Legal
Data Processing Agreement
Last updated · July 17, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Customer", acting as data controller) and BankFlow ("we", "our", "us", acting as data processor) governing your use of the BankFlow platform. It reflects the parties' obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws. Where this DPA conflicts with our Terms of Use, this DPA prevails for matters of personal data processing.
1. Roles of the parties
For personal data contained in the bank statements and other documents you upload, the Customer is the data controller and BankFlow is the data processor. BankFlow processes that data only on the Customer's documented instructions, including those set out in this DPA and the platform's normal functionality.
2. Subject matter and duration
The subject matter is the processing of personal data necessary to provide the BankFlow service: parsing, structuring, categorizing, and analyzing bank statement data. Processing continues for the duration of the Customer's use of the service and until data is deleted in accordance with Section 9.
3. Nature and purpose of processing
We process personal data to extract transactions from uploaded documents, categorize and analyze them, generate cashflow and analytics outputs, and enable export of results. We do not use Customer personal data for advertising or sale. External AI provider retention and training controls depend on the production account settings and service terms identified in our Privacy Policy.
4. Types of personal data and data subjects
Data subjects:the Customer's account holders, their counterparties, and individuals named in uploaded statements.
Categories of data: account and statement metadata, transaction dates, descriptions, merchant names, amounts and balances, and any personal data the Customer chooses to upload. The Customer is responsible for ensuring it has a lawful basis to provide this data to us.
5. Processor obligations
We will: (a) process personal data only on documented instructions; (b) ensure personnel authorized to process data are bound by confidentiality; (c) implement the security measures described in Section 6; (d) assist the Customer, taking into account the nature of processing, in responding to data subject requests and in meeting its security, breach-notification, and impact-assessment obligations; and (e) make available information reasonably necessary to demonstrate compliance.
6. Security measures
We maintain appropriate technical and organizational measures, including encryption in transit (TLS), encryption at rest through managed infrastructure, additional application-level encryption for stored secrets, role-based access controls, and audit records for privileged mutations. Further detail is available on our Security page.
7. Sub-processors
The Customer authorizes BankFlow to engage sub-processors needed to provide the service. Depending on enabled features, these may include Railway, Cloudflare, Vercel, Google (Gemini, Identity Services, and Fonts), OpenAI, Clerk, Dodo Payments, Resend, Sentry, Brandfetch, Clearbit, Iconify, Frankfurter, Crisp, and PostHog. Their roles are described in the Privacy Policy. We will provide notice of material changes to this list and an opportunity to object on reasonable data-protection grounds.
8. International transfers
Where personal data is transferred outside the EEA or UK, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary measures as needed.
9. Return and deletion of data
Settings provides separate controls to delete stored source documents, reset statements and transactions, and wipe application data. The Customer can also opt in to deletion of an original document after processing while retaining extracted data. An application-data wipe does not delete the Customer's Clerk identity, subscription, display currency, credit ledger, or limited billing, fraud-prevention, security, and audit records. Clerk identity deletion is a separate process and does not itself trigger an application-data wipe; identity recovery may remain available for up to 30 days. Upon a coordinated termination request, we will delete or return Customer personal data within a reasonable period except where retention is required by law or necessary for billing, security, fraud prevention, and audit obligations. Provider backups follow rolling retention cycles.
10. Audits
We will make available information necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits conducted by the Customer or an independent auditor it mandates.
11. Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data, and will provide information reasonably available to help the Customer meet its own notification obligations.
12. How to request a signed DPA
If your organization requires a countersigned copy of this DPA, contact us at dpa@bankflow.app and we will arrange execution. This document is provided for transparency and does not constitute legal advice.