Aspiro StateMint

Privacy Policy

Last updated: 13 June 2026

1. Who we are

Aspiro AI Ltd (“Aspiro”, “we”, “us”) is the controller of the personal data we collect about you when you use Aspiro StateMint. Our registered address and contact details are at the end of this policy. We are not currently registered with the ICO as a data controller. [Note: confirm ICO registration status before go-live.]

2. What data we collect about you

When you register and use the Platform we collect:

  • Account data: name, work email address, firm name, market, areas of practice, and optional regulatory reference number.
  • Consent records: the date and version of the Terms you accepted, and whether you consented to marketing communications.
  • Usage data: analyses run, credit balance, timestamps of activity, and session logs.
  • Technical data: IP address, browser type, and session tokens.

We do not retain uploaded bank statement source files. Statement PDFs and CSVs are processed in memory only and immediately discarded after analysis. Only the derived Analysis JSON (categorised transactions, key figures, flags) is stored.

3. Lawful bases for processing

  • Contract (Art. 6(1)(b)): processing necessary to provide the Platform to you: account management, running Analyses, billing.
  • Legitimate interests (Art. 6(1)(f)): security monitoring, fraud prevention, improving service reliability, and aggregated anonymised analytics.
  • Consent (Art. 6(1)(a)): marketing communications, where you have explicitly opted in. You can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): retaining records required by law.

4. How we use your data

  • To provide, operate, and improve the Platform.
  • To manage your account and credits.
  • To respond to your support requests.
  • To send service-related notices (security, policy changes, billing).
  • To send marketing communications, only where you have opted in.
  • To comply with our legal and regulatory obligations.

5. Processors and sub-processors

We use the following third-party processors:

  • Supabase: database hosting, authentication, and session management (EU region).
  • Anthropic: the AI model provider used to generate Analyses. Inputs to the Anthropic API include derived transaction data; Anthropic’s enterprise terms govern their use of API data.
  • Mem0: categorisation memory layer used to improve Analysis accuracy for your organisation over time.

All processors are bound by data processing agreements and are required to process data only on our instructions.

6. International transfers

Supabase stores data in the EU (eu-west-1). Some sub-processors may process data in the United States. Where data is transferred outside the UK or EEA we ensure appropriate safeguards are in place, including Standard Contractual Clauses or equivalent mechanisms.

7. Retention

We retain your account data for as long as your account is active. If you close your account we will delete or anonymise your personal data within 90 days, except where we are required to retain it for legal or compliance purposes (typically up to 7 years for billing records). Analysis results are retained for your account’s lifetime; you may delete individual Analyses from your History at any time.

8. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate data.
  • Erasure (“right to be forgotten”) in certain circumstances.
  • Data portability: receive your data in a structured, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent for marketing at any time (without affecting the lawfulness of prior processing). You can do this in your Account settings.
  • Restrict processing in certain circumstances.

To exercise any right, contact us at [email protected]. We will respond within one calendar month.

9. Cookies

The Platform uses only essential session cookies set by Supabase for authentication. We do not use advertising or tracking cookies. No cookie consent banner is shown because there are no non-essential cookies to consent to.

10. How to complain

If you believe we have not handled your personal data correctly you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email. The “Last updated” date at the top of this page reflects the current version.

12. Contact

Aspiro AI Ltd — [email protected]