Statement Poa

Legal

Privacy Policy

This policy explains the personal and financial information Statement Poa handles when you use the website and statement-analysis service.

Effective 21 July 2026

1. Who this policy covers

This policy applies to Statement Poa’s public website, hosted web application, account features, statement processing, licensing, and related support. “Statement Poa”, “we”, and “us” refer to the operator of the Statement Poa service. Questions or privacy requests can be sent to support@statementpoa.com.

2. Information we handle

  • Account data: name, email address, optional Kenyan mobile number, authentication method, email-verification status, and account or branch membership.
  • Statement data: uploaded PDF or XLSX files and the transactions, balances, counterparties, categories, flags, reports, and analytics derived from them.
  • Payment and licence data: selected plan, mobile number used for a payment prompt, payment reference and status, receipt or licence records, and related account entitlement data. We do not collect your M-Pesa PIN.
  • Security and support data: request metadata such as IP address, session and authentication events, error and queue logs, reCAPTCHA results, support correspondence, and time-limited support-access approvals.

If you upload another person’s statement, you are responsible for having authority to provide it and use the resulting analysis.

3. Why we use it

We use this information to create and secure accounts, verify identity, process statements, produce requested analysis and exports, administer licences and payments, enforce usage limits, provide support, prevent abuse, diagnose failures, improve reliability, and meet legal obligations. Depending on the context, processing is necessary to provide the service you request, based on your consent, needed for legitimate security and operational interests, or required by law.

4. Where processing happens and who receives data

The statement file and core extraction pipeline run in Statement Poa’s application environment. We use service providers only where needed to operate a feature:

  • hosting, database, storage, logging, and email-delivery providers;
  • Google, when you choose Google sign-in, and for reCAPTCHA abuse checks when enabled;
  • payment providers, when you initiate a licence payment;
  • OpenAI only for an optional audit-classification feature when enabled by the deployment administrator. That feature does not send the source PDF. It sends normalised transaction signatures by default; an administrator can separately opt in to sending transaction descriptions.

Some providers may process information outside Kenya. Where cross-border data-protection safeguards are required, we select and configure providers with those obligations in mind. We do not sell personal data.

5. File passwords, storage, and security

A password supplied to unlock a protected PDF is used to create a readable working copy and is not saved on the statement record. Source files are kept in non-public application storage so they are not served as public website assets. The current application does not add a separate encryption layer to stored statement files, so private storage must not be read as a claim that every file is encrypted at rest. Hosting-layer disk encryption and backup controls are deployment-specific. See our Security page for the current control boundary.

6. Retention and deletion

  • You can delete a statement at any time. Deleting it removes the active source file, transactions, analytics, and associated statement records.
  • If you enable auto-delete, completed statements become eligible for deletion seven days after processing.
  • Deleting your account deletes statement files and statement records owned by that account, except records we must retain for fraud prevention, enterprise audit integrity, payment, tax, dispute, or other legal purposes.
  • Account, licence, payment, security-log, and support records are retained only for as long as reasonably needed for their operational or legal purpose.
  • If the hosting environment maintains backups, deletion from the active system may not remove a backup copy immediately. Backup schedules and expiry are deployment-specific; contact us for the current operational period.

7. Your choices and rights

You can update profile information, control optional auto-deletion and support access, delete individual statements, and request account deletion from Settings. Subject to applicable law, you may also ask to access, correct, erase, restrict, object to, or receive a portable copy of personal data. We may need to verify your identity before completing a request.

If you believe your data-protection rights have not been respected, you may contact Kenya’s Office of the Data Protection Commissioner or another competent supervisory authority.

8. Changes and contact

We may update this policy when the service or legal requirements change. The effective date above will change when a revised policy is published. Material changes may also be communicated in the application or by email.

Privacy requests: support@statementpoa.com.