Privacy Notice
Scope and controller
This notice covers personal data processed when MKAB Cashflow connects to a company bank account and uses the resulting information for internal financial administration. It is made available before an account is connected.
Mikhail Kalkov AB, organisation number 559148-2939, is the controller for the processing described here after account information is delivered to the service. Contact: mikhail.kalkov@gmail.com.
People and information covered
The information may concern authorised account users and company representatives, as well as employees, customers, suppliers, and other natural-person counterparties identified in payment records.
The service may process account identifiers such as IBAN or account hashes, balances, transaction dates and status, amounts, currency, payment references and descriptions, and counterparty names and account details. It also processes authorization and session metadata needed to maintain the connection.
Public web security logs may contain an IP address, request time, HTTP method, sanitized path without query parameters, response status, and user agent. Callback requests containing authorization codes are not written to access logs.
Payment descriptions may incidentally reveal personal circumstances. The service does not use transaction data to infer sensitive traits or build profiles. BankID credentials are never collected or stored.
Sources
Account information comes from the selected bank through Enable Banking Oy. Information about employees, customers, suppliers, and counterparties is obtained from the company account's transaction records rather than directly from each person. Technical log information comes from requests to this website.
Purposes and legal bases
- Bookkeeping, tax records, and other required financial administration are processed to comply with Swedish legal obligations.
- Cash-flow forecasting, reconciliation, data-quality checks, service operation, and protection against technical abuse are processed for Mikhail Kalkov AB's legitimate interests in accurate financial management and a secure internal service.
For legitimate-interest processing, access is restricted to company needs, data is not sold or used for advertising, and the impact on affected people is limited through data minimisation, retention limits, and the rights below. The bank authorization permits technical account access; it is not relied on as GDPR consent for Mikhail Kalkov AB's subsequent processing.
Providers and recipients
Enable Banking Oy, located in Finland and regulated as an account information service provider, handles bank authorization and delivers account information. It is responsible for processing required under its own regulated service and privacy notice. The selected bank participates in authorization and supplies the account information.
Within Mikhail Kalkov AB, access is limited to authorised personnel who need the information. Hosting, backup, and security providers may process limited data under contractual and confidentiality obligations. Information may also be disclosed to accountants, auditors, banks, or public authorities when necessary for the stated purposes or required by law.
International transfers
MKAB Cashflow is designed to store its banking data in Sweden and does not intentionally transfer that locally stored data outside the EEA. If a service provider uses a recipient outside the EEA, the transfer must be covered by an adequacy decision or appropriate safeguards under Chapter V GDPR. Information about an applicable safeguard and how to obtain a copy is available from the contact address above.
Retention
- Active authorization secrets are kept only while access remains valid. They are reviewed and deleted no later than 30 days after expiry or revocation.
- Transient API snapshots are deleted after successful import and reconciliation, and no later than 90 days after collection, unless a specific item must be retained as accounting evidence.
- Information that forms part of the company's accounting records is kept for seven years after the end of the calendar year in which the relevant financial year ended, or longer only where another legal requirement applies.
- Minimised web security logs are retained for no more than 30 days. Backups follow the same purpose-based periods and are removed through the normal backup-expiry cycle.
Choice and automated processing
Providing bank access is voluntary. Refusing or revoking access does not affect the bank account, but MKAB Cashflow cannot automatically update its forecasts and reconciliations from that account.
No automated decision-making or profiling that produces legal or similarly significant effects is performed. Automated calculations remain subject to human review.
Your rights
Subject to the conditions and exceptions in applicable law, you may request access, correction, erasure, or restriction of your personal data. You also have the right to object to processing based on legitimate interests and the right to data portability where its legal requirements apply.
Send a request to the contact address above. Identity may need to be verified before information is disclosed. Requests are answered without undue delay and normally within one month. Some information cannot be erased while a legal retention duty applies.
You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
Managing bank access
Active data-sharing authorizations can be reviewed or terminated through the bank or through Enable Banking's consent management page. Revocation stops future retrieval after it takes effect. It does not invalidate earlier lawful processing or remove records that must be retained by law.
Security
Security measures include restricted access, encrypted transport, short-lived authorization callbacks, local protection of credentials, and minimised logging. No internet service can be guaranteed completely secure; suspected unauthorised access should be reported promptly.
Changes, cookies, and tracking
The effective date above identifies the current version. Material changes will be communicated to active authorised users before they take effect where reasonably possible.
These information pages contain no tracking code, advertising, or cookies.