Data Collection and Use of Sensitive Data
StatementCloud may collect sensitive data only as required to perform our core functions, such as providing access to your financial statements and organizing them into your designated cloud storage provider (e.g., Google Drive, Dropbox, OneDrive).
Sensitive data includes, but is not limited to, your financial statements, account identifiers, and any other personally identifiable information (PII) that is processed while accessing cloud storage services.
Data Protection Mechanisms
Encryption: All sensitive data is encrypted in transit and at rest. StatementCloud uses industry-standard encryption protocols (e.g., TLS/SSL) to secure data transferred between our application and cloud storage services. Sensitive data stored on our servers or within any cloud storage provider is also encrypted using advanced encryption standards.
Access Control: Only authorized personnel have access to sensitive data, and access is restricted based on role and necessity. User authentication mechanisms, such as two-factor authentication (2FA), are required for accessing sensitive features or data.
Data Minimization: We only request permissions to the data that are absolutely necessary for providing our service, ensuring minimal access to sensitive data across all integrated cloud storage providers.
Regular Audits: StatementCloud undergoes regular security audits to assess the security and compliance of our data handling practices. We also comply with data protection guidelines set by cloud storage service providers and continuously monitor our system for vulnerabilities.
User Rights and Controls
Revoking Permissions: Users can revoke StatementCloud’s access to their cloud storage account(s) at any time through their account settings with each respective cloud storage provider.
Data Deletion: Users may request the deletion of their data from StatementCloud, and we will ensure that all sensitive data is permanently erased from our servers and integrated services within a reasonable timeframe.
Data Breach Policy
In the event of a data breach, StatementCloud will notify affected users and relevant authorities in compliance with applicable laws and regulations. Immediate measures will be taken to minimize damage, and steps will be communicated to impacted users.