Data processing agreement
Last updated September 30, 2026. This data processing agreement applies when you, as a business or an accounting firm, upload files containing personal data to BankReconciler. It forms part of the terms of service. You can download a copy as PDF for your records.
Parties and roles
You, the account holder, are the controller of personal data in the files you upload. The company shown in the company details image on this page, which operates BankReconciler, is the processor and processes that data only on your documented instructions.
Subject and duration
- Subject. Reconciliation of bank and card statements against accounting records.
- Data. Names of payees, customers and vendors, account and reference numbers, transaction descriptions, dates and amounts, and user account details.
- Data subjects. Your customers, vendors, employees and other people who appear in your financial records, and your users.
- Duration. For as long as your account is active and the retention period you set has not ended.
Processor obligations
- Process personal data only to provide the service and on your instructions.
- Ensure that people authorized to process the data are bound by confidentiality.
- Apply the technical and organizational measures listed below.
- Assist you in responding to requests from data subjects.
- Notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach.
- Delete or return the data at the end of the service, at your choice, unless the law requires storage.
- Make available the information needed to demonstrate compliance and allow audits on reasonable notice.
Subprocessors
You authorize the use of subprocessors in these categories: a hosting provider for servers and encrypted storage, an email delivery provider, a payment operator, and a text recognition provider for scanned statements on paid plans. Each is bound by obligations equivalent to this agreement. We notify account holders by email at least 30 days before adding a new category, and you may object within that time.
Technical and organizational measures
- TLS encryption for all connections
- AES-256 encryption of uploaded files and results at rest
- Automatic deletion of files from reconciliations without an account after 24 hours
- Retention periods set per workspace, and deletion on request
- Role based access per workspace and an audit log on the Firm plan
- Access to production systems limited to authorized staff with individual credentials
- Regular backups with encryption and tested restore
International transfers
Where personal data is transferred outside the European Economic Area or your country, the transfer relies on standard contractual clauses or another valid safeguard.
Contact for data protection
Email support@bankreconciler.com with any question about this agreement or to request a signed copy.
Processor details
Company details