The short version
Your uploaded bank statement PDF is processed in the UK, used to generate your report, and then permanently deleted within 60 minutes. The original file is never retained. We are ICO registered, GDPR compliant, and process all data exclusively on UK servers. We never sell, share, or use your data for any purpose other than generating your report.

Security Measures

AES-256 Encryption

All files are encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. Your client's bank statement data is protected from the moment it leaves your browser to the moment it is deleted.

Automatic File Deletion — 60 Minutes

Uploaded bank statement PDFs are automatically and permanently deleted from our servers within 60 minutes of upload. The original PDF is never stored beyond this window. What we retain is only the structured analysis output — the income figures, risk scores, and transaction classifications.

UK & EU Data Processing

Uploaded bank statement files are processed exclusively on UK servers in the London region (AWS eu-west-2). Structured analysis data (income figures, risk scores, transaction classifications) is stored in encrypted EU servers in Ireland (Supabase eu-west-1), in full compliance with UK GDPR. No data is transferred outside the UK/EU.

ICO Registered

AutoConvertPros is operated by Sparkleen Consult Limited (Companies House: 15744371), registered with the UK Information Commissioner's Office under registration number ZC108380. Our ICO registration confirms we have declared our data processing activities to the regulator as required under UK GDPR.

No Data Sold or Shared

Your client's financial data is never sold, shared with third parties, used for advertising, or used to train machine learning models. The data you upload is used solely to generate your analysis report and then deleted.

Access Controls

Each user can only access their own uploaded statements. Firm plan admins can view statements uploaded by their team members. No cross-account data access is possible. All API access requires authentication.

What Data We Hold and For How Long

This table explains every category of data AutoConvertPros processes — what it is, how it is stored, and when it is deleted.

Data TypeHow It's StoredWhen It's Deleted
Uploaded bank statement PDFProcessed in memory, stored temporarily in UK S3Deleted within 60 minutes of upload
Extracted transaction dataStored in encrypted UK database (Supabase Ireland)Retained for 24 months, then deleted
Income analysis resultsStored in encrypted UK databaseRetained while account is active
Account information (email, name)Stored in encrypted UK databaseRetained while account is active; deleted on request
Payment informationHandled entirely by Stripe — never stored by AutoConvertProsGoverned by Stripe's data retention policy
Usage logs and audit trailStored in encrypted UK databaseRetained for 24 months for compliance

Your Rights Under UK GDPR

Under UK GDPR, you have the following rights regarding your personal data held by AutoConvertPros:

Right to accessRequest a copy of all personal data we hold about you.
Right to erasureRequest that we delete your account and all associated data. We will action this within 30 days.
Right to portabilityRequest your data in a structured, machine-readable format.
Right to rectificationRequest correction of any inaccurate personal data we hold.
Right to objectObject to processing of your personal data in certain circumstances.

To exercise any of these rights, email support@autoconvertpros.com. We will respond within 30 days.

Sub-Processors

AutoConvertPros uses the following third-party services to operate. Each is contractually bound to process data only as instructed and in compliance with UK GDPR.

AWS (Amazon Web Services)File storage and OCR processing
eu-west-2 (London, UK)
SupabaseDatabase and authentication
eu-west-1 (Ireland, EU)
StripePayment processing
EU/UK data centres
ResendTransactional email delivery
EU data centres
VercelApplication hosting
EU edge network
Questions About Data Security?

If you have any questions about how AutoConvertPros handles your data, or if you wish to exercise your GDPR rights, contact us directly.

support@autoconvertpros.com