Legal
Privacy Policy
Last updated 6 September 2026
1. Who we are
Statio is operated by Statio B.V. ("Statio", "we", "us"), a company registered in the Netherlands.
- Registered address: Giek 8, 1319 BN Almere, Netherlands
- Chamber of Commerce (KvK) number: 42014541
- VAT (BTW) number: NL869297302B01
- Privacy contact: privacy@statio.online
We have not appointed a Data Protection Officer; we are not required to. Privacy questions go to the address above and are answered by the company's management.
2. The two roles we play
This matters, because different rules apply to each.
We are the controller for the data we need to run Statio as a business: your account, your organisation's settings, your billing relationship, and our security and audit logs. This policy governs that data.
We are a processor for the business content you bring into Statio — your invoices, receipts, email content we read on your instruction, contacts, accounting records, and documents. Your organisation is the controller for that data; we act only on its documented instructions under our Data Processing Agreement. If you are an employee of a Statio customer and want to exercise rights over that content, contact your own organisation first.
3. What we collect and why
3.1 Account and organisation data (we are controller)
| Data | Why | Legal basis |
|---|---|---|
| Name, email address, password hash, role | To create and secure your account | Contract |
| Organisation name, country, industry, preferred language and timezone | To provide the service and tailor it to your jurisdiction | Contract |
| Multi-factor authentication secrets and recovery codes | Account security | Contract / legitimate interest in securing accounts |
| API tokens you create | Programmatic and desktop access | Contract |
| Login timestamps, IP address, device and app version | Security, abuse prevention, and supporting you | Legitimate interest |
| Billing contact, company VAT ID, payment method reference, subscription state | To bill you and meet tax obligations | Contract / legal obligation |
| Audit records of automated actions taken in your account | So you can see what the automation did while you were away; and our own accountability | Legal obligation (accountability) / legitimate interest |
We do not use your data for advertising, we do not sell it, and we do not profile you for any purpose other than delivering and securing the service.
3.2 Business content (we are processor)
When you connect a Statio App or a mailbox, Statio reads only what is needed to do the task you asked for. Section 5 describes mailbox handling specifically, because it is the most sensitive.
If you switch on desk awareness in the desktop application (watching your Downloads folder, a scan folder, or — only on your request — your Desktop), Statio reads new files there on your own computer to spot supplier invoices, receipts and till reports. What reaches us is the same as for any document you hand Statio yourself: the extracted fields that make up an approval card (supplier, amount, dates, reference, a short text snippet at most) together with a one-line note of where the file was found. The file itself is sent only in one case: after you approve a card, and only to your own accounting platform's document inbox where you have one. Documents that look personal — payslips, identity documents, bank statements, medical letters — are recognised on your computer and left alone: they are not read further, not sent anywhere and not mentioned.
3.3 What stays on your own computer
The Statio desktop application deliberately keeps a lot of data local, and it never leaves your machine:
- Your conversation history and local database (SQLite on your computer).
- Your Document Vault — the files you add, and the search index built from them. Document embeddings are computed locally on your machine, offline; the file contents are not uploaded to us to be indexed.
- Locally generated skills and your personal usage model.
- Your voice: Statio never records or keeps audio. A dictated clip is sent for transcription and discarded (see §6).
- What Statio noticed in your folders (desk awareness, opt-in): the list of files it looked at, what it decided about them, the rules you set ("not a business expense") and the copies of documents it kept for you after you approved a card. All of this is kept on this computer in plain files under Statio's own data folder, protected by whatever disk protection your computer already uses; "what did you read from my folders?" shows you the full list, and "forget my folders" removes it.
- What you copy to the clipboard: Statio reads the clipboard only when you press the hotkey, never in the background, and refuses anything your password manager marked as confidential.
Desk awareness is invisible to your employer and to us: no file names, application names, window titles, clipboard contents or "a file was skipped" facts ever reach Statio's servers or your organisation's administrator — only the aggregate AI usage every feature already reports. Statio never looks at which application or window you are using. For organisations with 50 or more staff we still recommend recording desk awareness as a line item in your data protection impact assessment, because it is an opt-in tool on employees' computers.
If you uninstall the desktop app, that data goes with it.
4. Google user data (Gmail and Google Calendar)
This section exists because Google requires it, and because it is the honest description of what we do. It applies when you connect a Google account to Statio.
What we access. With your explicit consent we request:
gmail.readonly— to read messages so Statio can find incoming invoices, receipts and bills, and so automations you configure can react to them.gmail.send— to send messages only when you tell it to: replying to a supplier, sending an invoice, or sending a payment reminder you have approved.- Google Calendar scopes, if you connect Calendar — to read your schedule and create or update events you ask for.
How we use it. Solely to provide the features you switched on. Specifically: classifying which emails contain a financial document, extracting the fields from that document, showing you an approval card, and — after you approve — booking it into your accounting platform or sending the reply you approved.
How long we keep it. We do not store your email. Message bodies and attachments are processed in memory only and discarded when the job finishes. What we keep afterwards is a short list of extracted fields — sender, subject, amount, currency, vendor name, due date, reference number, and the classification result — plus the message ID so we do not process the same message twice. Raw message bodies and attachment contents are never written to our database, our object storage, or our logs.
Who we share it with. Only:
- Mistral AI (France), our AI provider, which performs the classification and extraction. It receives the content transiently for that purpose.
- Your own accounting or business platform, when you approve an action that writes there.
We do not share Google user data with anyone else, and we never sell it.
Attachments needing OCR. Attachments that arrive through a mailbox automation are read in memory on our servers by Mistral AI's document-reading model (France, EU) — the file is sent for that single purpose, is not stored by us, and is not used to train any model — or, if that is unavailable, handed to the Statio desktop application on your own computer and processed there. Where an attachment must be staged for that handover it is stored encrypted in EU object storage under an automatic 24-hour deletion rule and fetched over a short-lived signed link.
Documents on your own computer. For files you give the desktop application directly (a watched folder, a file you pick), the text is read on your own computer: a PDF's text layer is extracted locally and images are read by a local OCR engine. A scanned document that has no text layer is sent to Mistral AI's document reader (EU endpoint, transient, no training) only if you have switched the desktop to assisted OCR and have consented for that document or folder. The default is local-only, in which case such a document is left unread and you are told so. Documents you add to your Document Vault are always read and indexed locally on your own computer and are never sent to us or to Mistral. When Statio cannot decide on its own what a file in a watched folder is, it may send a short text snippet (at most about 2 000 characters, and only after the local personal-data check found nothing) to Mistral AI to classify it — never the file. When you ask Statio to review a contract, it sends only the relevant passages (the first two pages and the sentences around the clauses it found), on your request, never as part of indexing.
Limited Use. Statio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalised AI or machine-learning models, we do not transfer it except as described above, and we do not allow humans to read it except with your explicit consent, to resolve a specific support issue you have raised, for security purposes, or where required by law.
Turning it off. You can disconnect your Google account at any time in Statio, and independently revoke Statio's access at myaccount.google.com/permissions. Revoking access stops all future reads immediately.
5. How we handle mailbox content (all providers)
The rules in section 4 are not Google-specific — they are our engineering policy for every mailbox, including Microsoft 365. In summary:
- Bodies and attachments are processed in memory, server-side, and discarded when the job ends.
- Only a fixed allow-list of extracted fields is stored (listed in section 4).
- Document reading (OCR) of mailbox attachments happens transiently on our servers via Mistral AI (EU), or on your own computer — in either case the file itself is never stored by us. Files you give the desktop application directly are read on your own computer; a scanned document with no text layer goes to Mistral AI's document reader only in assisted OCR mode with your consent (the default is local-only). Document Vault files are always processed only on your own computer.
- Every automated access is written to an audit log you can query, scrubbed of content.
- Extracted fields are deleted or anonymised together with the record they belong to, under the normal retention rules in section 8.
6. AI processing
Statio uses Mistral AI SAS (France) for all AI processing. Content you send in a conversation, and content the automation extracts, is sent to Mistral to produce the result.
- Processing takes place in the EU.
- Your content is not used to train Mistral's or Statio's models.
- Your API key is never held by the desktop application; requests are proxied through our servers so credentials stay server-side.
- If your organisation turns on Voice, dictated audio is sent to Mistral AI (France) to be turned into text and discarded, and — if you ask to hear a reply — that reply's text is sent to be turned into speech. Neither is stored by Statio. Mistral may retain inputs for abuse monitoring for up to 30 days unless zero-retention is active on our account.
AI output can be wrong. Statio is designed so that anything consequential — booking an invoice, sending an email, paying a reminder — requires your explicit approval first. You remain responsible for what you approve.
7. Who else processes your data
We use a small number of carefully chosen sub-processors. The current list, what each one does, and where it is located, is published and kept up to date at https://statio.online/legal/sub-processors.
At the time of writing they are: UpCloud (hosting and storage, Netherlands), Mistral AI (AI processing, France), Stripe (payments, Ireland), and Resend (outbound email, United States, under Standard Contractual Clauses).
Separately, when you connect a Statio App, we exchange data with your own provider — your accounting platform, mailbox or shop — using credentials you supplied. Those providers are not our sub-processors; your relationship is with them.
8. How long we keep things
| Data | Retention |
|---|---|
| Account and organisation data | For as long as your account exists, then deleted or anonymised within 30 days of account closure |
| Extracted document fields | For the life of the record they belong to (e.g. a booked invoice, a reminder sequence), then removed by the normal erasure flow |
| Mailbox bodies and attachments | Not retained — in-memory only |
| Staged attachments awaiting OCR | Automatically deleted after 24 hours |
| Voice clips used for dictation | Not retained — transcribed in memory and discarded |
| Files in your watched folders (desk awareness) | Not held by us — read on your own computer; the approved source copy is kept on your computer (and, where you have one, in your accounting platform's inbox) |
| Classification snippets and contract-review passages | Not retained — processed in memory by Mistral AI and discarded; only the resulting card fields are kept, as "extracted document fields" above |
| Synthesized speech | Held only in the app's memory for playback; never written to disk |
| Audit logs of automated actions | 12 months |
| Security and access logs | 90 days |
| Invoices and billing records | 7 years, as Dutch tax law requires |
| Database backups | Taken daily and deleted on their normal rotation cycle; deleted data disappears from backups as they age out |
9. Where your data is
Hosting, storage and AI processing are in the European Union (Netherlands and France).
The exception is outbound email, which is sent via Resend in the United States. That transfer is covered by Standard Contractual Clauses.
10. How we protect it
- Encryption in transit (TLS) everywhere, and at rest for stored credentials, which are encrypted with AES-256-GCM.
- Multi-factor authentication available on every account, and role-based access control within an organisation.
- Strict tenant isolation — every query is scoped to your organisation.
- API tokens can be scoped and given an expiry.
- Every automated action against your data is audit-logged.
- Statio staff do not access customer content in the normal course of business. Where access is unavoidable to resolve a support issue you have raised, it is limited, logged, and on your request.
No system is perfectly secure. If a breach affects your personal data we will notify the Dutch Data Protection Authority within 72 hours where required, and notify you without undue delay where the risk to you is high.
11. Your rights
Under the GDPR you can ask us to: access your data, correct it, delete it, restrict or object to processing, or provide it in a portable format. You can also withdraw consent at any time where we rely on consent.
Statio has these built in — you can request an export or an erasure from your account settings, and we will act on it. Otherwise write to privacy@statio.online. We respond within one month.
If you are unhappy with our response you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live.
Where the data concerned is your employer's business content rather than your own account data, we will refer your request to your organisation, which is the controller for it.
12. Cookies
The Statio web console uses only what it needs to work: a session cookie (statio-token) that keeps you logged in, and a language preference cookie (statio-locale). We do not use advertising or third-party tracking cookies, so there is no consent banner to click through.
13. Children
Statio is a business tool and is not intended for anyone under 16. We do not knowingly collect data about children.
14. Changes
If we change this policy we will update the date at the top and, for changes that materially affect you, tell you by email or in the application before they take effect.