Legal

Privacy Policy

Last updated 6 September 2026

1. Who we are

Statio is operated by Statio B.V. ("Statio", "we", "us"), a company registered in the Netherlands.

  • Registered address: Giek 8, 1319 BN Almere, Netherlands
  • Chamber of Commerce (KvK) number: 42014541
  • VAT (BTW) number: NL869297302B01
  • Privacy contact: privacy@statio.online

We have not appointed a Data Protection Officer; we are not required to. Privacy questions go to the address above and are answered by the company's management.

2. The two roles we play

This matters, because different rules apply to each.

We are the controller for the data we need to run Statio as a business: your account, your organisation's settings, your billing relationship, and our security and audit logs. This policy governs that data.

We are a processor for the business content you bring into Statio — your invoices, receipts, email content we read on your instruction, contacts, accounting records, and documents. Your organisation is the controller for that data; we act only on its documented instructions under our Data Processing Agreement. If you are an employee of a Statio customer and want to exercise rights over that content, contact your own organisation first.

3. What we collect and why

3.1 Account and organisation data (we are controller)

DataWhyLegal basis
Name, email address, password hash, roleTo create and secure your accountContract
Organisation name, country, industry, preferred language and timezoneTo provide the service and tailor it to your jurisdictionContract
Multi-factor authentication secrets and recovery codesAccount securityContract / legitimate interest in securing accounts
API tokens you createProgrammatic and desktop accessContract
Login timestamps, IP address, device and app versionSecurity, abuse prevention, and supporting youLegitimate interest
Billing contact, company VAT ID, payment method reference, subscription stateTo bill you and meet tax obligationsContract / legal obligation
Audit records of automated actions taken in your accountSo you can see what the automation did while you were away; and our own accountabilityLegal obligation (accountability) / legitimate interest

We do not use your data for advertising, we do not sell it, and we do not profile you for any purpose other than delivering and securing the service.

3.2 Business content (we are processor)

When you connect a Statio App or a mailbox, Statio reads only what is needed to do the task you asked for. Section 5 describes mailbox handling specifically, because it is the most sensitive.

If you switch on desk awareness in the desktop application (watching your Downloads folder, a scan folder, or — only on your request — your Desktop), Statio reads new files there on your own computer to spot supplier invoices, receipts and till reports. What reaches us is the same as for any document you hand Statio yourself: the extracted fields that make up an approval card (supplier, amount, dates, reference, a short text snippet at most) together with a one-line note of where the file was found. The file itself is sent only in one case: after you approve a card, and only to your own accounting platform's document inbox where you have one. Documents that look personal — payslips, identity documents, bank statements, medical letters — are recognised on your computer and left alone: they are not read further, not sent anywhere and not mentioned.

3.3 What stays on your own computer

The Statio desktop application deliberately keeps a lot of data local, and it never leaves your machine:

  • Your conversation history and local database (SQLite on your computer).
  • Your Document Vault — the files you add, and the search index built from them. Document embeddings are computed locally on your machine, offline; the file contents are not uploaded to us to be indexed.
  • Locally generated skills and your personal usage model.
  • Your voice: Statio never records or keeps audio. A dictated clip is sent for transcription and discarded (see §6).
  • What Statio noticed in your folders (desk awareness, opt-in): the list of files it looked at, what it decided about them, the rules you set ("not a business expense") and the copies of documents it kept for you after you approved a card. All of this is kept on this computer in plain files under Statio's own data folder, protected by whatever disk protection your computer already uses; "what did you read from my folders?" shows you the full list, and "forget my folders" removes it.
  • What you copy to the clipboard: Statio reads the clipboard only when you press the hotkey, never in the background, and refuses anything your password manager marked as confidential.

Desk awareness is invisible to your employer and to us: no file names, application names, window titles, clipboard contents or "a file was skipped" facts ever reach Statio's servers or your organisation's administrator — only the aggregate AI usage every feature already reports. Statio never looks at which application or window you are using. For organisations with 50 or more staff we still recommend recording desk awareness as a line item in your data protection impact assessment, because it is an opt-in tool on employees' computers.

If you uninstall the desktop app, that data goes with it.

4. Google user data (Gmail and Google Calendar)

This section exists because Google requires it, and because it is the honest description of what we do. It applies when you connect a Google account to Statio.

What we access. With your explicit consent we request:

  • gmail.readonly — to read messages so Statio can find incoming invoices, receipts and bills, and so automations you configure can react to them.
  • gmail.send — to send messages only when you tell it to: replying to a supplier, sending an invoice, or sending a payment reminder you have approved.
  • Google Calendar scopes, if you connect Calendar — to read your schedule and create or update events you ask for.

How we use it. Solely to provide the features you switched on. Specifically: classifying which emails contain a financial document, extracting the fields from that document, showing you an approval card, and — after you approve — booking it into your accounting platform or sending the reply you approved.

How long we keep it. We do not store your email. Message bodies and attachments are processed in memory only and discarded when the job finishes. What we keep afterwards is a short list of extracted fields — sender, subject, amount, currency, vendor name, due date, reference number, and the classification result — plus the message ID so we do not process the same message twice. Raw message bodies and attachment contents are never written to our database, our object storage, or our logs.

Who we share it with. Only:

  • Mistral AI (France), our AI provider, which performs the classification and extraction. It receives the content transiently for that purpose.
  • Your own accounting or business platform, when you approve an action that writes there.

We do not share Google user data with anyone else, and we never sell it.

Attachments needing OCR. Attachments that arrive through a mailbox automation are read in memory on our servers by Mistral AI's document-reading model (France, EU) — the file is sent for that single purpose, is not stored by us, and is not used to train any model — or, if that is unavailable, handed to the Statio desktop application on your own computer and processed there. Where an attachment must be staged for that handover it is stored encrypted in EU object storage under an automatic 24-hour deletion rule and fetched over a short-lived signed link.

Documents on your own computer. For files you give the desktop application directly (a watched folder, a file you pick), the text is read on your own computer: a PDF's text layer is extracted locally and images are read by a local OCR engine. A scanned document that has no text layer is sent to Mistral AI's document reader (EU endpoint, transient, no training) only if you have switched the desktop to assisted OCR and have consented for that document or folder. The default is local-only, in which case such a document is left unread and you are told so. Documents you add to your Document Vault are always read and indexed locally on your own computer and are never sent to us or to Mistral. When Statio cannot decide on its own what a file in a watched folder is, it may send a short text snippet (at most about 2 000 characters, and only after the local personal-data check found nothing) to Mistral AI to classify it — never the file. When you ask Statio to review a contract, it sends only the relevant passages (the first two pages and the sentences around the clauses it found), on your request, never as part of indexing.

Limited Use. Statio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalised AI or machine-learning models, we do not transfer it except as described above, and we do not allow humans to read it except with your explicit consent, to resolve a specific support issue you have raised, for security purposes, or where required by law.

Turning it off. You can disconnect your Google account at any time in Statio, and independently revoke Statio's access at myaccount.google.com/permissions. Revoking access stops all future reads immediately.

5. How we handle mailbox content (all providers)

The rules in section 4 are not Google-specific — they are our engineering policy for every mailbox, including Microsoft 365. In summary:

  1. Bodies and attachments are processed in memory, server-side, and discarded when the job ends.
  2. Only a fixed allow-list of extracted fields is stored (listed in section 4).
  3. Document reading (OCR) of mailbox attachments happens transiently on our servers via Mistral AI (EU), or on your own computer — in either case the file itself is never stored by us. Files you give the desktop application directly are read on your own computer; a scanned document with no text layer goes to Mistral AI's document reader only in assisted OCR mode with your consent (the default is local-only). Document Vault files are always processed only on your own computer.
  4. Every automated access is written to an audit log you can query, scrubbed of content.
  5. Extracted fields are deleted or anonymised together with the record they belong to, under the normal retention rules in section 8.

6. AI processing

Statio uses Mistral AI SAS (France) for all AI processing. Content you send in a conversation, and content the automation extracts, is sent to Mistral to produce the result.

  • Processing takes place in the EU.
  • Your content is not used to train Mistral's or Statio's models.
  • Your API key is never held by the desktop application; requests are proxied through our servers so credentials stay server-side.
  • If your organisation turns on Voice, dictated audio is sent to Mistral AI (France) to be turned into text and discarded, and — if you ask to hear a reply — that reply's text is sent to be turned into speech. Neither is stored by Statio. Mistral may retain inputs for abuse monitoring for up to 30 days unless zero-retention is active on our account.

AI output can be wrong. Statio is designed so that anything consequential — booking an invoice, sending an email, paying a reminder — requires your explicit approval first. You remain responsible for what you approve.

7. Who else processes your data

We use a small number of carefully chosen sub-processors. The current list, what each one does, and where it is located, is published and kept up to date at https://statio.online/legal/sub-processors.

At the time of writing they are: UpCloud (hosting and storage, Netherlands), Mistral AI (AI processing, France), Stripe (payments, Ireland), and Resend (outbound email, United States, under Standard Contractual Clauses).

Separately, when you connect a Statio App, we exchange data with your own provider — your accounting platform, mailbox or shop — using credentials you supplied. Those providers are not our sub-processors; your relationship is with them.

8. How long we keep things

DataRetention
Account and organisation dataFor as long as your account exists, then deleted or anonymised within 30 days of account closure
Extracted document fieldsFor the life of the record they belong to (e.g. a booked invoice, a reminder sequence), then removed by the normal erasure flow
Mailbox bodies and attachmentsNot retained — in-memory only
Staged attachments awaiting OCRAutomatically deleted after 24 hours
Voice clips used for dictationNot retained — transcribed in memory and discarded
Files in your watched folders (desk awareness)Not held by us — read on your own computer; the approved source copy is kept on your computer (and, where you have one, in your accounting platform's inbox)
Classification snippets and contract-review passagesNot retained — processed in memory by Mistral AI and discarded; only the resulting card fields are kept, as "extracted document fields" above
Synthesized speechHeld only in the app's memory for playback; never written to disk
Audit logs of automated actions12 months
Security and access logs90 days
Invoices and billing records7 years, as Dutch tax law requires
Database backupsTaken daily and deleted on their normal rotation cycle; deleted data disappears from backups as they age out

9. Where your data is

Hosting, storage and AI processing are in the European Union (Netherlands and France).

The exception is outbound email, which is sent via Resend in the United States. That transfer is covered by Standard Contractual Clauses.

10. How we protect it

  • Encryption in transit (TLS) everywhere, and at rest for stored credentials, which are encrypted with AES-256-GCM.
  • Multi-factor authentication available on every account, and role-based access control within an organisation.
  • Strict tenant isolation — every query is scoped to your organisation.
  • API tokens can be scoped and given an expiry.
  • Every automated action against your data is audit-logged.
  • Statio staff do not access customer content in the normal course of business. Where access is unavoidable to resolve a support issue you have raised, it is limited, logged, and on your request.

No system is perfectly secure. If a breach affects your personal data we will notify the Dutch Data Protection Authority within 72 hours where required, and notify you without undue delay where the risk to you is high.

11. Your rights

Under the GDPR you can ask us to: access your data, correct it, delete it, restrict or object to processing, or provide it in a portable format. You can also withdraw consent at any time where we rely on consent.

Statio has these built in — you can request an export or an erasure from your account settings, and we will act on it. Otherwise write to privacy@statio.online. We respond within one month.

If you are unhappy with our response you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live.

Where the data concerned is your employer's business content rather than your own account data, we will refer your request to your organisation, which is the controller for it.

12. Cookies

The Statio web console uses only what it needs to work: a session cookie (statio-token) that keeps you logged in, and a language preference cookie (statio-locale). We do not use advertising or third-party tracking cookies, so there is no consent banner to click through.

13. Children

Statio is a business tool and is not intended for anyone under 16. We do not knowingly collect data about children.

14. Changes

If we change this policy we will update the date at the top and, for changes that materially affect you, tell you by email or in the application before they take effect.