Data Privacy and Security
Presto takes rigorous measures to ensure a high standard of data privacy and security for our customers.
Security architecture
Strict access management: Data access follows the least-privilege principle and is limited to the absolute minimum.
Layered security architecture: Multiple independent security layers protect your data at every level of the platform.
Adaptive security: Continuous updates to security controls defend against current and future threats.
Hardened data processing: Secure processes govern data handling from start to finish.
A reliable data foundation
EU hosting: The application and your data are hosted entirely in the EU, with servers in Frankfurt.
No model training: Customer data is never used to optimise or train AI models.
Zero Data Retention: Presto has Zero Data Retention and EU-hosting agreements in place with all LLM providers.
Encryption in transit and at rest: Data is encrypted with AES-256 and TLS 1.2+.
Secure credential management
How Presto keeps supplier portal credentials controlled.
Credentials stay on your device: The portal downloader runs locally on your computer. Credentials for supplier portals are never uploaded to our cloud.
Strong agent guardrails: Agents used to download invoices from billing portals never access your passwords directly. Passwords are filled in by a dedicated local tool and agents only see placeholders.
Legal documents
Questions & answers
Everything about data privacy and security.
Is my data safe?
Yes. Your portal credentials are encrypted and stored only on your device — they never reach our servers. Invoice files are processed securely and transferred directly to your chosen export destination.
Are my portal credentials stored in the cloud?
No. The portal downloader runs locally on your computer. Credentials for supplier portals are kept encrypted on your device and are never uploaded to our cloud.
Is Presto GDPR-compliant?
Yes. Presto is fully GDPR-compliant and all data is hosted exclusively in the EU (Frankfurt). Your portal credentials are never stored in the cloud — the portal downloader runs locally on your machine. We provide a Data Processing Agreement (DPA) on request.
How does Presto encrypt data?
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256 — industry-standard methods that protect your data both during processing and in storage.
Does Presto use my data to train AI models?
No. Your data is never used to optimise or train AI models.
Do you provide a Data Processing Agreement (DPA)?
Yes. We provide a DPA for business customers on request. Just reach out and we'll send you the document to sign.
What happens to my data if I stop using Presto?
You can request deletion of your data at any time. Data is only retained for as long as necessary to provide the service and is then removed in line with our deletion policy.