The rules we work to, in one place
A summary of how data protection law applies to Export Bank Statement. The full, binding version is our privacy policy; this page is the quick read for a client file or a supplier review.
Which law, and what it means here
UK GDPR and EU GDPR
Export Bank Statement is the data controller. We rely on contract, legitimate interests, consent (for analytics) and legal obligation (for tax records). You can access, correct, delete, restrict, object and port your data; we reply within one month, and you can complain to the ICO or your local authority.
Transfers outside the UK and EEA
Some providers run in the United States and Singapore. Those transfers rely on the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or the provider's adequacy arrangements.
India: DPDP Act
Users in India have equivalent rights under the Digital Personal Data Protection Act, including access, correction, erasure and grievance redressal, through the same email address.
California: CCPA
We don't sell or share personal information as the CCPA defines those terms. You can request access to or deletion of your data.
How long we keep things
Uploaded statements
Not retained. Discarded once converted.
Account records
While your account exists, then deleted on request.
Usage counts
Days for daily limits; about two months for monthly allowances.
Payment records
As long as tax law requires, typically six years.
Server logs
A short period, for security and debugging.
Card payments
Card details never reach us
What we don't hold
No SOC 2 or ISO 27001 today
