ReconCSV
Menu

Data Processing Agreement

Effective date: July 25, 2026

This Data Processing Agreement ("DPA") is a template that accounting and bookkeeping professionals can execute with ReconCSV when using the Service to process client bank statements. It is designed for professionals subject to obligations such as the FTC Safeguards Rule and the data-security expectations of IRS Publication 4557, who need a written processor agreement for their own compliance files.

The headline: ReconCSV's standard converter processes statement PDFs locally in your (or your client's) browser. Statement data never reaches our servers. Most processor obligations in a typical DPA concern what happens to data on the processor's systems — by design, there is no statement data on ours.

This template is provided for convenience and transparency and is not legal advice. Have your own counsel review it if your regulatory situation requires.

1. Parties and roles

This DPA is entered into between:

  • Customer — the accounting, bookkeeping, or tax professional (or their firm) identified in the signature block below, acting as the controller of any personal data contained in the documents they process; and
  • ReconCSV ("Processor", "we", "us") — operator of the ReconCSV service at reconcsv.com, acting as the processor (or service provider) where and only where any personal data is processed on our systems.

Each party is responsible for its own compliance with applicable data-protection and financial-privacy laws.

2. Scope and purpose of processing

Processing under this DPA is limited to what is necessary to provide the Service: converting bank-statement PDFs into CSV, Excel, or QBO files, and reconciling extracted transactions against statement balances. No processing is performed for advertising, profiling, resale of data, or any purpose unrelated to delivering the conversion Service.

3. Nature of the data

The data concerned is the content of bank-statement PDFs: account holder names, account numbers, transaction dates, descriptions, amounts, and balances, belonging to the Customer's clients.

For the standard in-browser converter, none of this data is transmitted to, stored by, or accessible to ReconCSV (see Section 4). The personal data ReconCSV itself holds is limited to the Customer's account email (if registered), aggregate usage counters containing no file contents, and standard server logs.

4. Local-first processing clause

  1. The standard ReconCSV converter executes entirely in the user's web browser. Statement PDFs are read and parsed by JavaScript on the user's own device; the file bytes and everything extracted from them remain in browser memory and are never sent to ReconCSV servers.
  2. The exported CSV/Excel/QBO files are generated on the user's device and saved directly to it.
  3. The parties therefore agree that, for use of the standard converter, the processing of statement content does not occur on Processor systems, and the processor obligations in this DPA (security of stored data, breach of Processor systems, deletion from Processor systems, subprocessors) are satisfied by design for that data: there is no statement data on Processor systems to secure, breach, retain, or delete.
  4. The Customer remains the controller of all statement data and is responsible for the security of the devices and browsers on which conversions are performed.

5. Processing for the optional cloud feature (future)

Status: planned, optional, off by default. This section applies only if and when the feature launches and the Customer explicitly opts in per file.

For scanned PDFs that cannot be parsed locally, we plan to offer an optional cloud AI conversion feature. If enabled and used:

  1. Transient processing. Uploaded PDFs are processed in memory; original files are deleted immediately after processing, and generated exports are retained no more than 24 hours for download, then deleted.
  2. No training. Customer documents are never used to train AI models, by us or by any provider; AI API providers are engaged under zero-retention terms.
  3. Subprocessors. Hosting (Vercel), payment processing (Paddle, when paid plans are used), transactional email (Resend, when enabled), and the cloud AI API provider (when the feature is used). We will notify Customers by email before adding or replacing any subprocessor, and Customers may terminate use of the affected feature if they object.
  4. The Customer chooses the feature per file; local conversion remains the default and nothing in this section changes Section 4 for local conversions.

6. Confidentiality

ReconCSV personnel and contractors are bound by confidentiality obligations covering any Customer or client data they may access in the course of operating the Service. Given the local-first architecture, such access to statement content does not occur for standard conversions; for any support interaction, Customer data is used solely to provide the Service and is never disclosed except as required by law.

7. Security measures

ReconCSV maintains administrative, technical, and organizational measures appropriate to the data it actually handles, including:

  • TLS encryption for all traffic between the browser and our servers;
  • Encryption at rest for any transient storage (applies to the optional cloud feature, when enabled);
  • Access controls limiting production-system access to authorized personnel on a least-privilege basis;
  • The architectural control that standard conversions involve no server-side receipt of statement data at all.

Formal third-party certifications (e.g., SOC 2) are on our roadmap but not yet held; we make no certification claims. Customers who require certified attestations today should rely on the standard local converter, which keeps statement data off our systems entirely.

8. Data subject rights assistance

Taking into account the nature of our processing — we hold, at most, an account email and aggregate counters — ReconCSV will reasonably assist the Customer in responding to data-subject requests (access, deletion, correction) that relate to data in our possession, at no charge for routine requests. Requests concerning statement content itself can only be fulfilled by the Customer, because that content is on the Customer's side, not ours.

9. Deletion on completion

Upon termination of the Customer's use of the Service or upon request, we will delete the personal data we hold (account email and any associated records) within a reasonable period, subject to legal retention requirements. Statement content requires no deletion action on our side for standard conversions — it was never received. For the optional cloud feature (when enabled), deletion follows the schedule in Section 5 automatically.

10. Audit and information rights

Given the scale of our operation, audits are handled by questionnaire: the Customer may submit reasonable written security and privacy questions (for example, a standard vendor-assessment or SIG-lite questionnaire) to [email protected], and we will respond in writing within a reasonable time. On-site inspections are not practicable for a service of our size; the local-first architecture is intended to make extensive audit rights unnecessary for the data that matters most.

11. Liability

Each party's liability under this DPA is subject to the limitation-of-liability provisions of the ReconCSV Terms of Service. Nothing in this DPA limits liability that cannot be limited by law.

12. Governing law

This DPA is governed by the laws of the State of Delaware, USA, and any disputes will be resolved in the state or federal courts located in Delaware.

13. Signatures

For the Customer For ReconCSV
Name _____________________________ _____________________________
Company _____________________________ ReconCSV
Title _____________________________ _____________________________
Date _____________________________ _____________________________
Signature _____________________________ _____________________________

How to execute this DPA

  1. Fill in and sign the Customer column (digitally or on paper).
  2. Email the signed page to [email protected] — we countersign and return it within 2 business days.
  3. Keep the countersigned copy in your compliance files (e.g., alongside your FTC Safeguards Rule or IRS Pub 4557 documentation).

Questions before signing? Email [email protected].