Privacy Policy
1. Data Collection
Balanzio collects minimal personal data necessary for service operation:
- Email address (for registered users)
- IP address hash (for anonymous quota management - not reversible)
- Technical metadata (file size, upload time, processing status)
We do NOT store: The content of your bank statements, transaction details, account numbers, balances, or any financial data.
2. Data Processing
Your uploaded PDF files are processed to extract transaction data:
- Files are processed in temporary storage only
- Automatic deletion after 24 hours (RGPD compliance)
- Processing happens entirely on our EU-based servers
- No third-party services have access to your files
- No AI/LLM services process your data
3. Data Retention
Maximum retention: 24 hours
All uploaded files and conversion results are automatically deleted 24 hours after upload. Only technical metadata (file UUID, size, upload timestamp) is retained for service operation.
4. Your Rights (RGPD/GDPR)
Under RGPD/GDPR, you have the following rights:
- Right to access: Request a copy of your personal data
- Right to rectification: Correct inaccurate data
- Right to erasure: Delete your account and all associated data
- Right to data portability: Export your data in JSON format
- Right to object: Object to data processing
To exercise these rights, contact: privacy@balanzio.app
5. Security Measures
- TLS 1.3 encryption for all data transmission
- ClamAV antivirus scanning on upload
- Rate limiting to prevent abuse
- SHA-256 file hashing for integrity
- IP hashing with pepper (non-reversible)
- No logging of transaction content
6. Cookies
Balanzio uses minimal cookies:
- Session cookie: For authenticated users (HttpOnly, SameSite=Lax)
- Locale cookie: To remember your language preference
No third-party tracking cookies are used.
7. Data Sharing
We do not share, sell, or rent your data to third parties.
Data may only be disclosed if required by law or to protect our legal rights.
8. Children's Privacy
Balanzio is not intended for users under 18 years of age. We do not knowingly collect personal information from children.
9. Changes to Privacy Policy
This privacy policy may be updated periodically. The latest version will always be available at this URL with the effective date below.
10. Contact
For privacy-related questions or to exercise your rights: