Legal

Privacy Policy

Last updated 3 August 2026

This document is a draft pending legal review. Values shown in dashed brackets are placeholders that have not been filled in yet.

1. Who we are

Statio is operated by [[LEGAL ENTITY NAME]] ("Statio", "we", "us"), a company registered in the Netherlands.

  • Registered address: [[REGISTERED ADDRESS]]
  • Chamber of Commerce (KvK) number: [[KVK NUMBER]]
  • VAT (BTW) number: [[VAT NUMBER]]
  • Privacy contact: privacy@statio.online

We have not appointed a Data Protection Officer; we are not required to. Privacy questions go to the address above and are answered by the company's management.

2. The two roles we play

This matters, because different rules apply to each.

We are the controller for the data we need to run Statio as a business: your account, your organisation's settings, your billing relationship, and our security and audit logs. This policy governs that data.

We are a processor for the business content you bring into Statio — your invoices, receipts, email content we read on your instruction, contacts, accounting records, and documents. Your organisation is the controller for that data; we act only on its documented instructions under our Data Processing Agreement. If you are an employee of a Statio customer and want to exercise rights over that content, contact your own organisation first.

3. What we collect and why

3.1 Account and organisation data (we are controller)

DataWhyLegal basis
Name, email address, password hash, roleTo create and secure your accountContract
Organisation name, country, industry, preferred language and timezoneTo provide the service and tailor it to your jurisdictionContract
Multi-factor authentication secrets and recovery codesAccount securityContract / legitimate interest in securing accounts
API tokens you createProgrammatic and desktop accessContract
Login timestamps, IP address, device and app versionSecurity, abuse prevention, and supporting youLegitimate interest
Billing contact, company VAT ID, payment method reference, subscription stateTo bill you and meet tax obligationsContract / legal obligation
Audit records of automated actions taken in your accountSo you can see what the automation did while you were away; and our own accountabilityLegal obligation (accountability) / legitimate interest

We do not use your data for advertising, we do not sell it, and we do not profile you for any purpose other than delivering and securing the service.

3.2 Business content (we are processor)

When you connect a Statio App or a mailbox, Statio reads only what is needed to do the task you asked for. Section 5 describes mailbox handling specifically, because it is the most sensitive.

3.3 What stays on your own computer

The Statio desktop application deliberately keeps a lot of data local, and it never leaves your machine:

  • Your conversation history and local database (SQLite on your computer).
  • Your Document Vault — the files you add, and the search index built from them. Document embeddings are computed locally on your machine, offline; the file contents are not uploaded to us to be indexed.
  • Locally generated skills and your personal usage model.

If you uninstall the desktop app, that data goes with it.

4. Google user data (Gmail and Google Calendar)

This section exists because Google requires it, and because it is the honest description of what we do. It applies when you connect a Google account to Statio.

What we access. With your explicit consent we request:

  • gmail.readonly — to read messages so Statio can find incoming invoices, receipts and bills, and so automations you configure can react to them.
  • gmail.send — to send messages only when you tell it to: replying to a supplier, sending an invoice, or sending a payment reminder you have approved.
  • Google Calendar scopes, if you connect Calendar — to read your schedule and create or update events you ask for.

How we use it. Solely to provide the features you switched on. Specifically: classifying which emails contain a financial document, extracting the fields from that document, showing you an approval card, and — after you approve — booking it into your accounting platform or sending the reply you approved.

How long we keep it. We do not store your email. Message bodies and attachments are processed in memory only and discarded when the job finishes. What we keep afterwards is a short list of extracted fields — sender, subject, amount, currency, vendor name, due date, reference number, and the classification result — plus the message ID so we do not process the same message twice. Raw message bodies and attachment contents are never written to our database, our object storage, or our logs.

Who we share it with. Only:

  • Mistral AI (France), our AI provider, which performs the classification and extraction. It receives the content transiently for that purpose.
  • Your own accounting or business platform, when you approve an action that writes there.

We do not share Google user data with anyone else, and we never sell it.

Attachments needing OCR. If a document needs OCR, the attachment is handed to the Statio desktop application on your own computer and processed there. Where an attachment must be staged for that handover it is stored encrypted in EU object storage under an automatic 24-hour deletion rule and fetched over a short-lived signed link.

Limited Use. Statio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalised AI or machine-learning models, we do not transfer it except as described above, and we do not allow humans to read it except with your explicit consent, to resolve a specific support issue you have raised, for security purposes, or where required by law.

Turning it off. You can disconnect your Google account at any time in Statio, and independently revoke Statio's access at myaccount.google.com/permissions. Revoking access stops all future reads immediately.

5. How we handle mailbox content (all providers)

The rules in section 4 are not Google-specific — they are our engineering policy for every mailbox, including Microsoft 365. In summary:

  1. Bodies and attachments are processed in memory, server-side, and discarded when the job ends.
  2. Only a fixed allow-list of extracted fields is stored (listed in section 4).
  3. Heavy extraction (OCR) happens on your own computer, not on our servers.
  4. Every automated access is written to an audit log you can query, scrubbed of content.
  5. Extracted fields are deleted or anonymised together with the record they belong to, under the normal retention rules in section 8.

6. AI processing

Statio uses Mistral AI SAS (France) for all AI processing. Content you send in a conversation, and content the automation extracts, is sent to Mistral to produce the result.

  • Processing takes place in the EU.
  • Your content is not used to train Mistral's or Statio's models. [[CONFIRM AGAINST MISTRAL'S SIGNED COMMERCIAL TERMS BEFORE PUBLISHING — see sub-processors.md, open item 1]]
  • Your API key is never held by the desktop application; requests are proxied through our servers so credentials stay server-side.

AI output can be wrong. Statio is designed so that anything consequential — booking an invoice, sending an email, paying a reminder — requires your explicit approval first. You remain responsible for what you approve.

7. Who else processes your data

We use a small number of carefully chosen sub-processors. The current list, what each one does, and where it is located, is published and kept up to date at https://statio.online/legal/sub-processors.

At the time of writing they are: UpCloud (hosting and storage, Netherlands), Mistral AI (AI processing, France), Stripe (payments, Ireland), and Resend (outbound email, United States, under Standard Contractual Clauses).

Separately, when you connect a Statio App, we exchange data with your own provider — your accounting platform, mailbox or shop — using credentials you supplied. Those providers are not our sub-processors; your relationship is with them.

8. How long we keep things

DataRetention
Account and organisation dataFor as long as your account exists, then deleted or anonymised within 30 days of account closure
Extracted document fieldsFor the life of the record they belong to (e.g. a booked invoice, a reminder sequence), then removed by the normal erasure flow
Mailbox bodies and attachmentsNot retained — in-memory only
Staged attachments awaiting OCRAutomatically deleted after 24 hours
Audit logs of automated actions[[RETENTION PERIOD — recommend 12 months]]
Security and access logs[[RETENTION PERIOD — recommend 90 days]]
Invoices and billing records7 years, as Dutch tax law requires
Database backups[[BACKUP RETENTION — confirm against the backup CronJob policy]]; deleted data disappears from backups as they age out

9. Where your data is

Hosting, storage and AI processing are in the European Union (Netherlands and France).

The exception is outbound email, which is sent via Resend in the United States. That transfer is covered by Standard Contractual Clauses. [[If Resend is replaced with an EU provider before launch, delete this paragraph and simplify section 9 to "all processing takes place in the EU."]]

10. How we protect it

  • Encryption in transit (TLS) everywhere, and at rest for stored credentials, which are encrypted with AES-256-GCM.
  • Multi-factor authentication available on every account, and role-based access control within an organisation.
  • Strict tenant isolation — every query is scoped to your organisation.
  • API tokens can be scoped and given an expiry.
  • Every automated action against your data is audit-logged.
  • Statio staff do not access customer content in the normal course of business. Where access is unavoidable to resolve a support issue you have raised, it is limited, logged, and on your request.

No system is perfectly secure. If a breach affects your personal data we will notify the Dutch Data Protection Authority within 72 hours where required, and notify you without undue delay where the risk to you is high.

11. Your rights

Under the GDPR you can ask us to: access your data, correct it, delete it, restrict or object to processing, or provide it in a portable format. You can also withdraw consent at any time where we rely on consent.

Statio has these built in — you can request an export or an erasure from your account settings, and we will act on it. Otherwise write to privacy@statio.online. We respond within one month.

If you are unhappy with our response you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live.

Where the data concerned is your employer's business content rather than your own account data, we will refer your request to your organisation, which is the controller for it.

12. Cookies

The Statio web console uses only what it needs to work: a session cookie (statio-token) that keeps you logged in, and a language preference cookie (statio-locale). We do not use advertising or third-party tracking cookies, so there is no consent banner to click through.

13. Children

Statio is a business tool and is not intended for anyone under 16. We do not knowingly collect data about children.

14. Changes

If we change this policy we will update the date at the top and, for changes that materially affect you, tell you by email or in the application before they take effect.