DRAFT — must be reviewed and finalized by legal counsel before launch.
Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains what personal data BankStmt collects, why, on what legal basis, who it is shared with, how long it is kept, and the rights you have over it. It is written to meet the transparency requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR. Bank-statement data is inherently sensitive, and it is treated accordingly.
1. Who is responsible for your data
[LEGAL ENTITY NAME], [REGISTERED ADDRESS] (company number [COMPANY REGISTRATION NUMBER]), is the controller for personal data processed about you when you use BankStmt directly. Where your employer or another organisation provides BankStmt to you, that organisation is the controller and we act as its processor under the Data Processing Agreement. Privacy contact: privacy@bankstmt.com. EU/UK representative (where applicable): [EU REPRESENTATIVE, IF APPLICABLE].
2. The data we process
- Account and identity data — name, email address, and the identifier issued by our identity provider.
- Customer content — the bank statements and financial documents you upload, and everything derived from them: transactions, merchants, categories, balances, account numbers as printed on your statements, and account-holder names.
- Usage and technical data — log records, IP address, browser/device information, request timestamps, error diagnostics and API usage counters.
- Billing data — plan, subscription status and billing period. Card details are handled by our payment processor and are never received or stored by us.
- Preferences — language, theme, chosen data-residency region and cookie/consent choices.
- Support correspondence — messages you send us and our replies.
3. Why we process it, and our legal basis
We rely on a specific GDPR Article 6 basis for each purpose. We do not process your data for purposes incompatible with those listed here.
- To provide the Service — parsing statements, categorizing and recognizing merchants, producing analytics, summaries, forecasts and reports, and operating the API. Basis: performance of a contract (Art. 6(1)(b)).
- To authenticate you and keep accounts secure — sign-in, session management, API-key verification, abuse and fraud prevention, rate limiting. Basis: performance of a contract and our legitimate interests in securing the Service (Art. 6(1)(b), 6(1)(f)).
- To bill and collect payment, and to keep accounting records. Basis: performance of a contract and legal obligation (Art. 6(1)(b), 6(1)(c)).
- To operate, monitor, debug and improve the Service, including aggregated and de-identified statistics. Basis: our legitimate interests in maintaining and improving a reliable Service (Art. 6(1)(f)).
- To communicate with you about service changes, security notices and support. Basis: performance of a contract and legitimate interests (Art. 6(1)(b), 6(1)(f)).
- To send marketing email, where you have opted in. Basis: consent (Art. 6(1)(a)) — withdrawable at any time via the unsubscribe link.
- To store non-essential cookies or similar technologies. Basis: consent (Art. 6(1)(a)).
- To comply with law and to establish, exercise or defend legal claims. Basis: legal obligation and legitimate interests (Art. 6(1)(c), 6(1)(f)).
4. Automated processing and AI
BankStmt uses automated processing, including AI models, to extract transactions from documents, assign categories, recognize merchants, detect unusual or potentially fraudulent transactions, forecast cash flow and calculate loan affordability. These outputs are informational and advisory. We do not use them to make decisions producing legal or similarly significant effects about you without human involvement, and we do not make lending, credit or eligibility decisions about you. You can correct any category, merchant or transaction we get wrong, and your corrections take precedence over the model's. Your content is not used to train third-party AI models.
5. Who we share data with
We do not sell personal data. We share it only with: (a) sub-processors that operate the Service on our behalf, listed with their roles and locations on the Sub-processors page, each bound by a written contract and permitted to process data only on our instructions; (b) professional advisers, auditors and insurers under confidentiality; (c) authorities where we are legally required to, after checking the request is valid and, where lawful, notifying you; and (d) a counterparty in a merger, acquisition or asset sale, under equivalent protections.
6. Where your data is stored and international transfers
BankStmt lets you choose the region in which your documents are stored, by country, at upload time — including the United States, United Kingdom, Germany, Ireland, France, Italy, Spain, Sweden, Singapore and India. We keep your content in the region you choose. Where operating the Service requires a transfer outside the EEA or UK, we rely on an adequacy decision where one applies, and otherwise on Standard Contractual Clauses (and the UK Addendum where relevant) together with supplementary technical measures including encryption in transit and at rest. You can request a copy of the relevant safeguards.
7. How long we keep it
- Statements, documents and derived transactions — for as long as your account is active. Deleting a statement removes it and its derived transactions; deleting your account removes your content.
- Account and profile data — for the life of the account, then deleted within 30 days of account deletion, save where longer retention is legally required.
- Backups — deleted content persists in encrypted backups for up to 35 days before being overwritten on the normal backup cycle.
- Billing and accounting records — retained for the period required by tax and company law in our jurisdiction (typically 6–7 years).
- Security and access logs — retained for up to 12 months for security monitoring and incident investigation.
- Support correspondence — retained for up to 24 months after the matter is closed.
8. Your rights
Subject to the conditions in the GDPR/UK GDPR, you have the right to: access a copy of your personal data; have inaccurate data corrected; have data erased; restrict or object to processing (including processing based on our legitimate interests); receive your data in a portable, machine-readable format; withdraw consent at any time without affecting prior lawful processing; and not be subject to solely automated decisions with legal or similarly significant effects. You can export and delete your data yourself in the app at any time, or contact privacy@bankstmt.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need longer. Exercising your rights is free unless a request is manifestly unfounded or excessive.
9. Complaints
If you believe we have handled your data improperly, please contact us first so we can put it right. You also have the right to lodge a complaint with a data protection supervisory authority — in the EU or UK, the authority where you live, work, or where the alleged infringement occurred. Our lead supervisory authority is [LEAD SUPERVISORY AUTHORITY].
10. How we protect your data
Security measures are described in detail on the Security page. In summary: encryption in transit (TLS) and at rest, additional application-level encryption of sensitive fields, strict per-tenant data isolation enforced in the application and database layers, least-privilege access controls, secrets held in a managed secret store, rate limiting and abuse protection, audit logging of significant actions, and regular dependency patching. No system is perfectly secure; we do not claim it is.
11. Data breaches
We maintain an incident response process. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will inform you without undue delay where the risk is high. Where we act as a processor, we will notify the controller without undue delay.
12. Cookies and local storage
We use strictly necessary storage to keep you signed in and remember preferences such as language, theme and your consent choice. Anything beyond strictly necessary is used only with your consent, which you can change at any time. Full detail is in the Cookie Policy.
13. Children
The Service is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact privacy@bankstmt.com and we will delete it.
14. Changes to this policy
We may update this policy. Material changes will be notified by email or in-app before they take effect, and the "last updated" date above always reflects the current version.
Contact
Questions about these documents or your data? Contact privacy@bankstmt.com. For security matters, contact security@bankstmt.com.