BankStmt ← Back to bankstmt.com

DRAFT — must be reviewed and finalized by legal counsel before launch.

Data Processing Agreement

Last updated: 20 July 2026

This Data Processing Agreement ("DPA") applies where you use BankStmt as an organisation and we process personal data on your behalf. It forms part of the Terms of Service. In this DPA you are the "Controller" and we are the "Processor", and terms such as personal data, processing, data subject and supervisory authority have the meanings given in the GDPR. Where you require a countersigned copy, contact privacy@bankstmt.com.

1. Subject matter, duration, nature and purpose

We process personal data to provide the Service described in the Terms: ingesting and parsing bank statements, extracting and categorizing transactions, recognizing merchants, generating analytics, summaries and reports, and making that data available to you through the application and API. Processing lasts for the term of your subscription plus the deletion periods in section 10.

2. Categories of data subjects and personal data

  • Data subjects — your authorised users, your account holders, and individuals appearing in the statements you upload (for example counterparties and payees).
  • Personal data — names, email addresses and user identifiers; bank account identifiers as printed on statements; transaction dates, amounts, descriptions, merchants and balances; derived categories and analytics; usage and log data.
  • No special-category data is required by the Service. You must not upload special-category data (GDPR Art. 9) or criminal-offence data unless separately agreed in writing.

3. Our obligations as processor

  • We process personal data only on your documented instructions, including regarding international transfers, unless required otherwise by law — in which case we will inform you first unless the law prohibits it.
  • We will promptly inform you if, in our opinion, an instruction infringes data protection law.
  • Personnel authorised to process personal data are bound by confidentiality obligations.
  • We implement appropriate technical and organisational measures under GDPR Art. 32, as described in section 6 and on the Security page.
  • We assist you, taking into account the nature of processing and the information available to us, with data subject requests, security obligations, breach notification, data protection impact assessments and prior consultation.

4. Your obligations as controller

You warrant that you have a lawful basis for the personal data you upload and for instructing us to process it, that you have provided any required notices to data subjects, and that your instructions comply with applicable law. You are responsible for the accuracy of the data you provide and for managing your users' access.

5. Sub-processors

You give general authorisation for us to engage sub-processors. Current sub-processors, their roles and their locations are published on the Sub-processors page. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain fully liable to you for their performance. We will give at least 30 days' notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds; if we cannot resolve the objection, you may terminate the affected Service without penalty for the remainder of the prepaid term.

6. Security measures

Measures include encryption of personal data in transit and at rest, additional application-level encryption of sensitive fields, strict logical separation of each tenant's data enforced in the application and database layers, role-based least-privilege access, managed secret storage, network controls, rate limiting and abuse protection, audit logging, dependency patching, backup and restore procedures, and an incident response process. Measures are reviewed and may be updated provided the level of protection is not reduced.

7. Data subject requests

The Service provides self-service export and deletion so you can respond to data subject requests directly. Where a data subject contacts us instead, we will refer them to you and will not respond substantively without your instruction, unless legally required. We will assist you with any request you cannot fulfil through the Service.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, with the information available to us to help you meet your notification obligations, and will provide updates as the investigation progresses.

9. International transfers

The Service lets you select the storage region for your content by country. Where providing the Service requires a transfer of personal data outside the EEA or UK, we rely on an adequacy decision where one applies, and otherwise on the Standard Contractual Clauses (with the UK Addendum where relevant), which are incorporated into this DPA by reference, together with supplementary technical measures.

10. Return and deletion

You may export your data at any time during the term. On termination, or on your written request, we will delete personal data processed on your behalf within 30 days, except where retention is required by law. Data in encrypted backups is overwritten within the normal backup cycle of up to 35 days.

11. Audits

On reasonable written request, no more than once per twelve months (or after a material breach), we will make available information necessary to demonstrate compliance with this DPA and will respond to reasonable security questionnaires. Where an on-site audit is legally required, it will be at your cost, during business hours, under confidentiality, and arranged so as not to disrupt the Service or other customers.

12. Order of precedence

In the event of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service, in each case in respect of data protection.

Contact

Questions about these documents or your data? Contact privacy@bankstmt.com. For security matters, contact security@bankstmt.com.