Privacy Policy

Introduction

We, at Owlytic I.O Ltd. (the “Company”, “we”, “us”, or “our”), are committed to protecting your personal information and your right to privacy, and to complying with applicable data protection, financial services, and information security laws and standards, including principles derived from the General Data Protection Regulation (GDPR), Open Banking frameworks (including PSD2-equivalent principles), and applicable Israeli law.

This Privacy Policy (the “Privacy Policy”) explains how we collect, use, process, store, transfer, and safeguard personal data in connection with our website (https://owlytic.io), our application (https://app.owlytic.io), and any related services (collectively, the “Services”).

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, you must discontinue use of the Services.

1. Nature of the Services and Regulatory Role

The Services operate as a financial data aggregation, accounting, and analytics platform, enabling users to access, consolidate, and analyze financial and accounting information from multiple sources, including banks, financial institutions, ERP systems, and governmental APIs.

The Company operates as a technology service provider and data intermediary, and does not act as a bank, payment institution, broker, or licensed financial advisor. The Company does not hold or control user funds and does not initiate payment transactions.

Where applicable, the Company performs a role comparable to an Account Information Service Provider (AISP) under PSD2/Open Banking principles. Access to financial data is performed strictly on the basis of user authorization.

The Company acts solely as a technical conduit and processor of financial data, and shall not be deemed the source of truth of any financial information presented through the Services.

2. Open Banking Authorization and Consent

Where the Services rely on Open Banking or similar frameworks, financial data is accessed only based on your explicit, informed, and revocable consent.

By connecting financial accounts or external systems, you authorize the Company to access, retrieve, store, process, and display financial data from such sources, including banks, ERP systems, and governmental APIs (including, where applicable, the Bank of Israel API).

You may withdraw your consent at any time. Upon withdrawal, access to such data sources will be terminated. However, previously collected data may be retained where required for legal, audit, compliance, fraud prevention, or legitimate business purposes.

3. Information We Collect

We collect personal data that you provide directly, data obtained through integrations, and data collected automatically through use of the Services.

This includes identifying information such as your name and email address.

Due to the nature of the Services, we collect extensive financial and accounting data, including but not limited to bank account details, account types, balances (including daily balances), transaction data (including amounts, descriptions, value dates, references, and raw JSON data received from Open Banking providers), financial statements, trial balances, accounting entries, adjusted journal entries (AJE), cash flow classifications, and general ledger (GL) data obtained through ERP integrations.

We also collect data relating to integrations with external systems, including ERP connection details such as system URLs and authentication credentials (including usernames and encrypted passwords), as well as consent keys and tokens used for Open Banking access.

Users may upload documents and files, including financial files (such as Excel or JSON files) and profile-related data such as images.

We collect technical and usage data automatically, including IP address, device and browser information, operating system, access timestamps, and usage patterns.

We maintain detailed system and security logs, including audit logs of user actions, login history, failed login attempts, account lockouts, token refresh activity, and system events, for security, compliance, and monitoring purposes.

We also collect authentication-related data, including multi-factor authentication (MFA) information such as TOTP secrets and backup codes.

Due to the nature of the Services, a substantial portion of the data processed constitutes financial and accounting data of a highly sensitive nature, which is handled with enhanced safeguards.

4. Legal Basis for Processing

Where applicable under GDPR or similar laws, we process personal data on the basis of performance of a contract, your explicit consent (particularly for Open Banking access), our legitimate interests (including security, fraud prevention, and service improvement), and compliance with legal and regulatory obligations.

5. How We Use Your Information

We use personal data to provide, operate, maintain, and improve the Services, including aggregating financial data, generating reports and insights, enabling integrations with third-party systems, and providing customer support.

We use personal data for security and compliance purposes, including fraud detection, audit logging, monitoring system integrity, enforcing our policies, and complying with legal obligations.

We may send service-related communications, including reports and operational notifications. Marketing communications may be introduced in the future, subject to applicable law.

6. Data Accuracy and Third-Party Data Disclaimer

Financial data presented through the Services is obtained from third-party sources, including banks, financial institutions, ERP systems, and governmental APIs.

The Company does not control, verify, or guarantee the accuracy, completeness, or timeliness of such data. The Company does not modify source financial data beyond technical processing and presentation.

All financial outputs, analytics, and reports are derived from third-party data and are provided for informational purposes only.

To the fullest extent permitted by law, the Company disclaims any responsibility for errors, omissions, inconsistencies, or delays originating from third-party data providers, and any reliance on such data is solely at the user’s risk.

7. Disclosure of Information

We may share personal data with service providers and vendors that support the operation of the Services, including cloud infrastructure providers (such as AWS), AI service providers (such as OpenAI), monitoring and error tracking providers (such as Sentry), security and performance providers (such as Cloudflare), and integration partners (such as ERP systems including Priority).

We may also share data with professional advisors acting on behalf of users, including accountants and financial advisors, where such access is part of the Services or authorized by the user.

We may disclose information where required by law, regulation, or legal process, or where necessary to protect rights, prevent fraud, or ensure safety.

We do not sell personal data.

8. International Data Transfers

Personal data may be transferred to and processed in jurisdictions outside Israel, including jurisdictions that may not provide the same level of data protection.

Where required, such transfers are conducted in accordance with applicable law and safeguarded through mechanisms such as Standard Contractual Clauses (SCCs) or equivalent protections.

9. Data Retention

We retain personal data for as long as necessary to provide the Services, fulfill contractual obligations, comply with legal and regulatory requirements, resolve disputes, enforce agreements, and maintain audit and security records.

In practice, data may be retained for extended or indefinite periods unless deletion is requested, subject to legal and compliance requirements.

Users may request deletion of their personal data by contacting us. We will process such requests in accordance with applicable law, subject to legal retention obligations.

10. Information Security

We implement and maintain a comprehensive information security program aligned with industry standards, including principles derived from SOC 2 and ISO/IEC 27001.

Such measures include encryption of data in transit and at rest, role-based access controls, least-privilege principles, network segmentation, secure infrastructure, continuous monitoring and logging, audit trails, multi-factor authentication, incident detection and response procedures, and vendor risk management.

While we take reasonable steps to protect personal data, no system can guarantee absolute security.

11. Your Rights

Depending on your jurisdiction, you may have rights including access, rectification, deletion, restriction of processing, data portability, and objection to processing.

Where processing is based on consent (including Open Banking consent), you may withdraw such consent at any time.

We will respond to requests in accordance with applicable law.

12. User Responsibilities

You are responsible for maintaining the confidentiality of your account credentials and ensuring that access permissions granted to third parties are appropriate.

You acknowledge that sharing credentials or access permissions may result in unauthorized access to your data, for which the Company shall not be responsible.

13. Children’s Privacy

The Services are not intended for individuals under the age of 18, and we do not knowingly collect personal data from minors.

14. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements, regulatory expectations, or our practices. Continued use of the Services constitutes acceptance of the updated policy.

15. Contact Information

If you have any questions or requests regarding this Privacy Policy, you may contact us at: [email protected]

Pinchas Rosen 65, Tel Aviv, Israel.

Last updated: April 5, 2026

The Finance Frontier | Owlytic
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.