Privacy Policy
This policy explains what personal data Highwater collects, how it is used and disclosed, how long it is retained, and the rights available to you under the General Data Protection Regulation.
Version of 1 September 2026
1. Introduction
Highwater is a personal financial management service operated by Kamil Slaoui Benyahia, a sole trader established in Spain (in this policy, "Highwater", "we", "us" and "our").
For the purposes of the GDPR, we are the data controller in respect of the Personal Data described in this policy.
- Postal address Residencia Almazara Hills, Calle Liam Almazara 26, Istán, Málaga, Spain
- Contact for data protection matters privacy@highwaterapp.com
This policy applies to the Highwater application and to this website. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR.
2. Definitions
- Personal Data Any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
- Services The Highwater application and this website.
- Household The unit within which Personal Data is stored in the Services. A Household has one or more members. See section 8.
- GDPR Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
3. Personal Data we collect
We collect and process the following categories of Personal Data.
- (a) Account and identity data Your email address, and the public key, device label and usage metadata of any passkey you register. We do not use passwords. The private key of a passkey remains on your device and is not disclosed to us.
- (b) Household data The Household to which you belong, its other members, your settings, and any account holder names you record so that the Services can identify them within bank transaction descriptions.
- (c) Financial data you provide Holdings and trades, mortgages and property, income, equity and option grants, carried interest and co-investments, insurance policies, receivables and payables, and any other record you enter.
- (d) Financial data obtained from connected accounts Account identifiers, balances and transaction records obtained from an account connection you have authorised, including the date, amount, currency, description and merchant of each transaction.
- (e) Derived data Categories assigned to transactions, month-end balance and net worth snapshots, savings rate and projection outputs, and the pairings that identify one transaction as the counterpart of another.
- (f) Technical data In production, diagnostic data relating to errors and a sample of performance traces. This data concerns the operation of the software and may incidentally include Personal Data displayed at the time an error occurred.
We do not knowingly collect special categories of Personal Data within the meaning of Article 9 of the GDPR.
4. How we use Personal Data
We process Personal Data for the following purposes.
- To create and administer your account and authenticate you.
- To establish and maintain connections to your payment accounts and to import transaction and balance data.
- To categorise transactions and to identify recurring charges and subscriptions.
- To produce the balance sheets, projections and other outputs that constitute the Services.
- To provide technical support and to respond to correspondence.
- To monitor, secure and improve the operation of the Services.
- To comply with legal obligations to which we are subject.
We do not sell, rent or license Personal Data. We do not use Personal Data for advertising, for lead generation, or to train machine learning models. We do not aggregate Personal Data across users for disclosure to third parties.
5. Legal bases for processing
We process Personal Data only where a lawful basis under Article 6 of the GDPR applies. The bases on which we rely are set out below.
| Purpose | Legal basis |
|---|---|
| Providing the Services, including connecting accounts, importing and categorising transactions, and producing balance sheets and projections | Article 6(1)(b) GDPR: performance of a contract to which you are a party |
| Accessing information held in your payment accounts | Article 6(1)(a) GDPR: the explicit consent you give to your account servicing payment service provider when you authorise the connection, which you may withdraw at any time |
| Maintaining the security and availability of the Services, diagnosing faults and preventing misuse | Article 6(1)(f) GDPR: our legitimate interests in operating a secure service |
| Responding to correspondence you send to us | Article 6(1)(f) GDPR: our legitimate interests in answering enquiries |
6. Automated processing of transaction categories
Transactions are categorised by rules that operate within our own infrastructure. Where a merchant is not matched by any rule, we submit a normalised form of the merchant name to Anthropic, PBC in order to obtain a suggested category.
The submission consists of the normalised merchant name and, where applicable, an indication that the charge recurs at an approximate amount. It does not include your name, your account identifiers, your account balances, the transaction date or the full transaction description. Account holder names recorded in your settings are removed from the merchant name before submission.
The service returns a suggested category and a confidence score. Where the confidence score exceeds our threshold, the category is applied automatically. You may change any category at any time.
This processing does not produce legal effects concerning you and does not similarly significantly affect you within the meaning of Article 22 of the GDPR.
7. Apple Account Data Transfer
We have applied to Apple for access to the Account Data Transfer API, which is provided under the Digital Markets Act. If access is granted and you elect to connect your Apple account, the following terms apply to Personal Data obtained through it.
- The transfer is initiated by you. It ceases when you disconnect the account.
- We request the appstore-info-account-data scope only. We do not request app install activity or push notification activity.
- We retain the product name, the transaction date and the transaction amount. The remainder of the payload is discarded once processed.
- The data is used solely to identify charges appearing on your own connected payment accounts, and is displayed only within your Household.
- We do not sell or license this data, disclose it to third parties, use it for advertising or profiling, use it to train machine learning models, or aggregate it across users.
A subscription billed through Apple appears on a payment account as a single undifferentiated entry, and the transaction data supplied by the account servicing payment service provider does not identify the product to which it relates. The purpose of this processing is to associate each such entry with the corresponding purchase in your own Apple account.
8. Household accounts
Personal Data in the Services is stored at the level of a Household rather than the individual user. Where two or more users are members of the same Household, each member has access to all Personal Data associated with that Household, including data recorded before they became a member.
The Services do not provide member-level access restrictions within a Household. You should add a person to your Household only if you intend them to have access to all of its data.
9. Disclosure of Personal Data
We disclose Personal Data to the processors listed below, each of which acts on our instructions under a written agreement and may process the data only for the purpose stated. We may also disclose Personal Data where required to do so by law or in connection with legal proceedings.
| Recipient | Purpose | Personal Data disclosed |
|---|---|---|
| Supabase, Inc. | Database hosting, authentication and file storage | All Personal Data held in the Services. Hosted in Ireland. |
| Vercel, Inc. | Application hosting and content delivery | Request metadata, including IP address. Served from Dublin, Ireland. |
| Enable Banking Oy | Account information services under PSD2 | Account and transaction data returned by an account connection you have authorised. |
| Fintable | Alternative transaction source, where you connect one | Transaction data contained in the spreadsheet you connect. |
| Anthropic, PBC | Suggesting a category for an unrecognised merchant | A normalised merchant name and, where applicable, an indication that a charge recurs at an approximate amount. See section 6. |
| Functional Software, Inc. (Sentry) | Error and performance monitoring, in production only | Diagnostic data relating to errors and a sample of requests, which may incidentally include data displayed at the time of an error. |
| Brandfetch | Display of merchant and instrument logos | The domain name or instrument identifier of a logo. Requested by your browser, not by our servers. |
| Market data providers | Prices, exchange rates and company information | No Personal Data. Requests concern financial instruments and economic indicators only. |
10. International transfers
Personal Data held in the Services is stored within the European Union. Our database is hosted in Ireland and the application is served from Dublin, Ireland.
Certain of the recipients listed in section 9 process limited categories of data outside the European Economic Area, principally in the United States. Those transfers are confined to the data described in that section and are made subject to appropriate safeguards under Chapter V of the GDPR, including the standard contractual clauses adopted by the European Commission where applicable.
11. Retention
We retain Personal Data for as long as is necessary for the purposes set out in this policy, or for such longer period as may be required by law.
| Category | Retention period |
|---|---|
| Account and identity data, including passkey credentials | For as long as your account remains open. Deleted when the account is closed. |
| Financial data you provide, and data obtained from connected accounts | For as long as your Household exists. Individual transaction records are not deleted during routine synchronisation, so that a record re-sent by a provider does not lose the categorisation applied to it. All records are deleted when the Household is deleted. |
| Derived data, including month-end snapshots and projection outputs | For as long as your Household exists. Historical snapshots are retained so that earlier periods remain comparable. |
| Diagnostic data | In accordance with the retention period applied by our monitoring provider. |
| Correspondence | For as long as necessary to deal with the matter raised, and for a reasonable period afterwards. |
Where you close your account, the associated records, including derived data, are deleted. Where you disconnect an account connection, the authorisation is revoked with the provider.
12. Security
Account connections are read-only and the Services contain no payment initiation functionality. Authentication uses passkeys rather than passwords. Data is encrypted in transit and at rest, and row-level access controls restrict the data available to a given session to the Household to which it belongs.
Further detail is set out on our security page. Highwater is in early access and has not been independently certified.
No method of transmitting or storing data is entirely secure. While we take appropriate technical and organisational measures, we cannot guarantee the absolute security of Personal Data.
13. Your rights
Subject to the conditions set out in the GDPR, you have the following rights in respect of your Personal Data.
- Right of access (Article 15) To obtain confirmation of whether we process your Personal Data and to receive a copy of it.
- Right to rectification (Article 16) To have inaccurate Personal Data corrected and incomplete Personal Data completed.
- Right to erasure (Article 17) To have your Personal Data deleted where one of the grounds in Article 17(1) applies.
- Right to restriction (Article 18) To have processing restricted in the circumstances set out in Article 18(1).
- Right to data portability (Article 20) To receive the Personal Data you have provided to us in a structured, commonly used and machine-readable format.
- Right to object (Article 21) To object to processing carried out on the basis of our legitimate interests.
- Right to withdraw consent (Article 7(3)) To withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
You may exercise the rights of access and portability directly within the Services, which provide an export of your data, and you may delete your account and its associated records at any time. For any other request, contact us at the address in section 17. We will respond within one month of receipt, as provided by Article 12(3) of the GDPR. That period may be extended by two further months where necessary, in which case we will inform you within one month of receipt.
If you consider that our processing of your Personal Data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain.
15. Children
The Services are not directed at children and are not intended for use by persons under the age of 18. We do not knowingly collect Personal Data relating to children. If you believe that a child has provided us with Personal Data, contact us and we will delete it.
16. Changes to this policy
We may amend this policy from time to time. The date of the current version appears at the head of this page. Where an amendment materially affects the processing of Personal Data already held, we will notify account holders directly.
17. Contact
Enquiries and requests under this policy should be addressed to:
- Controller Kamil Slaoui Benyahia
- Postal address Residencia Almazara Hills, Calle Liam Almazara 26, Istán, Málaga, Spain
- Email privacy@highwaterapp.com