Data processing agreement

For firms who need this on file before onboarding a supplier. It describes the same system the privacy policy does, in the terms a data protection review asks for.

Last updated 7 September 2026

Roles

Where you convert statements belonging to your own clients, you are the controller of that personal data and we are your processor. We process it only to provide the service, and only on your instructions — which, in practice, are the conversions you ask for.

For your own account data — your email address, your plan, your usage — we are the controller.

What is processed

The subject matter is the conversion of bank and credit card statements into accounting formats. The duration is for as long as your account exists, subject to the retention you set.

The categories of data are those printed on a statement: account holder name, account number as printed, institution, transaction dates, amounts, balances and descriptions. Descriptions can identify counterparties, so they should be treated as personal data whether or not they name a person.

The data subjects are the account holders whose statements you convert, and any individuals named in the transactions.

Where processing happens

Digital statements are processed in the browser on your own device and their contents do not reach our infrastructure. Scanned statements are processed on our servers and by a vision model provider.

Our infrastructure providers operate internationally. Where personal data is transferred across borders, it is done under the transfer mechanisms those providers maintain.

Sub-processors

We use the following sub-processors. We will keep this list current, and material additions are announced on this page.

  • Vercel — hosting for this application. Sees requests and IP addresses, not statement contents beyond what passes through a request.
  • Supabase — database and authentication, hosting your account record and your extracted transactions.
  • Cloudflare R2 — object storage for the original PDF, when you choose to keep it.
  • OpenRouter — routes scanned statements to a vision model. Requests are sent with data collection denied, so they are only served by providers that do not retain or train on what is sent.
  • Paddle — merchant of record for payments. Paddle, not us, is the seller on your invoice, and it handles card details end to end.
  • Resend — transactional email, such as sign-in links.

Security

Access to stored data is enforced at the database with row-level security, so a request can only ever return rows belonging to the authenticated account. Stored PDFs are reached through short-lived URLs scoped to one object and one method; the credentials for the underlying bucket are held server-side and are never issued to a browser.

Authentication is passwordless — an emailed link or Google — so there is no password for us to store or for anyone to steal from us.

Everything is served over TLS.

Deletion and return

You control retention, including setting it so nothing is stored at all. Data past its retention is deleted daily, covering both the extracted transactions and the stored PDF.

You can delete any statement immediately, and closing your account deletes your data with it. Your data is exportable at any time in eight formats, which is the return mechanism — there is nothing you can put in that you cannot get back out.

Assistance

We will help you respond to requests from data subjects, and will tell you without undue delay if we become aware of a breach affecting personal data you have entrusted to us.

If your review needs something this page does not cover, write to us and ask. We would rather answer a specific question than publish a longer document nobody reads.

The rest of it

Something here not answered, or your review needs a detail these pages do not cover? Write to us.