish to learn more about the service providers we use, please contact Flinks’ Privacy Officer.

To learn more about how we store and protect your personal information, please visit our Security page.

Your Rights and Making a Data Subject Request

Depending on where you reside, you may be entitled to exercise certain rights with respect to your personal and financial information.  At Flinks, we want all of our clients’ customers to have equal privacy rights, and that’s why no matter where you reside, we will use our best efforts to afford you the same rights as others, even where we aren’t required to.

Specifically, Flinks recognizes that individuals have the following privacy rights:

  • To Access Your Personal Information.  Where Flinks has collected personal information pursuant to this Privacy Statement, you have the right to access the records Flinks holds containing your personal information.  
  • To Correct Your Personal Information.  If you believe Flinks holds inaccurate or out-of-date personal information related to you and you would like Flinks to update its records, then you have the right to request correction of those records.  
  • To Withdraw Your Consent (otherwise known as “Opting-Out”). Should you choose to withdraw your consent that permits Flinks to process your personal information, please indicate for which purpose(s) you wish Flinks to stop Processing your personal information (e.g., for a particular purpose, or for all purposes).  Prior to fulfilling your request, we may inform you of any consequences that withdrawing your consent may have in relation to receiving services pursuant to this Privacy Statement.
    Please note that withdrawing your consent is not the same as requesting that Flinks delete any personal information, and Flinks may continue to hold your personal information pursuant to any business (e.g., retention) or legal requirements where deletion has not also been requested.
  • To Delete Your Personal Information.  If you no longer want Flinks to hold personal information related to you that is subject to this Privacy Statement, please indicate the specific records, or the types of records containing your personal information you would like Flinks to delete and Flinks will destroy those records subject to any legal or regulatory obligations that might prevent such destruction permanently.
  • To Make a Complaint. In the event you believe Flinks has collected, used, disclosed, or taken any other action(s) in regards to your personal information that you believe may not comply with this Privacy Statement or otherwise with applicable privacy legislation, then you are entitled to make a complaint to a regulatory authority (e.g., Office of the Privacy Commissioner of Canada, Commission d’accès à l’information du Québec). You may first contact Flinks’ Privacy Officer with the details of your complaint to inform Flinks of such activities, and potentially resolve the issue.  Flinks’ Privacy Officer may contact you with a proposed resolution, and if you are not satisfied with the proposed resolution and there is no alternative from Flinks’ perspective, then you are still entitled to file a formal complaint with the relevant regulatory body.  

 

Because Flinks has no direct relationship with you in providing our Services to our clients, we ask that you direct your request(s) that are related to Flinks’ processing of your personal information to the client with whom you have connected your financial account with.  In your request to them, please be sure to copy Flinks’ Privacy Officer on your e-mail ([email protected]) and indicate:

  • that you would like your request to be directed to the information Flinks processed on behalf of the company;
  • the right(s) you wish to exercise; and
  • if applicable, the specifics of your request (e.g., the records you are requesting access to, or the purposes for which you are withdrawing your consent).

If you are unsure of who to contact in order to make your request, please reach out to Flinks’ Privacy Officer and they will be able to assist you in facilitating your request.

You may be asked by our client to verify your identity by answering some questions (e.g. name, e-mail address registered with client, or other identifying information). Flinks may also request that your identity first be verified before processing your request.  In the event Flinks receives a request from a parent or guardian on behalf of an individual, Flinks or our clients may also ask for further information to prove the relationship before facilitating the request.

Our clients have the capability to fulfill any of your requests as it relates to Your Rights and the personal information processed by Flinks through our services.  Where our clients require assistance in fulfilling any request, we will provide the necessary assistance to fulfill your request. While our clients are responsible for facilitating your requests, Flinks’ Privacy Officer will nonetheless endeavour to assist in making sure  your request is processed within 30 days of your request being received and may notify you once your request has been completed. If an extension is required to respond to or facilitate your request, Flinks’ Privacy Officer or the organization using Flinks’ services will inform you of such an extension and the reasons for it nevertheless within the first 30 days.

Flinks reserves the right to refuse to address requests, questions, or complaints if, in the opinion of Flinks’ Privacy Officer, such request, question, or complaint is vexatious, unfounded, or repetitive in nature. 

Contact Flinks’ Privacy Officer

For any of Your Rights listed above, or any other inquiries related to this Privacy Statement or other privacy-related inquiries related to Flinks or its services, please direct all inquiries to Flinks’ Privacy Officer at [email protected].

Updates To This Policy

This Services Privacy Policy was last updated on April 19, 2024. From time to time, Flinks may update this Services Privacy Policy to reflect changes to Flinks’ services or purposes for which Flinks processes personal information, or to comply with new legal requirements.

Whenever Flinks makes an update to this Policy, Flinks will update its website to provide notice that changes have occurred, and direct individuals to the updated Services Privacy Statement.