Data Processing Agreement
Last updated: February 2026
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between you ("Customer", "Controller") and the operator of Bank Statement Matcher ("we", "us", "Processor"). It applies where we process personal data on your behalf in the course of providing the Service, in particular where you are a business customer, accountant, or bookkeeper uploading data relating to your own clients or third parties. In case of any conflict on data-protection matters, this DPA prevails over the Terms.
1. Definitions
"GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Sub-processor" have the meanings given in the GDPR. "Customer Personal Data" means personal data contained in the files and content you upload to or generate through the Service.
2. Roles of the Parties
For Customer Personal Data, you act as the Controller (or as a processor acting on behalf of your own clients) and we act as your Processor (or sub-processor). Each party will comply with its respective obligations under applicable data-protection law.
3. Scope and Instructions
We will process Customer Personal Data only to provide the Service and in accordance with your documented instructions, including as set out in the Terms, this DPA, and your use of the Service's features. We will inform you if, in our opinion, an instruction infringes applicable data-protection law.
4. Subject Matter, Duration, Nature and Purpose
The details of the processing are:
- Subject matter: Provision of automated bank-statement, reference-file and receipt matching and reconciliation.
- Duration: For the term of your use of the Service, subject to the retention and deletion terms below.
- Nature and purpose: Extraction, structuring, matching, storage and export of transaction and document data.
- Types of personal data: Names, account and transaction details, amounts, dates, references, and any other personal data contained in the files you upload.
- Categories of data subjects: You, your staff, and your customers or counterparties whose data appears in uploaded documents.
5. Confidentiality
We ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and process the data only as instructed.
6. Security
We implement appropriate technical and organisational measures to protect Customer Personal Data, including encryption in transit (TLS), access controls, audit logging, prompt deletion of raw uploads after processing, and encryption at rest where provided by our hosting infrastructure. These measures are described further in our Privacy Policy.
7. Sub-processors
You authorise us to engage the sub-processors listed in our Privacy Policy to support the provision of the Service. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will give notice of material changes to our sub-processors so you can object on reasonable data-protection grounds.
8. Assistance to the Controller
Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to data-subject requests (access, rectification, erasure, portability, restriction, and objection) and to meet your obligations regarding security, breach notification, and data-protection impact assessments. The Service also provides self-service tools to delete individual jobs or your entire account and associated data.
9. Personal Data Breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information reasonably necessary for you to meet your notification obligations.
10. International Transfers
Where Customer Personal Data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses, as described in our Privacy Policy.
11. Return and Deletion
Raw uploaded files are deleted promptly after processing. Structured results are retained for a limited retention window and then automatically purged. On termination, or on your request, we will delete Customer Personal Data in accordance with these terms, save where retention is required by law.
12. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits conducted by you or an independent auditor.
13. Contact and Acceptance
This DPA is entered into by your acceptance of the Terms and use of the Service in a business capacity. If you require a countersigned copy or have questions, contact us at legal@bankstatementmatcher.com.
Processor:
[REGISTERED ADDRESS]
[CITY, POSTAL CODE], Republic of Cyprus
Company registration no.: [REGISTRATION NUMBER]
This DPA supplements our Terms and Privacy Policy.