Skip to main content

GDPR Compliance

Your bank statements contain sensitive financial data. We've built BankStatementLab from the ground up with data protection at its core. Here's exactly how we protect your information.

Last updated: August 29, 2026

Our 6 data protection commitments

Every feature we build starts with one question: how do we protect our users' data?

Automatic source-PDF deletion

Source PDFs are deleted after processing. Exception: source PDFs for multi-table extractions by signed-in users may be retained for up to 7 days for quality review.

TLS 1.3 encryption

All data transfers use TLS 1.3 encryption. Your files are protected in transit, from upload to download.

No data selling or advertising use

We never sell or monetize your data, and your financial information is never used for advertising. Processing is limited to what is necessary to provide and secure the service and meet applicable legal obligations.

Full user control

Configure your own data retention policy. Choose auto-delete from 1 to 30 days, or manage your data manually.

Right to erasure guaranteed

Close your account from your profile at any time. This disables access and performs the operational deletion cascades described below; contact support to exercise a separate right-to-erasure request.

EU-based infrastructure

Our servers and databases are hosted in the European Union, subject to the strictest data protection regulations in the world.

Data-protection controls
TLS 1.3 Encrypted
Automatic Deletion
EU Data Hosting

Our commitment to GDPR

BankStatementLab is fully committed to the General Data Protection Regulation (EU) 2016/679. As a service that processes bank statements — highly sensitive financial documents — we hold ourselves to the highest standards of data protection. Under the GDPR, we process documents on behalf of users who determine the purposes of processing. We convert documents to structured formats (Excel, CSV, OFX), secure and support the Service, and meet legal obligations. We do not profile your financial data or use it for advertising or other unrelated purposes. Source PDFs are deleted after processing. Exception: source PDFs for multi-table extractions by signed-in users may be retained for up to 7 days for quality review. Retained PDFs are accessible only to authorized administrators. They cannot be downloaded by users or through the public API.

Data we collect

We follow the principle of data minimization. We collect only what is strictly necessary to provide the service: • Account information: email address, hashed password, language preference • Billing data: managed entirely by Stripe — we never store credit card numbers • Source PDFs are deleted after processing. Exception: source PDFs for multi-table extractions by signed-in users may be retained for up to 7 days for quality review. • Extraction results: structured transaction data (columns, amounts, dates) kept until you delete it or until the automatic deletion period you configure applies • PDF splitter sessions: pseudonymized technical state linked to your account (file and page counts, split points, outcome, and duration), retained for no more than 365 days to diagnose and improve the tool; no PDF content, filename, thumbnail, or text is stored in this history • Technical logs: minimized usage metrics used for security, diagnosis, and service improvement; when they remain linked to an account, we do not present them as anonymous We do NOT collect: your IP address for tracking, browsing history, device fingerprints, or any data beyond what is listed above.

How we process your files

When you upload a bank statement PDF, here is exactly what happens: 1. Your file is uploaded via an encrypted TLS 1.3 connection 2. Source PDFs are deleted after processing. Exception: source PDFs for multi-table extractions by signed-in users may be retained for up to 7 days for quality review. 3. Our AI extraction engine reads and structures the data 4. The structured data (transactions, columns) is saved to your account 5. Retained PDFs are accessible only to authorized administrators. They cannot be downloaded by users or through the public API. This entire process typically takes a few seconds. For guest users (without an account), the extraction and its data are deleted 24 hours after they are created.

Encryption and security measures

We implement multiple layers of security to protect your data: • Transport encryption: all communications between your browser and our servers use TLS 1.3, the latest encryption standard • Password security: all passwords are hashed using bcrypt with salt — we never store passwords in plain text • Secure authentication: JWT-based authentication with secure, httpOnly cookies • Access control: strict role-based access limits extraction access to you and authorized personnel when operational support, security, or legal obligations require it • Infrastructure security: our servers run on hardened environments with automatic security updates • Dependency monitoring: we regularly audit and update all software dependencies

Automatic file deletion

File deletion is automatic and systematic where a defined retention rule applies: • Source PDFs are deleted after processing. Exception: source PDFs for multi-table extractions by signed-in users may be retained for up to 7 days for quality review. • Temporary processing files (sliced pages): cleaned up automatically once processing is finished • Guest extractions: fully deleted 24 hours after they are created • Registered-user extractions: permanently deleted when you delete them or when your 1-to-30-day auto-delete rule applies, including their associated transaction data Our automated cleanup runs daily to apply each user's retention setting. Each run is logged and monitored to guarantee reliability.

Configurable data retention

For registered users, we give you full control over your data retention: • Auto-delete OFF (default): your extraction results are kept until you manually delete them • Auto-delete ON: choose a retention period from 1 to 30 days (initially 14 days when enabled). Extractions older than your chosen period are automatically and permanently deleted • PDF splitter technical sessions: automatically deleted no later than 365 days after creation and immediately when the account is closed You can configure your retention policy at any time from your profile settings. Changes apply immediately — if you reduce your retention period, extractions that exceed the new limit will be deleted during the next daily automated cleanup. For billing data, we retain invoices for 7 years as required by French tax law. After account closure, access is disabled; contact support to exercise your erasure rights.

Your rights under GDPR

Under the GDPR, you have the following rights, and we make it easy to exercise them: • Right of access (Art. 15): request a copy of all data we hold about you • Right to rectification (Art. 16): correct any inaccurate personal data • Right to erasure (Art. 17): request erasure of your personal data; self-service account closure disables access and performs the operational deletion cascades described below • Right to restriction (Art. 18): request that we limit processing of your data • Right to data portability (Art. 20): export your extraction data in standard formats (Excel, CSV, OFX) at any time • Right to object (Art. 21): object to any processing of your data To exercise any of these rights, contact us at support@bankstatementlab.com. We respond to all requests within 30 days, as required by the GDPR.

Controlled technical services

A limited number of technical services support the operation of BankStatementLab. Each service is selected and governed by contractual data-protection obligations: • Hosting, database, payment, transactional email, and customer support • Automated AI extraction used solely to perform the requested conversion • Consent-based website analytics and advertising conversion measurement Each operation is limited to its stated purpose. Where processing occurs outside the European Union, appropriate transfer safeguards apply. The current list of services, purposes, and locations is published on our Technical services page.

Data breach notification

In the unlikely event of a data breach, we commit to: • Notifying the relevant supervisory authority (CNIL in France) within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR • Notifying affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Article 34) • Documenting all breaches, their effects, and the remedial actions taken We maintain incident response procedures and regularly test our systems to prevent breaches. To date, we have not experienced any data breach.

Account deletion and right to be forgotten

When you close your account from your profile: • Access to the account is disabled and the account record is marked deleted • Active API keys are revoked and API request logs are deleted • Stored OFX banking identities and PDF-split technical sessions are deleted • Support-file submissions are anonymized and their uploaded binaries are removed Self-service account closure does not promise that every account or extraction record is immediately hard-deleted. To exercise a separate right-to-erasure request under Article 17 of the GDPR, contact support@bankstatementlab.com.

Data Processing Agreement (DPA)

For enterprise and business customers who need a formal Data Processing Agreement (DPA) as required by Article 28 of the GDPR, we provide a standard DPA upon request. Our DPA covers: • Nature and purpose of processing • Types of personal data processed • Categories of data subjects • Contractual obligations applicable to technical services • Data security measures • Breach notification procedures • Data deletion upon contract termination To request a DPA, contact us at support@bankstatementlab.com.

Contact us about data protection

For any questions about our data protection practices, GDPR compliance, or to exercise your rights: • Email: support@bankstatementlab.com • Contact form: available on our contact page We strive to respond to all privacy-related inquiries within 30 days. For urgent matters related to data security, we aim to respond within 24 hours. If you believe your data protection rights have been violated, you also have the right to lodge a complaint with your local supervisory authority. In France, this is the CNIL (Commission Nationale de l'Informatique et des Libertés).

Questions about data protection?

Our team is here to help. Whether you need a DPA, have compliance questions, or want to learn more about our security practices.