Legal
Data Processing Agreement
Version 1.0Last updated 6 September 2026
Parties and scope
This Data Processing Agreement is between the customer identified in the Statio subscription ("Controller", "you") and Statio B.V., KvK 42014541 ("Processor", "Statio", "we").
It forms part of, and is subject to, the Statio Terms of Service (the "Agreement"). It applies whenever Statio processes personal data on your behalf. Where it conflicts with the Agreement on personal-data matters, this DPA wins.
Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the GDPR (Regulation (EU) 2016/679).
1. Roles
1.1 For the business content you bring into Statio β your accounting records, contacts, documents, and the mailbox content you instruct Statio to read β you are the controller and we are the processor. This DPA governs that data.
1.2 For your account, authentication, billing and our own security records, we are an independent controller. That processing is governed by our Privacy Policy, not this DPA.
1.3 We do not act as a joint controller with you for any processing under this DPA.
2. Our instructions
2.1 We process personal data only on your documented instructions, which consist of: this DPA, the Agreement, and your use and configuration of the service (including the Statio Apps you connect, the mailboxes you authorise, the automations you create, and the desk-awareness features an authorised user switches on in the desktop application on your own systems β watched folders, the clipboard hotkey and the Document Vault β which are opt-in per user and off by default).
2.2 We will tell you if, in our opinion, an instruction infringes the GDPR or other EU or member state data protection law. We may suspend the affected processing until it is resolved.
2.3 If we are required by EU or member state law to process personal data beyond your instructions, we will tell you before doing so unless that law forbids it on important grounds of public interest.
2.4 We do not use your personal data for our own purposes. We do not sell it, we do not use it for advertising, and β importantly for an AI product β we do not use it to train artificial intelligence or machine-learning models, ours or any third party's, and we require the same of our AI sub-processor.
3. Confidentiality
We ensure that everyone authorised to process personal data under this DPA is bound by an appropriate duty of confidentiality, is granted access on a least-privilege basis, and is trained on their obligations.
4. Security
4.1 We implement and maintain appropriate technical and organisational measures under Article 32 GDPR. The measures in place are set out in Annex C.
4.2 We may update those measures over time. We will not reduce the overall level of security below what Annex C describes.
5. Transient processing of mailbox content β
This clause exists because it is Statio's most sensitive processing and its most distinctive commitment. It reflects an internal engineering policy that predates this DPA, and it is binding.
5.1 Where you authorise Statio to access a mailbox, message bodies and attachments are processed in memory only, for the duration of the classification or extraction job, and are then discarded.
5.2 Message bodies and attachment contents are not written to our database, our object storage, or our logs.
5.3 After extraction we persist only a defined allow-list of fields: sender, subject, detected amount and currency, document metadata (vendor name, due date, reference number), the classification result, and the provider's message identifier. Nothing outside that list is retained.
5.4 Attachments that require optical character recognition are processed in memory by sending the document bytes to Mistral AI's OCR model via our server-side proxy, the same transient handling as other mailbox content under this clause β never written to server-side disk. When server-side OCR is unavailable, extraction falls back to the Statio desktop application running on your own systems, which processes the attachment there instead. Where staging is necessary for that fallback handover, the attachment is held in encrypted EU object storage subject to an automatic deletion rule of no more than 24 hours, and is retrieved over a short-lived signed link.
Documents supplied directly to the Statio desktop application on the Customer's own systems (a watched folder, a file the user selects) are read there: a PDF's text layer is extracted locally and images are processed by a local OCR engine, and the document bytes are not transmitted to us or to any sub-processor. A scanned document without a text layer is transmitted to Mistral AI's OCR model (EU endpoint, in memory, no training use) only where the Customer has enabled assisted OCR on the desktop application and the user has consented for that document or folder; the default configuration is local-only, in which case the document is left unread.
Where a user has switched on watched folders (Downloads, a scan folder, or the Desktop on explicit request), new files are read on the Customer's own systems only: text extraction, a personal-data check keyed on checksummed identifiers and document structure, duplicate detection and classification all run locally, on at most the first three pages. Documents the check identifies as personal (payslips, identity documents, bank statements, medical correspondence) are not read further, not transmitted and not named. For the remainder we receive the extracted fields of an approval card and, where the local classifier cannot decide, a text snippet of at most 2 000 characters that has passed the personal-data check β never the document. The bytes of such a document leave the Customer's system in exactly one case: after an authorised user approves the card, and only to the Customer's own accounting platform's document inbox, transmitted through our servers in memory and not retained. Contract review sends only the relevant passages, on the user's request, never during indexing. No file names of skipped documents, application names, window titles or clipboard contents are transmitted to us or made visible to the Customer's administrators; the desktop application does not observe which application or window is in use. Because these features are employer-invisible in this sense they are not designed as an employee-monitoring system; Customers with 50 or more staff are nevertheless advised to record them as a line item in their data protection impact assessment.
5.5 Every automated access to a mailbox, and every automated action taken as a result, is recorded in an audit log available to you, scrubbed of message content.
6. Assisting you
6.1 Data subject requests. Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures in responding to requests to exercise data subject rights. The service includes self-service export and erasure functions which will, in most cases, be sufficient. If a data subject contacts us directly about data we process for you, we will refer them to you and tell you promptly, and will not respond substantively ourselves unless you instruct us to.
6.2 DPIAs and prior consultation. We will provide reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority, taking into account the information available to us.
6.3 We may charge a reasonable fee for assistance that goes materially beyond the self-service functions and the cooperation described above.
7. Sub-processors
7.1 You give general authorisation for us to engage sub-processors.
7.2 Our current sub-processors are listed at https://statio.online/legal/sub-processors. That page is the authoritative list and is maintained as it changes.
7.3 Notice of change. We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your account's administrative contact and by updating the page. You may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
7.4 We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
7.5 Providers you connect yourself β your accounting platform, your mailbox provider, your shop β are not our sub-processors. When Statio exchanges data with them it does so with credentials you supplied, on your instruction, and your relationship is with them directly. They are listed for transparency in Annex B2 of the sub-processor page.
8. International transfers
8.1 Personal data is hosted, stored and AI-processed within the European Union.
8.2 Where a sub-processor is located outside the EEA, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module 3 (processor to sub-processor), together with any supplementary measures identified in a transfer impact assessment. The sub-processor page identifies which entities this applies to.
8.3 We will not transfer personal data to a country without an adequacy decision except under a valid Article 46 transfer mechanism.
9. Personal data breaches
9.1 We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting personal data processed for you.
9.2 The notification will describe, so far as we know it: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose, and a contact point for further information. Where we cannot provide it all at once, we will provide it in phases without further undue delay.
9.3 We will cooperate with you and take the reasonable steps you direct to assist your investigation and your own notification obligations.
9.4 We will not notify a supervisory authority or a data subject about a breach affecting your data on your behalf unless you instruct us to or the law requires us to.
10. Deletion and return
10.1 On termination of the Agreement you may export your data using the service's export function for 30 days.
10.2 After that period we will delete or anonymise the personal data we process for you within 30 further days, except where EU or member state law requires us to keep it (for example statutory retention of invoicing records), in which case we will keep it only for as long as that law requires and only for that purpose.
10.3 Backups are deleted on their normal rotation cycle. Personal data present in a backup taken before deletion will persist until that backup ages out, during which time it remains protected by this DPA and is not restored into production except as part of a whole-system recovery.
10.4 Data held locally by the desktop application on your own systems is under your control; you delete it by removing the application and its data directory.
11. Audits
11.1 We will make available to you the information necessary to demonstrate compliance with Article 28 GDPR β ordinarily by providing Annex C, our sub-processor list, and answers to a reasonable security questionnaire.
11.2 Where that is not sufficient, you may audit us, or appoint an independent auditor who is not a competitor of ours and who is bound by confidentiality, on at least 30 days' written notice, no more than once in any 12-month period (unless a supervisory authority requires more, or a breach has occurred), during business hours, and in a way that does not disrupt our operations or the confidentiality of other customers' data. You bear the cost unless the audit reveals a material breach by us.
12. Liability
Liability under this DPA is subject to the limitations in the Agreement, including the cap in clause 10.4 of the Agreement, except where clause 10.6 of the Agreement disapplies them or where they cannot lawfully be applied. Nothing here limits a data subject's rights or a supervisory authority's powers.
13. Term, order of precedence, and law
13.1 This DPA runs for as long as we process personal data for you, and its surviving obligations continue afterwards.
13.2 In case of conflict: this DPA prevails over the Agreement on personal-data matters; the Standard Contractual Clauses prevail over this DPA on transfer matters.
13.3 Dutch law governs, with the jurisdiction stated in the Agreement.
Annex A β Details of processing
Subject matter. Provision of the Statio service: an AI back-office assistant that reads from and acts within the Controller's connected business applications.
Duration. The term of the Agreement, plus the deletion periods in clause 10.
Nature and purpose. Collection, storage, structuring, retrieval, analysis (including AI-based classification, extraction and drafting), transmission to the Controller's connected applications, erasure β all in order to automate back-office administration on the Controller's instruction.
Types of personal data.
- Users of the service: name, business email, role, authentication data, language and timezone, access logs, device and application version.
- Business content: contact details of the Controller's customers, suppliers and counterparties (name, business address, email, phone, VAT identification number, KvK number, bank account number); financial transaction details; correspondence metadata; content of documents the Controller uploads or instructs Statio to process.
- Transiently, and not retained: mailbox message bodies and attachment contents (clause 5); voice clips used for dictation and reply text sent for speech synthesis (PLAN-165); short text snippets (at most 2 000 characters, after a local personal-data check) from documents in a user's watched folders that the local classifier could not decide, and the passages of a contract a user asks Statio to review (clause 5.4, PLAN-167). Documents in watched folders and the Document Vault are otherwise processed only on the Controller's own systems.
Categories of data subjects. The Controller's employees and authorised users; the Controller's customers, suppliers and other counterparties, including sole traders and the employees of corporate counterparties whose details appear in documents or correspondence.
Special category data. Not requested and not required. The Controller should not deliberately place special category data (Article 9) or criminal conviction data (Article 10) into the service. Where such data appears incidentally in a document or message, it is processed under the same measures as all other content.
Frequency. Continuous for the duration of the Agreement.
Annex B β Sub-processors
The authoritative, maintained list is published at https://statio.online/legal/sub-processors and is incorporated into this DPA by reference. At the version date of this DPA it comprises: UpCloud (hosting and storage, EU), Mistral AI (AI processing, EU), Stripe (payments, EU/US), Resend (outbound email, US).
Annex C β Technical and organisational measures
Article 32 GDPR. These are measures that exist in the product today. Anything not yet built is listed under "Planned" and is not a contractual commitment until moved up.
Access control
- Role-based access control with three roles and strict per-organisation scoping; every data query is bound to the requesting organisation's identifier.
- Multi-factor authentication (TOTP) available on all accounts, with recovery codes.
- Single sign-on via Google and Microsoft using OAuth 2.0 with PKCE.
- API tokens are scoped and can be given an expiry; they are stored hashed.
- Passwords are stored using bcrypt. Passwords are never logged.
Encryption
- TLS for all data in transit, on all public endpoints, with certificates managed automatically.
- Third-party credentials (OAuth tokens, API keys) are encrypted at rest with AES-256-GCM.
- Provider API keys are held server-side only and never distributed to client applications; client AI requests are proxied so that credentials never reach the desktop.
Segregation and minimisation
- Multi-tenant segregation enforced in the data layer on every org-scoped query.
- The transient-processing policy in clause 5 β mailbox content is never persisted, and only an explicit allow-list of extracted fields is stored.
- Heavy document processing is performed on the Controller's own systems rather than ours.
Accountability and monitoring
- An audit log of tool calls and automated actions, attributable to a user or an automation, with content scrubbed.
- Application error and availability monitoring.
- Automated container vulnerability scanning on every build, with findings raised as tracked issues.
- Dependency update automation.
Resilience and recovery
- Daily encrypted database backups to EU object storage, with a documented restore procedure.
- Redundant application instances behind a load balancer; automated restart of failed instances.
- Documented rollback procedure for desktop application releases.
Data subject rights support
- Self-service data export (machine-readable) and erasure request flows, with erasure implemented as anonymisation where records must be retained for statutory reasons.
Organisational
- Least-privilege access to production for personnel; production access is logged.
- Confidentiality obligations on all personnel with access.
- Change management through version control and peer-reviewed merges, with automated type, translation, and security checks before deployment.
Planned β not yet contractual
Listed for transparency in customer security reviews. These are on the roadmap and are not warranted under clause 4 until delivered and moved into the sections above.
- High-availability managed PostgreSQL with point-in-time recovery (currently: single instance with daily backups).
- Formal, tested disaster-recovery exercise with a stated RPO/RTO.
- Third-party security assessment (a CASA Tier 2 assessment is planned as part of Google API verification).
- A published, tested incident response plan.
- Penetration testing.