EQVI

Product

Security

Security and data protection are foundational to how EQVI is built, not an afterthought layered on top.

1. Encryption in transit and at rest, with access controls and regular security review across our systems.

2. Purpose-built data boundaries. EQVI processes only the data categories a given integration requires, governed by an activity-by-activity controller/processor allocation agreed with each bank.

3. No health data. EQVI does not request, collect, or use medical or health information — including biometric, fitness, or activity data — for personalisation, and does not infer health status from the data it does process.

4. No credit, insurance, or eligibility decisions. EQVI does not make automated decisions that determine a customer's access to credit, insurance, or banking products. Those decisions remain with the bank.

5. Vetted subprocessors. Every service provider EQVI relies on operates under contractual confidentiality and data protection obligations, with an up-to-date list of categories and locations available to partner banks on request.

6. Governed by UK data protection law, including the UK GDPR and the Data Protection Act 2018, with equivalent safeguards applied for customers in the EEA.

7. Full technical and organisational measures documentation, our security overview, and our data processing agreement template are available to partner banks under NDA during due diligence.