FinCheqIQ

Privacy notice

What FinCheqIQ holds, where it comes from, who can see it, and what the platform deliberately does not do with it.

The bank's privacy notice — lawful basis, retention periods, data subject rights and the contact for them — is a legal document supplied at deployment, and it governs. This page states what the platform holds and how it is protected.

What the platform holds

Cheque images, front and back Retained unmodified for audit. Pre-processing — de-skew, contrast normalisation — works on a copy, never on the original.
Extracted field values and their confidence scores Every attempt is kept. Re-running extraction supersedes the current result but does not delete it.
Reference signature specimens Encrypted at rest. Every reveal is logged against the identity that made it, and the access entry cannot be removed.
Customer and account master data Mirrored from core banking and read-only here. FinCheqIQ never writes back.
Audit records Who did what, when, and to which record — append-only and hash-chained.
User accounts and role assignments Including sign-in activity and blocked access attempts.

Nothing is typed twice

Customer and account details are the bank's record, not FinCheqIQ's. They are synchronised from core banking and shown read-only, marked with a padlock. A correction is made at source and carried through by the next delta sync — which is why the platform cannot quietly hold a version of a customer that the bank does not have.

Who can see what

Access is role-scoped and checked at the point of use, not only at sign-in. A reviewer sees the cheques in their queue; the Signature Master is deliberately narrow because reference specimens are the comparison baseline for every cheque. Scheduled reports check the recipient's role at delivery, so someone who loses a role stops receiving them.

What the platform does not do

Signature verification compares two static images — shape, geometry and stroke arrangement. It does not observe pressure, speed, or anything else that exists only while a signature is being written, and it is not a behavioural biometric. It produces a probabilistic score, never a determination that a signature is genuine or forged.

The platform also does not write to core banking, does not make a lending or credit assessment, and does not profile a customer beyond the risk indicators a reviewer is shown with their reasons.

How long it is kept

Retention is jurisdiction-specific and configured by the bank. The platform never truncates the audit trail on its own, and no cheque is archived without an acknowledgement from core banking or an explicit bank-approved override.

Retention periods TBD — Bank-specific. Set per record class at deployment.
Lawful basis and cross-border transfer TBD — Bank-specific. Stated in the bank's own notice.
Data subject request routing TBD — Bank-specific. Handled through the bank's data protection function, not through FinCheqIQ.
Back to sign in v1.0 · prototype