Privacy Policy

Your privacy matters to us. This page will contain our comprehensive privacy policy.

Effective date: August 4, 2025

Owner/Operator: FACTIONER SRL (“StmtScan,” “we,” “us,” “our”)

Address: Gabor Aron street nr 26, Târgu Mureș, Romania

Website & Service: https://stmtscan.com (the “Service”)

Contact: office@stmtscan.com

This Policy explains how we collect, use, share, and protect information when you use the Service. If you use the Service on behalf of a company, you confirm you are authorized to do so.

1) Who we are & roles under GDPR

  • For account and site data, StmtScan is the Controller.
  • For documents (e.g., bank statements) uploaded by business customers, we typically act as a Processor for that customer (the Controller).

2) What we collect

Personal data you provide

  • Account & contact: name, email.
  • Documents you upload: bank statements and related content (which may include personal data).
  • Payments: billing details processed by our payments provider (we don’t store full card numbers).

Automatically collected (non-personal & personal)

  • Cookies and similar tech (see §10): device, IP, usage, and diagnostics.

3) Purpose of data collection (why we process data)

We process data to:

  • Provide and operate the Service (ingest, parse, and export structured outputs from bank statements).
  • Secure, maintain, and improve performance, accuracy, and reliability (including quality assurance, debugging, and model prompts evaluation).
  • Support you (respond to requests, provide onboarding and training).
  • Billing and account administration (subscriptions, receipts, fraud prevention).
  • Analytics and product development to understand features in use and prioritize improvements (using aggregated/de-identified insights wherever possible).
  • Legal compliance (tax, accounting, security, and responding to lawful requests).

Legal bases (GDPR): performance of a contract, legitimate interests (security, improvement, fraud prevention), and compliance with legal obligations. Where required, we rely on consent (e.g., optional Data Contribution Program).

4) How we use documents and outputs

  • We process uploaded bank statements to generate structured data (CSV/JSON/metrics) for your organization.
  • By default, we retain raw copies of your documents for research, quality improvement, and commercial datasets.
  • You may opt out of this retention by emailing us at office@stmtscan.com (see §8).

5) Data sharing (who we share with and why)

We may share information with:

  • Service providers. We use third-party service providers for hosting, storage, parsing, payments, analytics, and support. We share only the minimum data needed for them to perform services on our behalf, under contract, and subject to appropriate safeguards. Details of our current providers are available on request.
  • Professional advisors (lawyers, accountants, auditors) under confidentiality.
  • Legal and safety: if required by law or to protect rights, security, customers, or the public.
  • Business transfers: in a merger, acquisition, financing, or sale of assets, your data may be transferred under continued protections.
  • Aggregated/De-identified data that cannot reasonably identify you or your organization (e.g., usage statistics, performance benchmarks) for analytics, research, and improving the Service.
  • With your consent: unless you opt out of our Data Contribution Program (see §8), we may share raw documents and datasets with trusted partners (e.g., research institutions or analytics partners) to improve industry benchmarks and document-processing quality.

We do not sell personal data by default. Any broader reuse or sharing of document content is subject to opt-out rights.

6) Retention

  • Original documents: retained up to 365 days by default (configurable by contract).
  • Derived data/outputs: retained as needed to provide the Service and meet legal obligations.
  • Deletion requests are honored within 30 days of a verifiable request.

7) International transfers

We process data in us-east-1 (USA) and other locations of our providers. When transferring personal data outside the EEA/UK, we rely on appropriate safeguards (e.g., SCCs) and vendor compliance measures.

8) Data Contribution Program (opt-out)

By default, we retain and use raw copies of uploaded PDFs to:

  • Improve extraction accuracy,
  • Build benchmarks and research datasets, and
  • Collaborate with vetted partners.

We honor opt-out requests at any time. To opt out, email us at office@stmtscan.com with your request. Upon opt-out, we will stop new use and delete retained copies within 30 days.

 

9) Your rights

Depending on your location, you may have the right to request access, correction, deletion, restriction, portability, or objection to certain processing. To exercise rights, contact office@stmtscan.com. We may need to verify your identity. You can also complain to your local supervisory authority.

10) Cookies

We use necessary cookies (to run the site) and analytics cookies (to measure usage and improve features). You can manage cookies via your browser settings and, where available, our cookie banner preferences.

11) Security

We use industry-standard measures, including encryption in transit (HTTPS) and at rest (AES-256), access controls, logging, and backups. No method is 100% secure; please use strong passwords and protect your account.

12) Children’s privacy

The Service is for business use and not directed to children. We do not knowingly collect data from children. If you believe a child provided us personal data, contact us and we will delete it.

13) Third-party links and services

Third-party sites and services are governed by their own terms and privacy policies. We are not responsible for their practices.

14) Changes to this Policy

We may update this Policy. We will notify you by email (to the address in your account) and/or by posting the updated Policy with a new effective date.

15) Contact

Questions or requests: office@stmtscan.com

Postal: FACTIONER SRL, Gabor Aron street nr 26, Târgu Mureș, Romania

 

 

 

Last updated: August 4, 2025