How your client's statements are held

This page is for the person at your practice who has to sign off on sending client data to a third party. It names every company that touches a file, every window we keep one for, and every certification we do not hold.

Where it sits

Statement files are held in private, access-controlled object storage with server-side encryption, in a bucket whose jurisdiction is the EU. That jurisdiction is fixed when the bucket is made and cannot be changed afterwards.

The model that reads a scanned page runs on a third-party API and that inference is global by default. We do not pin it to a country. A bucket's jurisdiction does not bind inference, so we state the two separately rather than letting one imply the other.

In transit, TLS. At rest, AES-256: the storage provider encrypts every object by default, and the writes we make ourselves ask for it explicitly as well.

We never use your data, or your client's, to train any model. Nobody we send a page to trains on it either.

One credential set reaches the bucket and it is held by the person named on the about page. Every operator read of a statement or a transaction writes a row you can read on your own data page: who opened it, which client, which statement, and why.

Retention

Shorter than every tool we compared against, and each window has a reason rather than a default.

DataDefaultYour control
Statement PDFs7 days after delivery1, 7 or 30 days
Export files30 days7, 30 or 90 days
Transactions13 months, then archived and removed from the databaseDelete now, per client or per workspace
Merchant memoryKept while the client existsExport as CSV, delete per client, delete all
Job and event recordsKept as audit records, with no statement content in themDeleted with the account

Statement PDFs go at 7 days and not at 1 because 7 is the window in which a correction or a re-delivery is actually asked for. Exports go at 30 days, when the download link expires. A deletion you ask for overrides both, completes inside 24 hours, and is confirmed by email with a reference.

Sub-processors

Named, with what each one touches. We tell you before we add one.

Sub-processorWhat it processesWhereSees a statement?
CloudflareHosting, object storage, database, queues, and the sign-in challengeObject storage jurisdiction: EUHolds the file, reads nothing
AnthropicModel inference on statement pagesGlobal by defaultYes, the page content
StripePayment and billingStripe's own regionsNo, never
ResendTransactional email: the sign-in link, the receipt, the deletion confirmationResend's own regionsNo. An address and a subject line
GoogleSign-in only, and only if you choose itGoogle's own regionsNo, never

What we do not have

Named, because a page that omits the subject reads worse than one that names the gap.

Not heldWhen we revisit it
SOC 2 Type IIAt 50 paying practices, or the first buyer who requires it
ISO 27001Not planned
An external penetration testOnce we hold data for more than 50 practices
A bug bountyAfter the first penetration test
A published uptime commitment and a status pageAfter 100 practices
A choice of data region per customerAfter the first customer who requires storage outside the EU. The bucket jurisdiction is irreversible, so this means a second bucket

The data processing agreement

You are the controller and we are the processor, and your regulator expects a written contract between the two. It carries the Article 28(3) subject matter, duration, nature and purpose, the data types and the data subjects, plus the eight minimum terms, including sub-processors and audits.

Read the agreement and download it

If something goes wrong

Report a security problem to hello@halebook.com. One person is responsible for answering it, and that person is named on the about page.

  1. We assess within 4 hours: what happened, which workspaces, which data.
  2. We contain it: rotate the secret, revoke sessions, disable the path.
  3. We tell every affected practice within 24 hours, in writing, because you are the controller and your own 72-hour clock depends on ours.
  4. We notify the regulator within 72 hours where the threshold is met.
  5. We write a public note afterwards and link it from this page.