Aspiro StateMint

Data Processing Agreement

Last updated: 13 June 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Aspiro AI Ltd (“Processor”) and the Broker using Aspiro StateMint (“Controller”). It sets out how Aspiro processes personal data on behalf of the Controller in accordance with Article 28 of the UK General Data Protection Regulation (“UK GDPR”).

1. Roles

  • Controller:the Broker, who determines the purposes and means of processing their clients’ financial data (including bank statement data) and who instructs Aspiro to process that data via the Platform.
  • Processor: Aspiro AI Ltd, which processes personal data solely on the documented instructions of the Controller.

2. Subject-matter and duration of processing

Aspiro processes personal data on behalf of the Controller for the purpose of providing the Aspiro StateMint Analysis service (categorising bank statement transactions, identifying financial patterns, and generating lender-ready summaries) for as long as the Controller maintains an active account with Aspiro.

3. Nature and purpose of processing

Processing involves automated analysis of bank statement data using large language model technology to extract, categorise, and summarise financial transactions. The output is a structured Analysis report.

4. Types of personal data and data subjects

  • Types of personal data: bank transaction records, including transaction descriptions, amounts, dates, merchant names, and account balances, as contained in client bank statements submitted by the Controller.
  • Data subjects:the Controller’s clients whose bank statements are submitted for analysis.

Source file retention: uploaded Statement source files (PDFs and CSVs) are processed in memory only and are not persisted to any storage system. This is a deliberate security design decision. Only derived Analysis results (categorised transactions and summary data) are stored.

5. Processor obligations

5.1 Documented instructions

Aspiro will process personal data only on the documented instructions of the Controller as set out in these Terms. If Aspiro is required by law to process personal data otherwise, it will notify the Controller before doing so unless prohibited by law.

5.2 Confidentiality

Aspiro will ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.3 Security (Article 32)

Aspiro implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit (TLS 1.2+) and at rest.
  • Row-level security on all database tables.
  • No persistence of source Statement files (see clause 4).
  • Session expiry and idle timeout controls.
  • Access controls restricting analysis data to the account that generated it.

5.4 Sub-processors

The Controller grants general authorisation for Aspiro to engage sub-processors. Current sub-processors are:

  • Supabase: database, authentication, and storage (EU region).
  • Anthropic: AI model inference for Analysis generation. Transaction descriptions are included in API inputs; Anthropic’s enterprise data processing terms apply.
  • Mem0: categorisation memory layer for improved Analysis accuracy.

Aspiro will notify the Controller of any intended changes to sub-processors and give the Controller the opportunity to object. All sub-processors are bound by data protection obligations no less protective than this DPA.

5.5 Assistance with data subject rights

Aspiro will assist the Controller in responding to requests from data subjects exercising their rights under UK GDPR (access, rectification, erasure, portability, objection) to the extent technically feasible and within a reasonable timeframe.

5.6 Assistance with security, breaches, and DPIAs

Aspiro will notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed under this DPA. Aspiro will assist the Controller with security assessments and data protection impact assessments as required.

5.7 Deletion or return on termination

Upon termination of the service or at the Controller’s written request, Aspiro will delete or return all personal data processed under this DPA within 90 days, except where retention is required by applicable law.

5.8 Audit rights

Aspiro will make available to the Controller all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, subject to reasonable prior notice and confidentiality obligations.

6. International transfers

Where personal data is transferred outside the UK or EEA (for example, to Anthropic for model inference), Aspiro ensures appropriate safeguards are in place in accordance with Articles 46–49 of UK GDPR, including Standard Contractual Clauses where applicable.

7. Controller responsibilities

The Controller warrants and represents that:

  • It has a lawful basis for processing client bank statement data and has provided data subjects with appropriate notice.
  • It is authorised and regulated to carry out the credit or mortgage activities for which it uses the Platform.
  • It will not submit Statements relating to data subjects without having a lawful basis to do so.

8. Contact

For all DPA-related enquiries: Aspiro AI Ltd — [email protected]

Important: This DPA has been drafted by Aspiro AI Ltd and has not been independently reviewed by a qualified legal professional. It requires review by a solicitor experienced in UK data protection law before it is relied upon by any party. In particular, the sub-processor list, international transfer mechanisms, and DPIA assistance clauses should be verified against current ICO guidance.