Legal

Privacy Policy

This policy explains what personal data Highwater collects, how it is used and disclosed, how long it is retained, and the rights available to you under the General Data Protection Regulation.

Version of 1 September 2026

1. Introduction

Highwater is a personal financial management service operated by Kamil Slaoui Benyahia, a sole trader established in Spain (in this policy, "Highwater", "we", "us" and "our").

For the purposes of the GDPR, we are the data controller in respect of the Personal Data described in this policy.

  • Postal address Residencia Almazara Hills, Calle Liam Almazara 26, Istán, Málaga, Spain
  • Contact for data protection matters privacy@highwaterapp.com

This policy applies to the Highwater application and to this website. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR.

2. Definitions

  • Personal Data Any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
  • Services The Highwater application and this website.
  • Household The unit within which Personal Data is stored in the Services. A Household has one or more members. See section 8.
  • GDPR Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

3. Personal Data we collect

We collect and process the following categories of Personal Data.

  • (a) Account and identity data Your email address, and the public key, device label and usage metadata of any passkey you register. We do not use passwords. The private key of a passkey remains on your device and is not disclosed to us.
  • (b) Household data The Household to which you belong, its other members, your settings, and any account holder names you record so that the Services can identify them within bank transaction descriptions.
  • (c) Financial data you provide Holdings and trades, mortgages and property, income, equity and option grants, carried interest and co-investments, insurance policies, receivables and payables, and any other record you enter.
  • (d) Financial data obtained from connected accounts Account identifiers, balances and transaction records obtained from an account connection you have authorised, including the date, amount, currency, description and merchant of each transaction.
  • (e) Derived data Categories assigned to transactions, month-end balance and net worth snapshots, savings rate and projection outputs, and the pairings that identify one transaction as the counterpart of another.
  • (f) Technical data In production, diagnostic data relating to errors and a sample of performance traces. This data concerns the operation of the software and may incidentally include Personal Data displayed at the time an error occurred.

We do not knowingly collect special categories of Personal Data within the meaning of Article 9 of the GDPR.

4. How we use Personal Data

We process Personal Data for the following purposes.

  • To create and administer your account and authenticate you.
  • To establish and maintain connections to your payment accounts and to import transaction and balance data.
  • To categorise transactions and to identify recurring charges and subscriptions.
  • To produce the balance sheets, projections and other outputs that constitute the Services.
  • To provide technical support and to respond to correspondence.
  • To monitor, secure and improve the operation of the Services.
  • To comply with legal obligations to which we are subject.

We do not sell, rent or license Personal Data. We do not use Personal Data for advertising, for lead generation, or to train machine learning models. We do not aggregate Personal Data across users for disclosure to third parties.

6. Automated processing of transaction categories

Transactions are categorised by rules that operate within our own infrastructure. Where a merchant is not matched by any rule, we submit a normalised form of the merchant name to Anthropic, PBC in order to obtain a suggested category.

The submission consists of the normalised merchant name and, where applicable, an indication that the charge recurs at an approximate amount. It does not include your name, your account identifiers, your account balances, the transaction date or the full transaction description. Account holder names recorded in your settings are removed from the merchant name before submission.

The service returns a suggested category and a confidence score. Where the confidence score exceeds our threshold, the category is applied automatically. You may change any category at any time.

This processing does not produce legal effects concerning you and does not similarly significantly affect you within the meaning of Article 22 of the GDPR.

7. Apple Account Data Transfer

We have applied to Apple for access to the Account Data Transfer API, which is provided under the Digital Markets Act. If access is granted and you elect to connect your Apple account, the following terms apply to Personal Data obtained through it.

  • The transfer is initiated by you. It ceases when you disconnect the account.
  • We request the appstore-info-account-data scope only. We do not request app install activity or push notification activity.
  • We retain the product name, the transaction date and the transaction amount. The remainder of the payload is discarded once processed.
  • The data is used solely to identify charges appearing on your own connected payment accounts, and is displayed only within your Household.
  • We do not sell or license this data, disclose it to third parties, use it for advertising or profiling, use it to train machine learning models, or aggregate it across users.

A subscription billed through Apple appears on a payment account as a single undifferentiated entry, and the transaction data supplied by the account servicing payment service provider does not identify the product to which it relates. The purpose of this processing is to associate each such entry with the corresponding purchase in your own Apple account.

8. Household accounts

Personal Data in the Services is stored at the level of a Household rather than the individual user. Where two or more users are members of the same Household, each member has access to all Personal Data associated with that Household, including data recorded before they became a member.

The Services do not provide member-level access restrictions within a Household. You should add a person to your Household only if you intend them to have access to all of its data.

9. Disclosure of Personal Data

We disclose Personal Data to the processors listed below, each of which acts on our instructions under a written agreement and may process the data only for the purpose stated. We may also disclose Personal Data where required to do so by law or in connection with legal proceedings.

RecipientPurposePersonal Data disclosed
Supabase, Inc.Database hosting, authentication and file storageAll Personal Data held in the Services. Hosted in Ireland.
Vercel, Inc.Application hosting and content deliveryRequest metadata, including IP address. Served from Dublin, Ireland.
Enable Banking OyAccount information services under PSD2Account and transaction data returned by an account connection you have authorised.
FintableAlternative transaction source, where you connect oneTransaction data contained in the spreadsheet you connect.
Anthropic, PBCSuggesting a category for an unrecognised merchantA normalised merchant name and, where applicable, an indication that a charge recurs at an approximate amount. See section 6.
Functional Software, Inc. (Sentry)Error and performance monitoring, in production onlyDiagnostic data relating to errors and a sample of requests, which may incidentally include data displayed at the time of an error.
BrandfetchDisplay of merchant and instrument logosThe domain name or instrument identifier of a logo. Requested by your browser, not by our servers.
Market data providersPrices, exchange rates and company informationNo Personal Data. Requests concern financial instruments and economic indicators only.

10. International transfers

Personal Data held in the Services is stored within the European Union. Our database is hosted in Ireland and the application is served from Dublin, Ireland.

Certain of the recipients listed in section 9 process limited categories of data outside the European Economic Area, principally in the United States. Those transfers are confined to the data described in that section and are made subject to appropriate safeguards under Chapter V of the GDPR, including the standard contractual clauses adopted by the European Commission where applicable.

11. Retention

We retain Personal Data for as long as is necessary for the purposes set out in this policy, or for such longer period as may be required by law.

CategoryRetention period
Account and identity data, including passkey credentialsFor as long as your account remains open. Deleted when the account is closed.
Financial data you provide, and data obtained from connected accountsFor as long as your Household exists. Individual transaction records are not deleted during routine synchronisation, so that a record re-sent by a provider does not lose the categorisation applied to it. All records are deleted when the Household is deleted.
Derived data, including month-end snapshots and projection outputsFor as long as your Household exists. Historical snapshots are retained so that earlier periods remain comparable.
Diagnostic dataIn accordance with the retention period applied by our monitoring provider.
CorrespondenceFor as long as necessary to deal with the matter raised, and for a reasonable period afterwards.

Where you close your account, the associated records, including derived data, are deleted. Where you disconnect an account connection, the authorisation is revoked with the provider.

12. Security

Account connections are read-only and the Services contain no payment initiation functionality. Authentication uses passkeys rather than passwords. Data is encrypted in transit and at rest, and row-level access controls restrict the data available to a given session to the Household to which it belongs.

Further detail is set out on our security page. Highwater is in early access and has not been independently certified.

No method of transmitting or storing data is entirely secure. While we take appropriate technical and organisational measures, we cannot guarantee the absolute security of Personal Data.

13. Your rights

Subject to the conditions set out in the GDPR, you have the following rights in respect of your Personal Data.

  • Right of access (Article 15) To obtain confirmation of whether we process your Personal Data and to receive a copy of it.
  • Right to rectification (Article 16) To have inaccurate Personal Data corrected and incomplete Personal Data completed.
  • Right to erasure (Article 17) To have your Personal Data deleted where one of the grounds in Article 17(1) applies.
  • Right to restriction (Article 18) To have processing restricted in the circumstances set out in Article 18(1).
  • Right to data portability (Article 20) To receive the Personal Data you have provided to us in a structured, commonly used and machine-readable format.
  • Right to object (Article 21) To object to processing carried out on the basis of our legitimate interests.
  • Right to withdraw consent (Article 7(3)) To withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

You may exercise the rights of access and portability directly within the Services, which provide an export of your data, and you may delete your account and its associated records at any time. For any other request, contact us at the address in section 17. We will respond within one month of receipt, as provided by Article 12(3) of the GDPR. That period may be extended by two further months where necessary, in which case we will inform you within one month of receipt.

If you consider that our processing of your Personal Data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain.

14. Cookies

This website does not set cookies and does not use analytics or advertising technologies.

The Highwater application uses cookies that are strictly necessary to maintain your authenticated session. These cookies are not used for analytics, profiling or advertising.

15. Children

The Services are not directed at children and are not intended for use by persons under the age of 18. We do not knowingly collect Personal Data relating to children. If you believe that a child has provided us with Personal Data, contact us and we will delete it.

16. Changes to this policy

We may amend this policy from time to time. The date of the current version appears at the head of this page. Where an amendment materially affects the processing of Personal Data already held, we will notify account holders directly.

17. Contact

Enquiries and requests under this policy should be addressed to:

  • Controller Kamil Slaoui Benyahia
  • Postal address Residencia Almazara Hills, Calle Liam Almazara 26, Istán, Málaga, Spain
  • Email privacy@highwaterapp.com