DRAFT — must be reviewed and finalized by legal counsel before launch.
Sub-processors
Last updated: 20 July 2026
We use a deliberately small number of sub-processors to operate BankStmt. Each is bound by a written contract, may process data only on our instructions, and is subject to data protection obligations no less protective than our own. We give at least 30 days' notice before adding or replacing a sub-processor — subscribe to notifications by contacting privacy@bankstmt.com.
Infrastructure and processing
- Amazon Web Services (AWS) — cloud hosting, compute, database and object storage. Region determined by the data-residency region you select. Processes all Customer Data at rest and in transit.
- Amazon Bedrock (AWS) — AI model inference for document extraction, categorization, merchant recognition and insights. Processes statement content submitted for analysis. Content is not used to train the underlying models.
- AWS Secrets Manager / KMS (AWS) — management of encryption keys and application secrets. Does not process Customer Data directly.
Identity and authentication
- Keycloak, self-hosted on our AWS infrastructure — authentication, session and credential management. Processes account identity data (name, email, user identifier).
Billing
- Stripe — subscription billing and payment processing. Processes billing contact data and payment details. Card data is submitted directly to Stripe and is never received or stored by us.
Operations and monitoring
- Sentry — application error tracking and diagnostics, where enabled. Processes technical error data and may incidentally capture limited context; configured to minimise personal data.
Changes to this list
This page is the authoritative, current list. Where you have a Data Processing Agreement with us, you may object to a new sub-processor on reasonable data protection grounds as described in that agreement.
Contact
Questions about these documents or your data? Contact privacy@bankstmt.com. For security matters, contact security@bankstmt.com.