These Terms of Use are available in multiple languages. Only the German version is binding and legally effective. Other language versions are provided solely for your information.
finAPI GmbH, represented by the management, Adams-Lehmann-Strasse 44, 80797 Munich, Germany
(Munich District Court, HRB 175250), email: kontakt@finapi.io, phone: +49 89 416177555
("finAPI") is an authorized payment institution supervised by the Federal Financial Supervisory
Authority ("BaFin"), Graurheindorfer Str. 108, 53117 Bonn, fax: +49 228 4108-1550, email:
poststelle@bafin.de.
The account information service ("KID") provided by finAPI as an online service allows end users
to retrieve their account balances and transactions (hereinafter "account information") from
payment accounts and other accounts at credit and financial services institutions, credit card
companies and other financial data providers (hereinafter "account providers"), provided that
these accounts are included in the scope of services agreed between the end user and the service
provider (as defined below).
The payment initiation service ("ZAD") provided by finAPI as an online service allows end users
to initiate payment orders and payment transactions at the account provider.
The KID/ZAD services offered by finAPI may include both access and payment transactions that are
either regulated by law or not explicitly regulated by law.
The provisions of these Terms of Use ("Terms of Use") govern the legal relationship between
finAPI and consumers and business users who are also users of a service (which may also be
provided via an app) (the "Service") of a service provider (the "Service Provider") that
processes the account information and/or records payment orders and payment transactions and
forwards them to initiate a payment transaction ("finAPI KID/ZAD").
finAPI and the Service Provider are legally and economically independent companies and provide different services to the end user (for the interaction between finAPI and Service Providers, see section 2.1.1).
A prerequisite for the provision of account information and/or payment initiation services by finAPI is the conclusion of these Terms of Use. For this purpose, the end user is redirected from the provider’s service to a website/system of finAPI. On this website/system, the end user can perform the following activities:
a) The end user can review the privacy notice and the precontractual information for account information and payment initiation services, as well as the Terms of Use. By actively clicking on the opt-in checkbox and the "Next" button, the end user agrees to the Terms of Use. By giving consent, the contract between the end user and finAPI is concluded ("conclusion of contract"). The Terms of Use are provided to the end user via a link for downloading and printing.
b) Subsequently, the end user can enter their access data for accessing the account provider (user ID or similar, PIN/password, as well as two-factor authentication, see c)). In some cases, the end user additionally has the option to allow or refuse the storage of the PIN by finAPI. By clicking the corresponding button (e.g., "Import bank account"), the access data are transmitted to finAPI, and finAPI establishes the connection to the account provider.
c) In the context of the second Payment Services Directive (PSD2), in the case of a finAPI KID/ZAD, the account provider requires strong customer authentication ("SCA" or two-factor authentication). The type of SCA required is determined by the account provider. In this case, the end user must enter their personalized security credentials, e.g. a TAN, into the input mask and transmit them to the account provider via finAPI, if this is technically possible.
The integration of additional account providers and/or accounts after conclusion of the contract is generally possible, provided they are supported by the service provider, and also takes place by redirecting the end user to a website/system of finAPI.
For the provision of account information or payment initiation services by finAPI, only these Terms of Use apply between finAPI and the end user. Changes to these Terms of Use will be communicated to the end user in writing, electronically or in text form in good time before they take effect; they will be considered approved if finAPI does not receive an objection from the end user within one month after notification of the changes. The notification may be made by finAPI via a display in the input mask or through the service provider. An objection entitles the end user to terminate these Terms of Use with immediate effect. finAPI will draw the end user’s attention to the deadline and the possibility of objection.
The end user can use finAPI KID and ZAD from within the service of the service provider and is redirected from the provider’s service to a finAPI website/system for this purpose. The entry and management of the end user’s personal access data at the respective account provider, as well as the execution of the KID/ZAD, are carried out directly by finAPI for the end user. After execution of the KID/ZAD functions, finAPI provides the corresponding data to the end user for display and processing in the service of the service provider. The service provider does not receive any sensitive payment data at any time that would allow it to access the end user’s account information at the end user’s account providers. The sensitive payment data are passed directly to finAPI systems, processed by finAPI, and in the case of KID are stored by finAPI. The sensitive payment data entered by the end user are protected by finAPI from unauthorized access. The end user authorizes finAPI to use the stored sensitive payment data to execute a ZAD transaction. No sensitive payment data are stored permanently within the ZAD.
In general, finAPI’s KID/ZAD includes the following functions for the end user, provided that the functions available to the end user in each individual case also depend on the scope of services agreed between the end user and the service provider, so that some of the functions listed below may not be available to the end user:
Providing account information by a service authorized by the end user:
Identification procedure by a service authorized by the end user:
Data Intelligence Services:
Individual functions of finAPI’s KID/ZAD depend on products and services of third parties over which finAPI has no influence. This may cause individual functions of finAPI’s KID/ZAD to be temporarily or permanently unavailable.
Notes on Verification of Payee (VOP):
The payee verification is conducted by finAPI before authorizing the payment, checking if the name of the payee entered matches the name of the account holder stored at the bank. The following results of the payee verification are displayed to the end user:
If the payee verification results in a "match," the payee bank is responsible for ensuring that the payee information is correct at the time of verification.
If the payee verification results in anything other than "match," e.g. "close match," "no match," "not possible," or it is (still) not mandatory due to the aforementioned exceptions ("not applicable"), the transfer amount could be credited to an account whose holder is not the payee you specified. If you as the end user nevertheless authorize such a payment, you bear the risk of an erroneous transfer due to the discrepancy between IBAN and payee name. In this case, the payment service providers involved in executing the transfer are not liable!
Different rule for end users who are business customers (companies):
Guarantees and assurances of characteristics by finAPI are to be interpreted as such only if they are made in written form (with signature) and are designated as "Guarantee".
The end user has access to finAPI’s functionalities to the extent agreed between the end user and the service provider, and use of them is subject to these Terms of Use.
End users are not permitted to use the finAPI functions in any manner not expressly permitted by these Terms of Use.
End users may not access or use finAPI KID/ZAD to
finAPI is entitled to block the end user’s access if there are indications of abusive use or a threat to data security.
(i) were caused intentionally or by gross negligence of finAPI; or
(ii) were caused by slight negligence of finAPI and are attributable to material contractual obligations that are essential for achieving the purpose of this contract or to the violation of duties whose fulfillment enables proper execution of this contract and on whose observance the end user may rely (cardinal obligations). In this case, finAPI’s liability is limited to the damage typically foreseeable for a contract of this type.
Otherwise, finAPI’s liability is excluded regardless of the legal basis, unless finAPI is liable by law on a mandatory basis, in particular for injury to life, body or health, assumption of an explicit guarantee, fraudulent concealment of a defect, or under the Product Liability Act. The limitation of liability also applies to claims against employees and agents of finAPI.
The use of finAPI KID/ZAD is free of charge for the end user.
The contract begins with the conclusion of contract and is concluded for an indefinite period. The contract may be terminated by either party with two weeks’ notice. The right to extraordinary termination remains unaffected. Terminations must be in text form (e.g. email).
The contract ends without any declaration by the end user or by finAPI if
Upon termination of the contract, finAPI will delete the end user’s personal data in accordance with its deletion concept and in compliance with the General Data Protection Regulation (GDPR), unless finAPI is legally entitled or obliged to retain the data.
German law shall exclusively apply to this contract and all disputes arising in connection with it.
If the end user is a merchant, a legal person under public law, or a special fund under public law, Munich is the exclusive place of jurisdiction. In this case, finAPI is also entitled to bring an action at the customer’s registered office.
These Terms of Use apply exclusively. In the case of integration of UK accounts, the Terms and Conditions of Partner token also apply equally. Any conflicting or deviating general terms and conditions of the end user are not recognized by finAPI and have no legal effect, unless finAPI has expressly agreed to them in writing in advance.
Notes
I: Information obligations in the provision of payment services
finAPI GmbH
Adams-Lehmann-Strasse 44
80797 Munich
Germany
Phone: +49 89 416177-555
E-Mail: kontakt@finapi.io
Web: www.finapi.io
Federal Financial Supervisory Authority (BaFin)
E-Mail: poststelle@bafin.de
Web: www.bafin.de
Registered office in Bonn:
Graurheindorfer Str. 108
53117 Bonn
Office in Frankfurt:
Marie-Curie-Str. 24-28
60439 Frankfurt
Payment institution register: BaFin ID 151548
and
Deutsche Bundesbank
Head Office in Bavaria
Ludwigstrasse 13
80539 Munich
E-Mail: info@bundesbank.de
Web: www.bundesbank.de
The payment initiation service provided by finAPI allows end users to initiate payment orders and
payment transactions at the account provider.
The contract for each individual payment initiation is concluded between the end user and finAPI
when the end user enters the necessary data on finAPI's website and gives his explicit consent —
by initiating the payment.
For payment initiation, the end user enters the data for the payment order on finAPI's website. These include in particular:
These data can also be pre-filled by the service provider.
For the purpose of giving consent, the end user enters his personalized security credentials (user ID or similar, possibly account number or IBAN, and PIN/password) on finAPI's website. By confirming the corresponding dialog, the end user gives his explicit consent to access the accounts specifically designated by the end user. The payment order is considered issued when the instruction is sent by finAPI to the account provider. The execution of the payment order may then require further confirmation by the end user, if applicable, by entering a TAN.
Once the payment order has been issued, it can no longer be revoked.
finAPI transmits the payment order on behalf of the end user to the account provider. The maximum execution time therefore depends on the Internet connection and the technical accessibility of the account provider.
The possibility to agree on amount limits for the use of a payment instrument arises from your contractual relationship with the account provider. finAPI has no influence on this.
The account information service provided by finAPI is an online service for communicating consolidated information on payment accounts and other accounts at credit institutions, financial service providers, credit card companies and other financial data providers. The contract between the end user and finAPI for an account information service is concluded when the end user enters the personalized security credentials (user ID or similar, possibly account number or IBAN, and PIN/password) on finAPI's website and gives his explicit consent to the account information service by confirming the corresponding dialog.
The use of finAPI's payment services is free of charge for you. finAPI has no influence on any fees, interest, or exchange rates in your contractual relationship with the account provider.
The pre-contractual information obligations are provided to the end user by finAPI before conclusion of the respective contracts. The communication between the end user and finAPI takes place in the German language. This also applies to the language of the contract.
In case of suspected or actual fraud or security risks, finAPI or the service provider will inform the end user accordingly.
1. he was not able to recognize the loss, theft, misplacement or other unauthorized use of the payment instrument before the unauthorized payment transaction occurred, or
2. the loss of the payment instrument was caused by an employee, agent, branch of the account provider of the end user, or another entity to which the account provider's activities have been outsourced.
1. acted with fraudulent intent, or
2. caused the loss by intentional or grossly negligent breach of
a) one or more duties under § 675l paragraph 1 of the German Civil Code, or
b) one or more agreed conditions for the issuance and use of the payment instrument.
1. the account provider of the end user did not require a strong customer authentication within the meaning of Section 1 paragraph 24 of the German Payment Services Supervision Act, or
2. the payee or his payment service provider did not accept a strong customer authentication within the meaning of Section 1 paragraph 24 of the German Payment Services Supervision Act.
Sentence 1 does not apply if the end user acted with fraudulent intent. In the event of Sentence 1 number 2, the party who did not accept strong customer authentication is obliged to compensate the account provider of the end user for the resulting damage.
The end user is obliged to inform his account provider immediately upon becoming aware of an unauthorized or incorrectly executed payment transaction. Claims and objections of the end user against his account provider are excluded if the end user does not notify his account provider no later than 13 months after the day of the unauthorized or incorrectly executed payment transaction.
In the case of an unauthorized payment transaction, the account provider of the end user has no claim against the end user for reimbursement of his expenditures. The account provider of the end user is obliged to refund the payment amount to the end user immediately and, if the amount has been debited from a payment account, to restore that payment account to the state it would have been in had the unauthorized payment transaction not taken place. This obligation is to be fulfilled immediately, but in any case no later than the end of the business day following the day on which the account provider was informed that the payment transaction was unauthorized or otherwise became aware of it. Claims and objections of the end user against the account provider are excluded if the end user does not notify the account provider no later than 13 months after the debit of an unauthorized or incorrectly executed payment transaction.
9.1 If an end user initiates a payment transaction, he may demand immediate and full refund of the payment amount from his account provider in the event of a non-executed or incorrectly executed payment order. If the amount has been debited from the end user’s payment account, this account must be restored to the state it would have been in had the incorrectly executed payment transaction not taken place. If any charges were deducted from the payment amount contrary to § 675q paragraph 1 of the German Civil Code, the account provider of the end user must immediately transmit the deducted amount to the payee. If the account provider of the end user shows that the payment amount has been received in full by the payee’s payment service provider, liability under this paragraph shall cease to apply.
9.2 If an end user initiates a payment transaction, he may request that his account provider assert the claim according to the second sentence of paragraph 9.1 against the payment service provider of the payee in the event of delayed execution of the payment order. The account provider of the end user may demand that the payee’s payment service provider credit the payment amount to the payee’s account as if the transaction had been executed properly. If the account provider of the end user shows that the payment amount was received in due time by the payee’s payment service provider, liability under this paragraph shall cease to apply.
9.3 The end user has no claims against his account provider under sentences 1 and 2 of paragraph 9.1 if the payment order was executed in accordance with the incorrect payment identifier provided by the payment service user. In this case, however, the end user may demand that his account provider take reasonable steps within its capabilities to recover the payment amount.
9.4 In addition to the claims under paragraph 9.1, an end user may demand from his account provider the reimbursement of fees and interest charged by or debited to his payment account by his account provider in connection with the non-executed or incorrectly executed payment transaction.
9.5 If at least one payment service provider involved in the payment transaction is located within the EEA and at least one outside the EEA, paragraphs 9.1 and 9.2 do not apply to the parts of the payment transaction that occur within the EEA.
If complaints arise, end users may, in accordance with § 60 of the German Payment Services
Supervision Act (ZAG), contact the Federal Financial Supervisory Authority (BaFin). Complaints
must be submitted in writing or by a document recorded in writing with BaFin and should specify
the facts and the reasons for the complaint. The complaint should be addressed to:
Federal Financial Supervisory Authority (BaFin)
Graurheindorfer Str. 108, 53117 Bonn
finAPI is generally willing to participate in dispute resolution proceedings at the Arbitration
Board of the Deutsche Bundesbank. The Arbitration Board at the Deutsche Bundesbank is an
official consumer arbitration board. Its scope of competence is defined by law.
Arbitration Board at the Deutsche Bundesbank
P.O. Box 10 06 02
60006 Frankfurt am Main
Telephone: 069 / 9566-3232
E-mail: schlichtung@bundesbank.de
Internet:
https://www.bundesbank.de/de/service/schlichtungsstelle