
It is 9pm in the middle of filing season, you have a statement in a format nothing will read, and the first search result is a free tool that converts bank statement PDFs to Excel in one click. You upload the file. It works. You move on.
The tool did its job. The question worth sitting with is a different one: what did you just agree to on behalf of a client who was never asked?
What you actually uploaded
A bank statement is not a neutral document. In a single file it carries the account number, the account holder's name and address, the closing balance, every counterparty they paid or were paid by, their salary, their loan repayments, their insurance premiums, and a month by month picture of how the business or household actually operates.
It is close to the most sensitive commercial document a client will ever hand you, and it is more revealing than the financial statements you eventually produce from it. Those get summarised. The statement does not.
The terms you did not read
Free tools are not charities. The processing costs the operator real money, so it is reasonable to ask what pays for it.
The answers vary, and some are perfectly benign: a free tier that upsells to a paid one, or a loss leader for an accounting product. Others are not. The specific things worth knowing about any tool you upload to:
- How long the file is retained after conversion. "Deleted immediately" and "deleted after 24 hours" and "retained for service improvement" are three very different commitments, and only one of them is in your client's interest.
- Whether the content is used to train models. This is now a standard clause and it is frequently buried in a general "improve our services" phrase.
- Which country the server is in, and therefore whose law governs the copy.
- Whether there is any named legal entity behind the site at all. A surprising number of converter sites have no company name, no address and no way to contact anyone.
- Whether the connection and the storage are encrypted, which is the easiest of these to check and the least meaningful on its own.
Important
A tool that does not name the company operating it cannot be assessed at all. There is no entity to hold to a commitment, no jurisdiction, and nobody to ask what happened if the data turns up somewhere. That alone should be disqualifying for a client file.
Under the DPDP Act, this is your exposure and not theirs
This is the part that changes the calculation for a practice, and it is worth being precise about.
India's Digital Personal Data Protection Act works on a distinction between the Data Fiduciary, who determines why and how personal data is processed, and the Data Processor, who processes it on the fiduciary's behalf. When your client gives you their statement and you decide to route it through a converter, you are the fiduciary and the converter is your processor.
The practical consequence is straightforward. Choosing the processor is your decision, so the responsibility for that choice sits with your firm. It does not transfer to the vendor because their terms of service say so, and it does not disappear because the tool was free.
So the honest question is not "is this tool safe". It is "can I explain and defend this choice if I am ever asked to". Those are different standards, and the second one is the one that applies.
This is a general description of how the roles work and not legal advice for your firm. If you process client data at any scale, it is worth twenty minutes with someone who does this properly.
It is not your data to be relaxed about
There is a quieter point underneath the compliance one, and in practice it matters more.
The statement is not your firm's data. It belongs to your client, and they gave it to you for one narrow purpose: to get their books done. They did not give it to you so that it could be uploaded to a third party they have never heard of, in a country they were not told about, under terms nobody read to them.
When a client asks where their data goes, they are asking three specific things: where is it stored, who can see it, and who else has it been passed to. If your answer involves a converter site, you cannot answer any of the three with confidence. Being unable to answer is itself the problem, quite apart from whether anything ever goes wrong.
The firms that handle this well tend to be the ones that decided in advance, once, rather than deciding at 9pm in filing season with a deadline in front of them.
Pro tip
Write your answer down before you need it. One short paragraph in your engagement letter describing where client documents are processed and what tools touch them is worth more than any assurance you improvise on a phone call, and it forces the decision while you are calm.
The questions to ask, and what a good answer looks like
If you are evaluating any tool that touches client statements, cloud or otherwise, these five questions settle it quickly.
- Who is the legal entity operating this, and where is it registered? A named company with a real address is the minimum bar.
- Where is my client's file processed, and where is it stored afterwards? "On your own machine" is the simplest possible answer, because there is no afterwards.
- How long is it retained, and can I delete it? Retention should be a number, not an adjective.
- Is the content used for training or analysis of any kind? A clear no, in writing.
- If my client asks me where their statement went, what exactly do I tell them? If you cannot write that sentence down comfortably, you have your answer.
What on-device processing actually changes
There is a version of this problem that does not require you to trust anyone's retention policy, because there is nothing to retain.
When the statement is read on your own PC, the file never leaves the building. There is no upload, no third party copy, no jurisdiction question and no retention period, because no server ever received it. Your firm remains the data fiduciary from the moment the client sends the file to the moment the vouchers land in Tally, which is the only arrangement where the answer to "who else has this" is genuinely "nobody".
It is worth being precise about what this does and does not mean. It does not mean software that works without an internet connection; Greenote needs internet to sign in and to update, like anything else. It means your client's bank data is not part of that traffic. The only thing Greenote contacts to post vouchers is the Tally already running on your own machine.
It also means the tool is a pass-through and not a filing cabinet. The destination is Tally. Data sitting in a conversion tool all year is a liability rather than a safety net, which is a distinction worth applying to every tool in your practice.
Conclusion
Free online converters are not uniquely dangerous and this is not an argument that anyone using one has done something wrong. It is an argument for making the decision deliberately, once, in daylight, rather than at 9pm with a deadline.
Ask the five questions. Write down the answer you would give a client. If the answer is comfortable, carry on. If it is not, the fix is to move the processing somewhere you control.
Greenote reads bank statements on your own PC and posts vouchers straight into Tally, so the answer to "where did my statement go" stays "it never left your office". See how it compares with the cloud tools, or check your client's bank.
Start a free trial. Seven days, no card.
Turn bank statements into Tally vouchers offline
Greenote reads 100+ Indian banks and posts clean vouchers straight into Tally, fully on your PC. No uploads, no cloud, no manual entry.
7-day free trial, no card required. Works with Tally Prime & ERP 9.
