GDPR Compliance
Your bank statements contain sensitive financial data. We've built BankStatementLab from the ground up with data protection at its core. Here's exactly how we protect your information.
Last updated: August 29, 2026
Our 6 data protection commitments
Every feature we build starts with one question: how do we protect our users' data?
Automatic source-PDF deletion
Source PDFs are deleted after processing. Exception: source PDFs for multi-table extractions by signed-in users may be retained for up to 7 days for quality review.
TLS 1.3 encryption
All data transfers use TLS 1.3 encryption. Your files are protected in transit, from upload to download.
No data selling or advertising use
We never sell or monetize your data, and your financial information is never used for advertising. Processing is limited to what is necessary to provide and secure the service and meet applicable legal obligations.
Full user control
Configure your own data retention policy. Choose auto-delete from 1 to 30 days, or manage your data manually.
Right to erasure guaranteed
Close your account from your profile at any time. This disables access and performs the operational deletion cascades described below; contact support to exercise a separate right-to-erasure request.
EU-based infrastructure
Our servers and databases are hosted in the European Union, subject to the strictest data protection regulations in the world.
Our commitment to GDPR
Data we collect
How we process your files
Encryption and security measures
Automatic file deletion
Configurable data retention
Your rights under GDPR
Controlled technical services
Data breach notification
Account deletion and right to be forgotten
Data Processing Agreement (DPA)
Contact us about data protection
Questions about data protection?
Our team is here to help. Whether you need a DPA, have compliance questions, or want to learn more about our security practices.