Trust centre
Reviewed on 27 September 2026
This is what a company usually asks before connecting its banks: who processes the data, where it is, how it is protected and which certifications exist. Each item carries the date until which we stand by it; if that date passes without a review, the page flags it on its own instead of still claiming it.
Who processes the data
The providers involved in the service and where they are. The detail of what each one receives, the contracts and the change history are on the sub-processors page.
| Provider | What it does | Location | Safeguard |
|---|---|---|---|
|
Wealth Reader, S.L.
NIF B44575942 |
Connects with the bank, reads the accounts and delivers balances and transactions to us. Account Information Service Provider authorised by the Bank of Spain, no. 6939. | Spain (infrastructure on Google Cloud, European Economic Area regions: Madrid) | Processing agreement in Annex I of the framework contract between Wealth Reader and ONNA Digital |
| ONNA Digital | Holds the contract with Wealth Reader through which access is provided. It does not receive the bank data. | Not applicable: it does not host the bank data | Processing agreement with EasySoft Tech S.L.: in preparation |
| Contabo GmbH | Hosting of the application and the database | Germany | Processing within the European Union |
| Dinahosting SL | Email: the service's notifications and the [email protected] mailbox | Spain (data centre in Madrid) | Processing within the European Union |
| Cloudflare, Inc. | Domain name resolution (DNS) and the network through which the easybankdata.com traffic passes | Global network | Its data processing agreement, with the mechanisms of Chapter V GDPR |
Wealth Reader's providers
Wealth Reader passes on those of its own chain. For their changes we depend on the notice it gives us.
| Provider | What it does | Location | Safeguard |
|---|---|---|---|
| Google Cloud | Hosting of Wealth Reader's infrastructure | European Economic Area regions (Madrid, Spain) | Processing within the European Economic Area |
| Google LLC | Maintenance and support of that infrastructure, with possible remote access | United States and other countries | Towards the United States, the EU-US Data Privacy Framework |
Change notices
If you want to know before this list changes, leave us your email. We will write to you at least 30 days before a provider is added or replaced, with its name, what it does and where it is.
We only keep your email and whether you confirmed it, and only for this notice. We send you a link to confirm it; if you do not open it, we delete it. Every notice has its unsubscribe link. More in the privacy policy.
Certifications
The ones that actually exist, with their number, their scope exactly as the certificate states it, and how long they are valid.
EasySoft Tech S.L. does not currently hold any security certification of its own.
| Holder | What | Scope | Validity |
|---|---|---|---|
| Wealth Reader, S.L. |
ISO/IEC 27001
AENOR, no. SI-0102/2023 |
“agregación de activos financieros” (literal wording of the certificate: financial asset aggregation) | Valid until 3 October 2026 |
| Google LLC |
EU-US Data Privacy Framework
US Department of Commerce |
Covers remote access by Google LLC for maintenance and support of Wealth Reader's infrastructure. | Valid until 13 September 2027 |
How we protect the data
What the system does today. The time limits come from the same configuration the purge uses, so if one changes, it changes here too.
- What identifies someone in a transaction —the description, the counterparty's name and account— and each account number are stored encrypted (AES-256) with a dedicated key, separate from the application key. Amounts and dates are not encrypted, so they can be added up and sorted.
- What the provider delivers as it arrives (the original payload) is deleted after 30 days, and so are uploaded statements.
- The identity of transaction counterparties is masked 30 days after arrival; the entry itself (date, amount and balance) is kept.
- Attachments, statements, PDF reports and portability packages are stored encrypted and outside what the web server serves. Reports are deleted after 7 days and portability packages after 7.
- Two-factor authentication (TOTP, with recovery codes) for every account. Each company can make it mandatory for its team, and it is mandatory for EasySoft Tech S.L. support staff.
- Support sees the state of the service, not your transactions. To look at them it needs an authorisation from you that expires on its own, and it enters in read-only mode.
- Every look at bank data is logged: who, when, from where and on what, without copying the data.
- API keys are stored as a digest (SHA-256), never in clear text, and every notification (webhook) is signed with HMAC-SHA256 with the timestamp inside what is signed.
- EasySoft Tech S.L. does not send your data to any artificial intelligence provider and does not use artificial intelligence to process your bank data.
Data processing agreement (DPA)
The data processing agreement is being prepared. If you need it now, write to us at [email protected] and we will tell you where it stands.
Contact
For any question about this page, the providers or your data: [email protected].