Integration Data Access Terms

Growing Branches Oy — Omadata

Purpose

These terms govern how Omadata accesses third-party data on your behalf when you connect a provider (bank, accounting system, wearable device, or mailbox) to your Omadata account.

Explicit consent

Omadata only accesses provider data after you explicitly authorise the connection. You will be redirected to the provider's authentication page and must grant read-only access before any data is retrieved.

Scope of access

Omadata requests only the minimum permissions required: read-only access to account data, balances, transactions, and activity data. We never request write permissions, payment initiation, or access to data beyond what you explicitly authorise.

Token storage

Provider access tokens are encrypted at rest using AES-256 (Fernet symmetric encryption) and never stored in plaintext. Tokens are used only to perform scheduled data refreshes on your behalf.

Data refresh

Data is refreshed automatically according to the cadence you configure for each flow. You can change the cadence or disconnect any provider at any time from the Flows page.

Disconnecting

You can revoke any provider connection at any time. Revoking a connection deletes the stored access token and stops future data refreshes. Historical data already collected is retained until you delete your account or request data erasure.

PSD2 compliance

Bank connections for Finnish and Nordic banks are processed through Tink AB (a Visa company), a licensed Account Information Service Provider (AISP) under EU Directive 2015/2366 (PSD2). Growing Branches Oy is pursuing its own AISP registration with Finanssivalvonta.

Growing Branches Oy · [email protected]