Legal
GDPR
If you are in the EU or the UK, this is how the GDPR applies to what we hold and to the rights you have over it.
Last updated 12 August 2026
The short version
- You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. One month, no charge, no reason needed.
- Your statements are processed to produce your output and for nothing else. AI models read them; they may not train on them.
- Your data is processed in India, which has no adequacy decision — the transfer runs on standard contractual clauses.
- Ask through the contact page and we will action it, not argue it.
This summary is provided for convenience. The clauses below govern.
1. Who this page is for
This page applies where the EU General Data Protection Regulation, or the UK GDPR as retained in the Data Protection Act 2018, governs our processing of your personal data — broadly, if you are in the EU, the EEA or the UK when you use the service. References to the GDPR should be read as covering both.
It sits alongside the privacy policy, which sets out what we collect and why in full. Where this page and the privacy policy differ for a reader in the EU or the UK, this page prevails.
Statement Converter
New Delhi, India
[email protected]
2. Controller, processor, and which we are
- Your account data — name, email, plan and billing record. We are the controller. We decide what is held and why.
- Statements you upload — we are the processor and you are the controller. You decide which files to convert and for what; we convert them on your instruction and return the output. Where the statements belong to a client whose books you keep, that client's data is yours to control and ours only to process.
These terms, together with the terms and conditions and the security measures in the privacy policy, are the written terms Article 28 requires between a controller and a processor: we process only on your documented instructions, bind everyone with access to confidentiality, apply the measures in clause 9, help you answer data subject requests, and delete the data at the end of the retention period in clause 7. If your own compliance needs a separate signed data processing agreement, ask through the contact page and we will sign one.
3. What we process, and the Article 6 basis
- Running your account — name, email, hashed password, plan. Article 6(1)(b), performance of the contract you entered on signing up.
- Converting a statement — the file you upload, the pages read by an AI model, and the output produced. Article 6(1)(b), performance of the contract; this is the service itself.
- Taking payment — billing name, email and a payment reference. Article 6(1)(b), and Article 6(1)(c) where a tax or accounting record must be kept.
- Answering you — whatever you write in the contact form. Article 6(1)(f), our legitimate interest in replying to someone who wrote to us.
- Keeping the service up and secure — IP address, browser and device, request timestamps. Article 6(1)(f), our legitimate interest in preventing abuse and diagnosing faults, balanced against the limited nature of the data and its short life.
Financial transaction data is not a special category under Article 9, so no Article 9 condition is engaged. We nonetheless treat it as sensitive, because it is classified that way under the Indian rules we also operate under and because the harm from mishandling it is obvious.
4. AI models and automated processing
Extraction is performed by AI models, which read the pages of a statement to identify transactions, dates, amounts and balances. Where the model is run by a third-party provider, pages are transmitted to it for that purpose alone, under terms prohibiting training on the content. Providers are listed in clause 6.
This is automated processing, but it is not a decision within Article 22: we produce a converted file, and nothing the system does produces a legal effect concerning you or similarly significantly affects you. We do not profile you, score you, or use your statements to decide anything about you. What is decided from the output is decided by you, after you have checked it.
5. Your rights, and how to use them
- Access (Art. 15) — a copy of the personal data we hold about you, and the detail of how it is processed.
- Rectification (Art. 16) — correction of anything inaccurate, completion of anything incomplete.
- Erasure (Art. 17) — deletion, where we no longer need the data or where you withdraw consent it rested on.
- Restriction (Art. 18) — a pause on processing while an accuracy dispute or an objection is worked out.
- Portability (Art. 20) — your data in a structured, commonly used, machine-readable form, or sent directly to another provider where that is feasible.
- Objection (Art. 21) — to any processing that rests on legitimate interests. We stop unless we can show compelling grounds that override your interests.
- Withdrawal of consent (Art. 7(3)) — at any time, as easily as it was given, without affecting processing already carried out.
- Complaint (Art. 77) — to a supervisory authority, as in clause 13.
Requests go through the contact page. We respond within one month, extendable by two further months for a request that is genuinely complex, in which case we will tell you inside the first month and say why. No fee is charged and no reason is required. We may ask for enough information to be sure who you are before we act on a request — sending someone else's financial data to the wrong person is the failure this is guarding against.
Where you are the controller and we are the processor, a request from your client comes to you, not to us. Tell us and we will help you answer it.
6. Sub-processors
We engage the sub-processors below, each under a written contract imposing the same obligations we carry, and each acting only on our instructions.
| Sub-processor | Function |
|---|---|
| Cloud hosting | Runs the service and stores uploads and output |
| AI model provider | Reads the pages of an uploaded statement to extract the transactions; contractually barred from training on them |
| Dodo Payments | Merchant of record — takes card and UPI payments and issues the invoice; holds the card details, which never reach us |
| Transactional email | Sends account email — sign-in, resets and billing notices |
Where we intend to add or replace a sub-processor, we will update this list and tell account holders in advance, so that you have the opportunity to object under Article 28(2). If you object on reasonable grounds and we cannot offer an alternative, you may cancel and clause 9 of the terms governs what is refunded.
7. How long we keep it
| Category | Retention period | Reason |
|---|---|---|
| Uploaded statement PDFs | 90 days after conversion, then deleted automatically | Long enough to re-download or re-run a conversion, no longer |
| Converted sheets | 90 days after conversion, then deleted automatically | The same window as the file they came from — download them before it closes |
| Passwords for locked PDFs | Never stored — held in memory for one conversion | There is no purpose that needs them a second later |
| Account details | While the account is open, then 90 days | The window lets you reopen an account closed by mistake |
You may delete an uploaded file or its output yourself at any point before the period ends. Deletion removes data from the live service immediately; encrypted backups are overwritten within a further 30 days.
8. Transfers to India
Statement Converter is built and run from India. Personal data you give us is therefore transferred to and processed in India, and a sub-processor may process it elsewhere.
India is not the subject of an adequacy decision by the European Commission or by the UK government. Transfers accordingly rely on the standard contractual clauses adopted by the Commission under Article 46(2)(c), and on the UK Addendum or International Data Transfer Agreement for UK data, together with an assessment of the destination's laws and the technical measures in clause 9. A copy of the clauses we rely on is available through the contact page.
9. Security
The measures required by Article 32 are set out in section 9 of the privacy policy: TLS in transit and encryption at rest, salted password hashes, restricted and logged production access, non-enumerable object identifiers, and routine patching. They apply identically to EU and UK data.
10. Personal data breaches
Where we are the controller and a breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it under Article 33, and notify you directly without undue delay where the risk is high.
Where we are the processor — that is, for the statements you upload — we notify you without undue delay after becoming aware, with the detail you need to make your own notification, and assist you in making it.
11. Cookies
We set only cookies that are strictly necessary for the service to work: a session cookie for authentication and a preference cookie for display choices. Under the ePrivacy Directive these are exempt from consent, which is why you are not asked to dismiss a banner. We run no advertising cookies, no third-party trackers and no cross-site analytics.
12. Representative and data protection officer
We have not appointed a representative in the EU or the UK under Article 27. Our processing of EU and UK data is occasional, is not large-scale processing of special category data, and is unlikely to result in a risk to the rights and freedoms of individuals. If that ceases to be true — and marketing the service into Europe would be enough to change it — we will appoint one and name it here before we do.
We have not appointed a data protection officer, none being required under Article 37: our core activities are neither regular and systematic monitoring of data subjects on a large scale nor large-scale processing of Article 9 data. Data protection questions go to the address in clause 1 and are answered by a person.
13. Complaints
If you think we have handled your data badly, tell us first — most complaints are a misunderstanding we can fix the same day. Write to [email protected] or use the contact page.
You may also complain to a supervisory authority, whether or not you come to us first: in the EU, the authority in the member state where you live, work, or where the problem occurred; in the UK, the Information Commissioner's Office. Nothing on this page restricts that right, and you may also seek a judicial remedy.