Data Processing Agreement
Effective Date: July 31, 2026 · Version 2026-07-31
1. Introduction and Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between StatementPro.ai, operated by Mocsy Inc., a company with its registered office at 111 Peter Street, Suite 780, Toronto, Ontario M5V 2H1, Canada ("StatementPro.ai," "Processor," "we," or "us"), and the business customer identified in the Agreement ("Customer," "Controller," or "you").
This DPA applies where, and only to the extent that, StatementPro.ai processes Personal Data on behalf of the Customer in the course of providing the Service. It does not apply where an individual uses the Service for personal, family, or household purposes; in that case StatementPro.ai acts as controller of that individual's personal information, as described in the Privacy Policy.
This DPA reflects the parties' agreement with respect to the processing of Personal Data in accordance with Data Protection Laws, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA governs. In the event of a conflict between this DPA and the Standard Contractual Clauses incorporated under Section 11, the Standard Contractual Clauses govern.
2. Definitions
- "Personal Data" — any information relating to an identified or identifiable natural person contained in Customer Data that StatementPro.ai processes on the Customer's behalf.
- "Customer Data" — the documents, files, and other data that the Customer or its authorized users upload to or generate through the Service, including bank statements and converted output files.
- "Data Protection Laws" — all laws applicable to the processing of Personal Data under the Agreement, including the GDPR, UK GDPR, CCPA/CPRA, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and applicable Canadian provincial privacy legislation.
- "Sub-processor" — any third party engaged by StatementPro.ai to process Personal Data on the Customer's behalf. For clarity, extraction performed on StatementPro.ai's own platform, operated by Mocsy Inc., is internal processing by the Processor and does not create a Sub-processor relationship.
- "Standard Contractual Clauses" or "SCCs" — the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914.
- "UK Addendum" — the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.
- "Data Subject," "Controller," "Processor," "Processing," "Personal Data Breach," and "Supervisory Authority" have the meanings given in the GDPR.
- "Business," "Service Provider," "Sell," and "Share" have the meanings given in the CCPA/CPRA.
3. Roles of the Parties
With respect to the processing of Personal Data contained in Customer Data, the Customer is the Controller (or Business under the CCPA/CPRA) and StatementPro.ai is the Processor (or Service Provider). Where the Customer is itself acting as a processor on behalf of a third-party controller (for example, an accounting firm processing its clients' statements), StatementPro.ai acts as a sub-processor, and the Customer warrants that it has the authority and lawful basis to engage StatementPro.ai on those terms. Section 11 identifies which SCC module applies in each case.
4. Processing of Personal Data
4.1 Processing Instructions
StatementPro.ai processes Personal Data only on documented instructions from the Customer, including as set out in the Agreement, this DPA, and as necessary to provide the Service, unless required to do otherwise by applicable law (in which case StatementPro.ai will inform the Customer before processing, unless prohibited by law). StatementPro.ai will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
4.2 Purpose Limitation
StatementPro.ai processes Personal Data solely to provide and support the Service — to extract and convert the data contained in uploaded documents into the requested output format and to deliver the results. StatementPro.ai does not sell or share Personal Data, and does not use, retain, or disclose Personal Data for any purpose other than performing the Service for the Customer, including for training general-purpose or cross-customer machine-learning models, analytics profiling, advertising, or any other commercial purpose outside the direct business relationship with the Customer.
Model hosting. Extraction is performed using machine-learning models hosted for StatementPro.ai by Amazon Web Services in its US East region. Personal Data is transmitted to that infrastructure for the purpose of inference only. The model-hosting provider does not use Personal Data to train its own models and does not retain it for its own purposes.
4.3 Details of Processing
The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex I.
4.4 Confidentiality
StatementPro.ai ensures that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations and are trained on their data-protection responsibilities. Access is limited to personnel who require it to provide the Service.
4.5 Service Improvement and Extraction Accuracy
StatementPro.ai's extraction system improves over time from corrections made to extracted data by users of the Service. Personal Data is not used for that purpose. Before any correction is used to improve the extraction system, the underlying content is removed, so that what is retained describes only the structure of a document — field positions, label geometry, layout templates, and the mapping between a detected label and a canonical field name.
StatementPro.ai warrants that it does not use Personal Data to improve or train models serving any other customer or user, and that it does not: (a) build or modify a profile of any individual; (b) use Personal Data to infer characteristics about any individual; (c) disclose Personal Data, or any document or extracted value, to any other customer or user; or (d) combine Personal Data with data acquired from any other source.
5. Sub-processors
The Customer provides general authorization for StatementPro.ai to engage Sub-processors, subject to this section. Current Sub-processors are listed in Annex III. Extraction performed on StatementPro.ai's own platform is internal processing and does not require authorization under this section, as explained in Section 2.
StatementPro.ai imposes data-protection obligations on each Sub-processor by written contract that are no less protective than those in this DPA, and remains liable to the Customer for each Sub-processor's performance.
Notice. StatementPro.ai will give the Customer at least thirty (30) days' written notice (by email to the Customer's designated contact, or by updating Annex III and notifying subscribers to its sub-processor notification list) before a new Sub-processor begins processing Personal Data. Where a Sub-processor must be replaced urgently for security, continuity, or legal reasons, StatementPro.ai may act on shorter notice and will inform the Customer as soon as practicable.
Objection. The Customer may object to a proposed Sub-processor on reasonable data-protection grounds by giving written notice within thirty (30) days of StatementPro.ai's notice. The parties will discuss the objection in good faith for up to thirty (30) days and StatementPro.ai will use reasonable efforts to make available a commercially reasonable change in the Service, or recommend a commercially reasonable workaround, that avoids processing by the objected-to Sub-processor.
Remedy. If the parties cannot resolve the objection within that period, the Customer may terminate the affected Service by written notice, and StatementPro.ai will refund any prepaid fees covering the remainder of the then-current subscription term after the effective date of termination. This is the Customer's sole remedy for an unresolved sub-processor objection.
6. Security Measures
StatementPro.ai implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, described in Annex II, including encryption of Personal Data in transit (TLS) and at rest (AES-256), access controls, logical separation of Customer Data, and continuous monitoring. StatementPro.ai may update these measures from time to time provided it does not materially reduce the overall level of security.
Where output files are delivered to the Customer by email at the Customer's request, the Customer acknowledges that the security of that delivery depends in part on the Customer's own email infrastructure and the transport between the parties' systems, which is outside StatementPro.ai's control.
7. Personal Data Breach Notification
StatementPro.ai notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data, and will aim to do so within seventy-two (72) hours. Where a breach originates with a Sub-processor or infrastructure provider, StatementPro.ai's ability to notify depends in part on that provider's own notification to StatementPro.ai; StatementPro.ai will notify the Customer as soon as practicable after it becomes aware.
The notification describes, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Where all details are not available at the time of the initial notification, StatementPro.ai will provide further information in phases as it becomes available. StatementPro.ai reasonably assists the Customer in meeting its own breach-notification obligations. An initial notification is not an acknowledgement of fault or liability.
8. Assistance to the Controller
8.1 Data Subject Requests
Taking into account the nature of the processing, StatementPro.ai assists the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection). If StatementPro.ai receives a request directly from a Data Subject relating to Customer Data, it will promptly forward it to the Customer and will not respond directly except on the Customer's documented instructions or as required by law.
8.2 Impact Assessments and Consultations
StatementPro.ai provides reasonable assistance with data-protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of the processing and the information available to StatementPro.ai.
9. Return and Deletion of Personal Data
During the term. StatementPro.ai retains uploaded documents and the data extracted from them until the Customer requests deletion. Converted output files are delivered to the Customer and, where a download link is provided, the file backing that link is retained for up to thirty (30) days and then deleted. The Customer may request deletion of any Personal Data at any time by contacting hello@statementpro.ai, and StatementPro.ai will action verified requests within thirty (30) days.
On termination. Within thirty (30) days after termination or expiry of the Agreement, StatementPro.ai will, at the Customer's election, return Personal Data to the Customer in a commonly used format or delete it, and will delete existing copies (including from backups in accordance with its backup rotation cycle), except to the extent applicable law requires continued storage — for example, payment and transaction records retained for tax and accounting purposes. On request, StatementPro.ai will certify in writing that deletion has been completed.
10. Audits
StatementPro.ai makes available information reasonably necessary to demonstrate compliance with this DPA. Where StatementPro.ai holds current third-party certifications, audit reports, or completed security questionnaires — for example, once SOC 2 certification is completed; certification is currently in progress and not yet obtained — providing those materials to the Customer under confidentiality satisfies StatementPro.ai's audit obligation.
Where such materials are not available, or where the Customer reasonably demonstrates that they are insufficient to verify compliance, StatementPro.ai will allow for and contribute to an audit, including an inspection, conducted by the Customer or an independent auditor mandated by the Customer and reasonably acceptable to StatementPro.ai. Any such audit is conducted on at least thirty (30) days' prior written notice, during business hours, in a manner that does not unreasonably disrupt StatementPro.ai's operations, no more than once per twelve-month period (except following a Personal Data Breach affecting the Customer's Personal Data or where required by a Supervisory Authority), at the Customer's cost, and subject to confidentiality. StatementPro.ai may require the auditor to sign a non-disclosure agreement and may withhold access to information relating to other customers, pricing, or its own confidential security architecture where disclosure would create risk.
11. International Data Transfers
StatementPro.ai processes and stores Personal Data in Canada and the United States.
Transfers to Canada. Canada benefits from a European Commission adequacy decision in respect of organizations subject to PIPEDA. Transfers of Personal Data from the EEA to StatementPro.ai's processing in Canada therefore do not require an additional transfer mechanism.
Transfers to the United States. Where processing involves a transfer of Personal Data originating from the EEA to the United States, or to any other country not covered by an adequacy decision, the SCCs are incorporated into this DPA by reference and apply to that transfer, as follows:
- Module. Where the Customer is a controller and StatementPro.ai a processor, Module Two applies. Where the Customer is itself a processor acting for a third-party controller (see Section 3), Module Three applies.
- Clause 7 (docking clause). Applies.
- Clause 9 (use of sub-processors). Option 2 (general written authorisation) applies, with the notice period specified in Section 5 of this DPA.
- Clause 11 (redress). The optional independent dispute-resolution paragraph does not apply.
- Clause 17 (governing law). The SCCs are governed by the law of Ireland.
- Clause 18(b) (choice of forum). The courts of Ireland.
- Annexes. Annexes I, II, and III of this DPA populate Annexes I, II, and III of the SCCs respectively.
The Customer acts as "data exporter" and StatementPro.ai as "data importer."
United Kingdom. For transfers subject to the UK GDPR, the SCCs as incorporated above apply as varied by the UK Addendum, which is incorporated by reference.
Switzerland. For transfers subject to Swiss data-protection law, the SCCs apply with the modifications recognized by the Swiss Federal Data Protection and Information Commissioner, including that references to the GDPR are read as references to the Swiss FADP and that the competent authority is the FDPIC.
12. California Consumer Privacy (CCPA/CPRA) Terms
To the extent StatementPro.ai processes personal information of California residents on the Customer's behalf, StatementPro.ai acts as a "Service Provider." StatementPro.ai will not: (a) sell or share such personal information; (b) retain, use, or disclose it for any purpose other than performing the Service specified in the Agreement, or as otherwise permitted by the CCPA/CPRA; (c) retain, use, or disclose it outside the direct business relationship with the Customer; or (d) combine it with personal information from other sources, except as permitted by the CCPA/CPRA. StatementPro.ai certifies that it understands and will comply with these restrictions. Consistent with Section 4.5, StatementPro.ai does not retain, use, or disclose personal information to improve or enhance the Service for any other customer or user; only de-identified structural information is used for that purpose.
StatementPro.ai will notify the Customer if it determines it can no longer meet these obligations, and will grant the Customer the right to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information. StatementPro.ai imposes equivalent restrictions on any Sub-processor to which it discloses such personal information.
13. Governing Law
Except as set out below, this DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, consistent with the Terms of Service.
This choice of law does not apply to the Standard Contractual Clauses or the UK Addendum incorporated under Section 11, which are governed by the law specified in Clause 17 of the SCCs (or, for the UK Addendum, the law specified in it), and it does not derogate from any right a Data Subject has under those clauses.
14. Liability
The limitations and exclusions of liability in the Agreement apply to claims under this DPA, except that they do not limit or exclude: (a) either party's liability to a Data Subject under the Standard Contractual Clauses, which is governed by Clause 12 of those clauses and cannot be limited by this DPA or the Agreement; (b) liability that cannot be limited under Data Protection Laws or other applicable law; or (c) any liability cap separately agreed in writing between the parties in respect of data-protection claims.
15. Canadian Provincial Privacy Legislation
Where the Customer is subject to Canadian provincial privacy legislation, including Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, StatementPro.ai will, on reasonable request and at the Customer's cost where material effort is required: (a) provide the information the Customer reasonably needs to complete a privacy impact assessment in respect of a communication of personal information outside Quebec; (b) assist the Customer in responding to requests for access, correction, de-indexing, or portability; and (c) notify the Customer of any confidentiality incident in accordance with Section 7 and provide the information the Customer needs for its own register and for any notification to the Commission d'accès à l'information.
16. General
This DPA remains in effect for as long as StatementPro.ai processes Personal Data on the Customer's behalf. If any provision is found invalid, the remaining provisions continue in full force. Except as modified by this DPA, the terms of the Agreement remain in full force and effect. To request a signed copy of this DPA, contact hello@statementpro.ai with the subject line "DPA Request."
Annex I — Details of Processing
- Subject matter: Extraction and conversion of data contained in documents uploaded to the Service.
- Duration: For the term of the Agreement and until deletion in accordance with Section 9.
- Nature and purpose: Automated extraction of transaction and account data from uploaded bank statements and financial documents, and conversion into structured output formats requested by the Customer. Extraction is performed using machine-learning models hosted by Amazon Web Services in its US East region; document content is transmitted to that infrastructure for inference. De-identified structural information derived from corrections is additionally used to maintain and improve the accuracy of the extraction service; Personal Data is not used for that purpose (Section 4.5).
- Categories of Data Subjects: The Customer's account holders and end users; and any individuals whose personal information appears within uploaded documents (e.g., account holders named on a bank statement).
- Categories of Personal Data: Contact and account data (email address); financial-transaction data contained in uploaded statements (account numbers, transaction descriptions, dates, amounts); technical data (IP address, device and usage information).
- Special categories / sensitive data: Financial-account information contained in bank statements, which constitutes sensitive personal information under the CPRA and under Quebec Law 25. No other special categories are intentionally processed. Restrictions applicable: processing limited to performing the conversion, access restricted on a need-to-know basis, encryption in transit and at rest.
- Frequency: Continuous, on Customer-initiated uploads.
- Competent supervisory authority (SCC Annex I.C): as determined under Clause 13 of the SCCs.
Annex II — Technical and Organizational Security Measures
- Encryption of Personal Data in transit (TLS) and at rest (AES-256).
- Role-based access controls limiting access to Personal Data on a need-to-know basis.
- Logical separation of Customer Data within the processing environment, so that one customer's data is not accessible to another customer.
- Continuous monitoring and logging of access, and a documented incident-response plan.
- Regular security assessments, code reviews, and vulnerability testing.
- Infrastructure hosted on enterprise-grade cloud platforms that maintain SOC 2 compliance. StatementPro.ai's own SOC 2 certification is in progress and not yet obtained.
- Personnel bound by confidentiality obligations and trained on data-protection responsibilities.
Annex III — Authorized Sub-processors
Conversion is performed on StatementPro.ai's own extraction platform, operated by Mocsy Inc. That processing is internal to the Processor and is not a disclosure to a third party. The infrastructure and hosted models on which the platform runs are provided by the Sub-processors below.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure, storage, processing, and hosting of the machine-learning models used for extraction | Canada, and United States including the US East region |
| Stripe, Inc. | Payment processing | United States |
| Cloudflare, Inc. | Content delivery, security, and bot protection | United States |
| HubSpot, Inc. | Customer relationship management and email | United States |
For questions about this DPA or our sub-processors, contact hello@statementpro.ai. See also our Privacy Policy and Security page.