PRIVACY POLICY

At AvaFin Holding Ltd we are strongly committed to protecting and respecting your privacy in compliance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”). This Privacy Policy applies to all personal data collected or submitted by you during any written, electronic, or oral communications with us, in connection with your activity on AvaFin Holding Ltd websites, or when you otherwise interact with us through other online or offline means. This Privacy Policy may be supplemented by additional privacy statements, terms or notices provided to you. Please, be aware that our website may contain links to the websites of other partners and/or AvaFin Holding Ltd entities, and those websites have their own privacy policies. We do not accept any responsibility or liability for these policies unless required by law.

By submitting your personal data to us, you agree to this Privacy Policy. Moreover, when you provide personal data to us, you represent that the data is true, accurate, complete and up to date. In the event that you provide us with personal data from a third party (proxy holders or advisors), you represent that you have previously collected their consent, and also you commit yourself to inform them about the content of this Privacy Policy before the communication.

We recommend that you read this Privacy Policy in detail, and you visit it regularly as it may it be updated from time to time. If you need assistance or have any enquiry, you can contact our Data Protection Officer at dpo@avafin.com or by postal service to the address mentioned below.

For clarity, throughout this notice ‘AvaFin’ ‘we’ and ‘us’ and ‘our’ refers to AvaFin Holding Ltd; and ‘AvaFin Group’ refers to AvaFin Group’s holding company and its affiliates, directly or indirectly, controlled by the holding company.

Data Controller AVAFIN HOLDING LTD, with Reg. Number: HE335345, TAX No. CY 10335345O, and address at 40 Kimonos Street 3095, Limassol, Cyprus. Data Protection Officer (DPO) email address: dpo@avafin.com
Purpose(s) Answering questions and enquiries; management of investors relations; marketing and public relations; running public events, meetings and conferences; recruitment on our behalf or on behalf of AvaFin Group’s entities (as data processors); operating and managing lending operations of AvaFin Group lending companies; managing internal administrative purposes and compliance; and running the whistleblowing system.
Recipient(s) Public authorities, AvaFin Group’s entities or other third parties necessary for the performance of the entrusted activities.
Data retention Depending on the circumstances, we may be legally required to keep personal data for a specified period of time to comply with the law.
Automated individual decision-making Yes
Rights of the individual You can exercise your right to access, rectifiy, erase or restrict the processing of your personal data, to object, not to be subject to automated decisions (including profiling), to portability; by contacting us at the following e-mail address: dpo@avafin.com.
User User means any natural person who accesses, uses, or interacts with AvaFin Group’s websites, digital platforms, mobile applications, products, or services, including individuals who submit inquiries, request information, communicate with the Group, or otherwise provide personal data in connection with AvaFin Group’s activities. The term also includes prospective customers, existing customers, representatives acting on behalf of third parties, and any individuals whose data is processed in the context of the Group’s services.

1. Data Controller

The data controller is AVAFIN HOLDING LTD.

Please note that our subsidiaries may also act as either independent controllers or joint controllers of your personal data with us depending on our relationship and the business activities we are carrying out. For all matters related to privacy and the processing, use, and storage of your personal data by AvaFin Group entities, as data controllers, please visit the corresponding privacy policies available on their websites.

Data Protection Officer email address: dpo@avafin.com.

List of AvaFin Group entities

  • AvaFin Holding Ltd.: 40 Kimonos Street, 3095 Limassol, Cyprus. Registration Id: HE 335345.
  • AvaFin Latvia SIA: Skanstes street 12, Riga, LV-1013, Latvia. Registration Id: 40103283854. https://www.avafin.lv/
  • AvaFin Software SIA: Skanstes street 12, Riga, LV-1013, Latvia. Registration Id: 40103704007.
  • AvaFin Czech, s.r.o.: Jankovcova 1566/2b, Prague 7 – Holešovice, 170 00, Czech Republic. Registration Id: CZ24849707. https://www.crediton.cz/
  • Available Finances S.A. de C.V.: Dante 36, Piso 5, Col. Anzures. Delegación Miguel Hidalgo, Ciudad de México, C.P 11590. México. Registration Id: 558584-1. https://www.avafin.mx/
  • AvaFin IT GmbH: Domplatz 16/2, 2700 Wiener Neustadt, Austria. Registration Id: FN416590H.
  • AvaFin Spain, S.L.U.: Avenida Diagonal 508, 1 – 6, 08006, Barcelona, Spain. Registration Id: B71087472. https://www.avafin.es/
  • AvaFin Poland Sp. z o.o.: ul. Bukowińska 22 B, 02-703 Warsaw, Poland. Registration Id: 0000453034. https://www.avafin.com.pl/
  • RRM LTD: Suite 12, Businesslabs, Level 1, DunKarm Street, Birkirkara, BKR 9037, Malta. Registration Id: C67652.
  • Kancelaria Prawno-Windykacyjna Lex Actum Sp. z o.o.: ul. Hoża 86/410, 00-682 Warsaw, Poland. Registration Id: 0000728341.

2. Which categories of personal data do we collect?

We might collect data from you in connection with your activity on AvaFin Group websites or when you interact with us through other online or offline means. Sometimes you give your personal data to us directly (e.g. when you contact us to ask a question or apply for a job position), we automatically collect it ourselves (e.g. using cookies) or we receive your data from third parties, including AvaFin Group’s lending companies (e.g. when you submit a loan application), or from publicly available sources.

Categories of personal data collected Examples
Identification data Name, surname, national ID number, passport number, or tax identifications number.
Contact details Email address, telephone number, and physical address.
Social characteristics Information such as nationality, gender, age, marital status, date of birth, and place of birth.
Financial information Including credit card and bank account details (e.g. account owner, income, earnings, and expenses), tax-related information, and credit scores following creditworthiness assessments.
Credit bureau information Credit histories, credit scores, outstanding debt levels, and repayment behaviour.
Loan-related information Data from loan applications, including application details, loan terms, approval or rejection status, and any related correspondence or communications generated throughout the management of the loan agreement. This also encompasses records associated with debt collection processes.
Work-related information Details of previous and current jobs, including company names, roles, and durations of employment; job position and responsibilities; skills and competencies; payroll and non-economic data; etc.
Academic background Educational qualifications (e.g. diplomas, degrees, or certifications), academic institutions, areas of study or specializations, professional licenses or accreditations (e.g. bar membership for lawyers, CPA for accountants, etc.).
Behavioral data Information about individual interests, habits, satisfaction levels, marketing preferences, and newsletter subscription details, and other related quantitative or qualitative data.
AML/CFT information Due diligence information (e.g. KYC, screening, transaction monitoring), and other AML/CFT-related information disclosed, obtained through third parties or generated internally during investigations.
Information from public events Image and voice recordings; attendee information and preferences.
Technical data when browsing the website IP address, browser type, Internet provider, character encoding, time zone, location, operating system, access devices, output and browsing the web, pages of reference and output, viewed files (HTML, graphics, etc.), page response times, download errors, duration of visits, methods used to leave the page.
Other data Other personal data provided by you in open forms, when you interact with us, or collected from third parties, such as AvaFin Group’s entities.

3. Methods of Obtaining Personal Data

a) Personal data obtained directly from the User

The AvaFin Group collects personal data in two primary ways. The first involves information provided directly by the User, including in particular:

  • submitting a message via the contact form available on the AvaFin Group’s website (www.avafin.com),
  • using products or services offered by the AvaFin Group,
  • contacting the AvaFin Group to obtain information about services or to receive technical support.

b) Personal data obtained from other sources

The AvaFin Group also obtains personal data from sources other than the User, including:

  • data generated through the User’s interaction with the AvaFin Group products and services, collected via cookies and similar technologies, as well as error reports or usage data from software running on the User’s device,
  • data brokers, from whom the AvaFin Group may purchase demographic or supplementary information,
  • service providers supplying the AvaFin Group with location-related data based on Users’ IP addresses,
  • business partners with whom the AvaFin Group jointly offers products, services, or conducts marketing activities,
  • publicly available sources such as public registers or databases,
  • entities involved in processing payments or transactions, credit rating agencies, other financial institutions, commercial companies, or public authorities,
  • creditworthiness assessment sources, for information about financial obligations or scoring.

Personal data may also originate from additional sources, including legal representatives, attorneys under granted powers of attorney, business entities transferring data, employers, and contractual partners of the AvaFin Group.

4. For what purposes do we use your Personal Data and on which legal basis do we rely?

We take the collection, usage and security of your personal data seriously, and we can only use your personal data under law if we have a valid reason for doing so. Please note that we may also use personal data for other purposes with your consent. Depending on the circumstances and purposes indicated below, AvaFin may rely on your consent or the fact that the processing is necessary for the performance of a contract with you, or our legitimate interests, or to comply with legal obligations. Where we rely on our legitimate interests for a given purpose, it is our understanding that our legitimate interests are not overridden by your interests, rights or freedoms, given (i) the transparency we provide on our data processing activities, (ii) our data protection by design and default approach, (iii) our routine data protection reviews, and (iv) the rights you have in relation to our data processing activities.

Note that when you act on behalf of a company or other legal entity, we may process your personal data in relation to your position to engage into a business relationship with your company based on our legitimate interest.

List of processing activities

Processing activity Legal grounds
Answering questions and enquiries: We will respond to your enquiries and requests submitted through the contact form on our website or through any other communication channels you choose to use to reach us. Depending on the nature of your request, we may process your data based on our legitimate interest under Article 6(1)(f) of the GDPR, or as necessary to take steps at your request prior to entering into a contract under Article 6(1)(b) of the GDPR.
Managing investor relations: We will conduct the following activities: (1) Organize and facilitate shareholders’ meetings, including managing attendance and voting processes, maintaining shareholder registration records, and handling communication between you and AvaFin. This includes distributing meeting notices, relevant documentation, and processing proxies in accordance with internal procedures. (2) Process and distribute dividends to shareholders. (3) Capture images, videos, and/or audio during shareholders’ meetings for record-keeping or other purposes. (4) Conduct internal administration, manage risks, and carry out audits to ensure compliance with corporate governance standards. (5) Fulfil legal obligations, including AML/CFT due diligence measures and responding to orders or requests from courts, government agencies, or other competent authorities, and to detect, investigate, or report activities under applicable laws and regulations. (6) Transfer rights, obligations, or benefits related to a contractual relationship between you and AvaFin, such as those arising from mergers, acquisitions, or the lawful assignment of contracts, whether you act as an individual or as a representative of a legal entity. (7) Perform any acts to protect the rights or benefits of shareholders in the future. Processing is necessary for the performance of a contract under Article 6(1)(b) of the GDPR. Additionally, we may process your personal data to comply with legal obligations pursuant to Article 6(1)(c) of the GDPR or based on our legitimate interest under Article 6(1)(f) of the GDPR.
Marketing and public relations: The purpose is to send you commercial information through various channels (including post, email, phone, SMS, or other available electronic communications means) about AvaFin Group, our financial products, our funding and investment activities, or about public events organized by us. Furthermore, we can conduct public relations activities, including communication for the purpose of enhancing the strategic communication process with our stakeholders (e.g. with journalists, media agencies, bloggers and other people). When we send or display personalized marketing communications or content, we may use some techniques qualified as “profiling”. This means that we may collect personal data about you in different circumstances, we analyse it and thus we evaluate and predict your personal preferences and/or interests. Based on our analysis, we send, or display communications and/or content tailored to your interests/needs. You have the right to object to the use of your data for “profiling” in certain circumstances. Please see “What rights can you exercise?” (Section 8). Additionally, AvaFin has presence on various social media networks. We will process your personal data if you subscribe to our social media site as a follower, if you leave a comment or interact with us in a different way. Please note that social media sites are owned by third parties. This means that we do not have full control over these sites and any information that you may choose to share on our social media sites may also be used by the site provider for their own independent purposes, which are not covered by this privacy notice. We pursue our legitimate interest in conducting public relations activities, as well as making decisions based on profiling, in accordance with Article 6(1)(f) of the GDPR. When your consent is required for such marketing activities, we will ensure that your explicit and freely given consent is obtained in advance, as per Article 6(1)(a) of the GDPR.
Running public events, meetings and conferences: AvaFin may organize and manage webinars, seminars, workshops, conferences, or panel discussions, both virtual and on-site to share our expertise and knowledge and to promote our products and services. The information you provide will be processed for the following purposes: (a) sending the event invitation, (b) managing your participation and the event’s organization and logistics, (c) controlling access to the event, (d) capturing images and videos for creating audiovisual materials, and publishing them in our corporate media channels, both online and offline (e.g. corporate website, intranet, and social media profiles), (e) in certain cases, we may also use the information to conduct a satisfaction survey following the event. If you are not comfortable being photographed/filmed in our events or with any material published containing your image, you can object to such data processing by emailing us and we will do our best to respect your choice. You can also object by speaking to the photographer and/or choosing to stand out from the shot if you see that photographs/videos are taken. The legal basis for the processing of your personal data for the purposes indicated in sections a), b), c) and e) is our legitimate interest in accordance with Article 6(1)(f) of the GDPR. In the case of purpose d), the legal ground varies depending on the type of image: in the case of general plans and environmental sound, the legal basis is AvaFin’s legitimate interest (Article 6(1)(f) of the GDPR) in publicising and promoting the “AvaFin” image and brand and of the organising entity, both internally and externally. In the event that, within the framework of the collection of images during the holding of the aforementioned events, AvaFin, directly or through third parties contracted by AvaFin, captures shots in which you can be recognised directly (close-ups), the processing of your image and voice has its legal basis in the consent (Article 6(1)(a) of the GDPR) you give before attending the event.
Recruitment: We normally post job offers on our website or job search platforms like LinkedIn, which will collect the application information and may ask you to complete a work-related questionnaire that is used to assess your suitability for the role. We can also collect your personal data through employee referral programs. In general, (a) collecting and using your personal data enables us to manage the recruitment and selection process, including setting up an electronic job applicant HR file; managing your application and the communications with you; analysing your skills, experiences, and qualifications to understand your strengths and areas for improvement in relation to the open job position; and organizing interviews. (b) We may also process your personal data to meet recordkeeping and other internal administrative purposes at AvaFin Group. (c) Moreover, with the information collected during the process, we may internally analyse the effectiveness of our recruitment efforts. (d) Additionally, we may conduct pre-employment vetting and background checks, which includes verifying your right to work and, if applicable, requesting certain information for AML/CFT purposes. Also, we may gather information to accommodate individuals with disabilities and ensure compliance with health and safety regulations. If you are a freelancer, we may also request your VAT registration number. (e) Finally, we may process your data to establish a labour or B2B contract upon your acceptance of our job offer during the pre-contractual stage. Please note that under certain circumstances, we may also act as data processors for other AvaFin Group entities, when we post job offers, and we collect job applicants’ forms on our website or other public channels on their behalf. The legal basis for the processing of your personal data for the purposes indicated in sections a) b) and c) is our legitimate interest in accordance with Article 6(1)(f) of the GDPR. In the case of purpose d), compliance with legal obligations (Article 6(1)(c) of the GDPR). In the case of purpose e), the establishment of a contract (Article 6(1)(b) of the GDPR).
Operating and managing lending operations at AvaFin Group’s lending companies: We may act as joint controllers pursuant to Article 26 of the GDPR with other AvaFin Group entities providing lending services in the following processing activities: (a) Credit scoring, (b) Fraud prevention, (c) AML/CFT measures (d) Debt collection, (e) Marketing activities, (f) Market research and business development and (h) Customer service. Under these activities, the main data controller is the AvaFin Group entity with overarching decision-making authority regarding the processing activities. This includes determining the purposes, scope, and essential means of data processing. Typically, the main controller is the AvaFin Group entity that collects personal data from the data subjects. Therefore, we recommend that you review the specific privacy policy of the AvaFin Group lending company where you submit your loan application for further details. Please note that if you submit a loan application you will be subject to a decision solely based on automated processing, including profiling, which produces legal effects on you or similarly significantly affects you. The legal basis for the processing of your personal data for the purpose indicated in section a) is the execution and management of the loan agreement (Article 6(1)(b) of the GDPR), our legal obligations (Article 6(1)(c) of the GDPR), and our legitimate interests (Article 6(1)(f) of the GDPR). In section b) our legitimate interests (Article 6(1)(f) of the GDPR). In section c) compliance with our legal obligations (Article 6(1)(c) of the GDPR). In sections d) and h) it is the execution and management of the loan agreement (Article 6(1)(b) of the GDPR). In section e) it is our legitimate interests (Article 6(1)(f) of the GDPR) and your consent (Article 6(1)(a) of the GDPR). In sections f) our legitimate interests (Article 6(1)(f) of the GDPR).
Managing internal administrative purposes and compliance: We may process your personal data to support internal administrative functions and ensure the smooth operation of our business. This includes managing administrative activities, accounting, record-keeping, and compliance. To streamline these processes, we rely on an integrated approach that leverages our global communication platform (Intranet), centralized databases and applications, as well as shared communication channels across AvaFin Group. Additionally, we uphold ethical standards, ensure transparency, and enforce compliance with legal and regulatory requirements across the Group. We manage the financial and operational aspects of AvaFin Group’s entities and compile comprehensive reports to assess the Group’s overall performance and health (internal controlling and consolidated management reports). Furthermore, we have implemented a systematic approach to document, storage, and manage information relevant to the collective activities of the Group, ensuring efficient coordination and governance for record-keeping and accountability. The legal basis for the processing of your personal data is our legitimate interest in accordance with Article 6(1)(f) of the GDPR, and compliance with our legal obligations in accordance with Article 6(1)(c) of the GDPR.
Running the whistleblowing system: AvaFin Group has implemented a whistleblowing channel to allow whistleblowers to securely report any misconduct, money laundering activities, privacy or consumer protection breaches, fraud, corruption, or other unethical behaviour which has occurred, might be occurring or has been attempted, affecting AvaFin Group. Therefore, we may process your data to provide receipt confirmation and record the report in the system, to conduct a preliminary assessment, case management and investigation, to prevent future misconduct, to comply with legal obligations, to exercise our rights, to protect the whistleblower and the suspected perpetrator, and to guarantee collaboration and appropriate information sharing. If the breach report involves other subsidiaries of AvaFin Group, these companies and AvaFin Holding will process the personal data necessary for the management of the case as joint controllers pursuant to Article 26 of the GDPR. The legal basis for the processing of your personal data is our legitimate interest in accordance with Article 6(1)(f) of the GDPR, compliance with our legal obligations in accordance with Article 6(1)(c) of the GDPR, and the performance of the business or employment relationship with the whistleblower or the suspected perpetrator in accordance with Article 6(1)(b) of the GDPR.
Security: AvaFin Group processes personal data to ensure the security and integrity of its systems, networks, infrastructure, and services. This includes activities such as monitoring access logs, detecting and preventing unauthorised access attempts, mitigating cybersecurity threats, identifying potential vulnerabilities, ensuring business continuity, preventing fraud or abuse, and protecting the Group’s assets, data, and operations. We may also process personal data to investigate and address security alerts or incidents, to verify the identity of individuals accessing systems, and to ensure compliance with internal information security requirements. Where security events or threats affect other subsidiaries within AvaFin Group, the relevant companies and AvaFin Holding may process the personal data necessary for coordinating the security response and incident handling as joint controllers pursuant to Article 26 of the GDPR. The legal basis for this processing is our legitimate interest in protecting our operations, systems, employees, and customers in accordance with Article 6(1)(f) GDPR, as well as compliance with legal obligations relating to information security and data protection in accordance with Article 6(1)(c) GDPR.
Claims Management: AvaFin Group may process personal data for the establishment, exercise, or defence of legal claims. This includes assessing, documenting, and managing customer or partner claims, handling disputes, debt recovery and enforcement actions, negotiating settlements, responding to regulatory inquiries, and preparing legal documentation. Personal data may also be processed to investigate the circumstances of a claim, verify relevant facts, protect our rights, and ensure that any legal proceedings or pre-litigation activities are properly managed. If a claim or dispute involves additional subsidiaries of AvaFin Group, the relevant companies and AvaFin Holding may jointly process the necessary personal data as joint controllers pursuant to Article 26 of the GDPR to ensure coordinated case handling. The legal basis for this processing is our legitimate interest in protecting and enforcing our rights in accordance with Article 6(1)(f) GDPR, as well as compliance with legal obligations under Article 6(1)(c) GDPR. Where applicable, processing may also be necessary for the performance of a contract or for actions taken at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) GDPR.

5. How do we protect your personal data?

We are committed to ensuring the security of your data. To this end, we maintain appropriate technical and organizational measures to ensure a high level of security and confidentiality of the information handled by AvaFin Group, and to avoid, as far as possible, any accidental or unlawful destruction, loss, alteration, or unauthorized access. We adopt internal organizational measures; we develop security procedures and we implement technical measures which meet in particular the principles of data protection by design and data protection by default. For the implementation of our technical and organizational measures, we take into consideration the nature of the personal data, the scope, context, and purposes of the processing, as well as likelihood and severity of risks to the rights and freedoms of the data subjects. This ensures that our practices are both proactive and adaptive to evolving threats. We protect your personal data through a comprehensive set of technical and organisational measures aligned with our Information Security Management System based on ISO 27001. Our security controls—including access management, encryption, secure development practices, and continuous monitoring—are implemented to ensure the confidentiality, integrity, and availability of your data. These measures form an integral part of our Information Security Policy, which provides the overarching framework for safeguarding personal data across the Group.

6. For how long will we keep your data?

We will keep your personal data only for as long as it is necessary, according to the following criteria:

  • We retain your personal data for as long as we maintain an active relationship with you. This includes instances where you have subscribed to our newsletter, hold an active loan, act as an investor, or participate in our events. If the processing of your data is based on your consent, you have the right to withdraw that consent at any time.
  • We retain your personal data for as long as needed in order to comply with legal requirements or contractual obligations which we are subject to (e.g. tax obligations, AML/CFT, etc.).
  • We retain your personal data for the establishment, exercise or defence of legal claims (for instance in relation to statutes of limitations, litigation, or legal investigations) and to pursue the legitimate interests of AvaFin.

This means that we may keep your personal data for a reasonable period after your last interaction with us. However, when the personal data is no longer necessary, we will destroy, delete, or anonymise it in a secure manner. As the processing is carried out under a joint controllership model, the applicable retention periods may vary depending on the local legal and regulatory requirements of the lending companies operating in each country. These local rules determine the specific timeframes for which certain categories of personal data must be retained.

Where cookies are placed on your computer, we keep them for as long as necessary to achieve their purposes (e.g. for the duration of a session for session ID cookies) and for a period defined in accordance with local regulations and guidance, as outlined in the Cookies Policy.

7. Do we transfer your data to third parties?

Under certain circumstances, we may communicate your personal data to some recipients:

  • Entities authorized to receive them under legal provisions, including public authorities, legislative bodies, and supervisory bodies, such as central banks and other financial sector supervisors, as well as those maintaining databases in connection with creditworthiness checks or credit risk analysis;
  • Entities performing certain services in the sales process, such as courier/postal service providers;
  • Providers of advertising or marketing services, in the case of direct marketing of the Data Controller’s own services;
  • Providers of legal, accounting, advisory, and support services in specific areas of their business, including the pursuit of claims (in particular, law firms and debt collection agencies);
  • Entities processing personal data on behalf of the Data Controller, e.g. subcontractors of the Data Controller’s services;
  • Entities authorized to obtain data under applicable law, e.g. tax authorities, courts, or law enforcement agencies, when they submit a request based on an appropriate legal basis.
  • To AvaFin Group entities on a need-to-know basis – see a list of AvaFin Group entities in Section 1.

Some of AvaFin Group entities and third parties with whom we share your personal data may be located in countries outside the EU and/or European Economic Area. When we transfer your personal data to AvaFin Group entities and third parties located outside the EU and the European Economic Area, we may be required to take specific additional measures to safeguard the relevant personal data. Certain countries outside the EU and the European Economic Area have been approved by the European Commission as providing protection essentially equivalent to the EU data protection laws and, therefore, no additional safeguards are required to transfer your personal data to these jurisdictions. In countries that have not had these approvals, we will use appropriate safeguards to protect any personal information that is being transferred, such as EU Commission-approved standard contractual clauses, or other measures, to ensure that your personal data is protected adequately.

Whenever we transfer your data to third parties, we are committed to ensuring that the Recipient has the appropriate technical and organizational measures in place to guarantee the confidentiality and security of the data transferred.

8. What rights can you exercise?

You have the following rights in relation to your personal data that we process:

  • Right of access (Article 15 GDPR).
  • Right to rectification (Article 16 GDPR).
  • Right to erasure (Article 17 GDPR).
  • Right to restriction of processing (Article 18 GDPR).
  • Right to data portability (Article 20 GDPR).
  • Right to object to the processing of your personal data (Article 21 GDPR).
  • Right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects (Article 22 GDPR).

If the legal basis for using your personal data is your consent, you may at any time withdraw your consent by informing us about your wishes. If you choose to withdraw your consent, we may no longer use your personal data based on consent. The withdrawal will not affect the lawfulness of use based on consent before its withdrawal. In some cases, we may continue using your personal data after withdrawal of your consent, if allowed or required by applicable legislation.

Please note that these rights are subject to certain exemptions and may not all be available in the country in which you are based. This might be due to obligations imposed upon us, such as other legislation requiring us to retain personal data, protection of the rights and freedoms of others, or the like. We always do our utmost to carefully evaluate every single request and will provide the reasons if actions are not taken.

If you wish to further understand or exercise your rights, please contact us by post to the AvaFin Group’s address, or by e-mail to the following address: dpo@avafin.com.

If you have requested to receive information from AvaFin Group, such as newsletters, and you no longer wish to receive these, you can unsubscribe at any time via the email that you receive.

If you are not satisfied with our response, you can always lodge a complaint with your local data protection authority. For more information, please click on the following link.

9. Changes in our Privacy Policy

This Privacy Policy supersedes all prior versions, and we reserve the right to update or modify it as needed. In the event of significant changes, we will provide notice either on our website or via email, where deemed necessary.

This Privacy Policy was last updated: December 2025