How your client's statements are held
This page is for the person at your practice who has to sign off on sending client data to a third party. It names every company that touches a file, every window we keep one for, and every certification we do not hold.
Where it sits
Statement files are held in private, access-controlled object storage with server-side encryption, in a bucket whose jurisdiction is the EU. That jurisdiction is fixed when the bucket is made and cannot be changed afterwards.
The model that reads a scanned page runs on a third-party API and that inference is global by default. We do not pin it to a country. A bucket's jurisdiction does not bind inference, so we state the two separately rather than letting one imply the other.
In transit, TLS. At rest, AES-256: the storage provider encrypts every object by default, and the writes we make ourselves ask for it explicitly as well.
We never use your data, or your client's, to train any model. Nobody we send a page to trains on it either.
One credential set reaches the bucket and it is held by the person named on the about page. Every operator read of a statement or a transaction writes a row you can read on your own data page: who opened it, which client, which statement, and why.
Retention
Shorter than every tool we compared against, and each window has a reason rather than a default.
| Data | Default | Your control |
|---|---|---|
| Statement PDFs | 7 days after delivery | 1, 7 or 30 days |
| Export files | 30 days | 7, 30 or 90 days |
| Transactions | 13 months, then archived and removed from the database | Delete now, per client or per workspace |
| Merchant memory | Kept while the client exists | Export as CSV, delete per client, delete all |
| Job and event records | Kept as audit records, with no statement content in them | Deleted with the account |
Statement PDFs go at 7 days and not at 1 because 7 is the window in which a correction or a re-delivery is actually asked for. Exports go at 30 days, when the download link expires. A deletion you ask for overrides both, completes inside 24 hours, and is confirmed by email with a reference.
Sub-processors
Named, with what each one touches. We tell you before we add one.
| Sub-processor | What it processes | Where | Sees a statement? |
|---|---|---|---|
| Cloudflare | Hosting, object storage, database, queues, and the sign-in challenge | Object storage jurisdiction: EU | Holds the file, reads nothing |
| Anthropic | Model inference on statement pages | Global by default | Yes, the page content |
| Stripe | Payment and billing | Stripe's own regions | No, never |
| Resend | Transactional email: the sign-in link, the receipt, the deletion confirmation | Resend's own regions | No. An address and a subject line |
| Sign-in only, and only if you choose it | Google's own regions | No, never |
What we do not have
Named, because a page that omits the subject reads worse than one that names the gap.
| Not held | When we revisit it |
|---|---|
| SOC 2 Type II | At 50 paying practices, or the first buyer who requires it |
| ISO 27001 | Not planned |
| An external penetration test | Once we hold data for more than 50 practices |
| A bug bounty | After the first penetration test |
| A published uptime commitment and a status page | After 100 practices |
| A choice of data region per customer | After the first customer who requires storage outside the EU. The bucket jurisdiction is irreversible, so this means a second bucket |
The data processing agreement
You are the controller and we are the processor, and your regulator expects a written contract between the two. It carries the Article 28(3) subject matter, duration, nature and purpose, the data types and the data subjects, plus the eight minimum terms, including sub-processors and audits.
If something goes wrong
Report a security problem to hello@halebook.com. One person is responsible for answering it, and that person is named on the about page.
- We assess within 4 hours: what happened, which workspaces, which data.
- We contain it: rotate the secret, revoke sessions, disable the path.
- We tell every affected practice within 24 hours, in writing, because you are the controller and your own 72-hour clock depends on ours.
- We notify the regulator within 72 hours where the threshold is met.
- We write a public note afterwards and link it from this page.