GDPR Compliance
Your bank statements contain sensitive financial data. We've built BankStatementLab from the ground up with data protection at its core. Here's exactly how we protect your information.
Last updated: March 8, 2026
Our 6 data protection commitments
Every feature we build starts with one question: how do we protect our users' data?
Zero long-term file storage
Your PDF files are never stored on our servers. We never keep your source documents.
End-to-end encryption
All data transfers use TLS 1.3 encryption. Your files are protected from upload to download.
No data sharing or selling
We never sell, share, or monetize your data. Your financial information is never used for advertising or analytics.
Full user control
Configure your own data retention policy. Choose auto-delete from 1 to 30 days, or manage your data manually.
Right to erasure guaranteed
Delete your account and all associated data at any time. We perform a complete hard-delete — no residual data remains.
EU-based infrastructure
Our servers and databases are hosted in the European Union, subject to the strictest data protection regulations in the world.
Our commitment to GDPR
Data we collect
How we process your files
Encryption and security measures
Automatic file deletion
Configurable data retention
Your rights under GDPR
Sub-processors
Data breach notification
Account deletion and right to be forgotten
Data Processing Agreement (DPA)
Contact us about data protection
Questions about data protection?
Our team is here to help. Whether you need a DPA, have compliance questions, or want to learn more about our security practices.