Position
What we do not need, we do not store.
For a tool that works with documents, data protection is not a footnote in the proposal. It is half the construction.
The points below are written so that they can be checked. What is here is also in the data processing agreement; what is not there, we do not promise here.
- 01
Processed in the EU
Application, database and file storage sit in European data centres. Language models run through European providers or European regions; transcription uses a European model by default. You get the list of services and processing locations before signing.
- 02
No training on your content
The models we use run without a training licence. Your documents do not improve anyone else’s model.
- 03
Separation between tenants
Every organisation works on its own records. The access check sits in the database itself rather than in the application in front of it — a bug in the interface cannot bypass it.
- 04
Restraint with personal data
Specially protected fields are replaced before a language model sees them, not redacted afterwards. The test is whether data relates to a person, not which category the statute puts it in.
- 05
Deletion on a deadline
Enquiries and bookings made on this site are deleted automatically after a set period. Access and erasure run through the tools built for it rather than an email to us.
- 06
No third-party scripts
This website loads no fonts, maps, videos or counting pixels from anyone else. That is why there is no consent banner — there would be nothing to consent to.
AI Act
Classified, not asserted.
Every workflow carries its legal basis and its risk classification — derived from what the workflow actually reads, not from a self-assessment.
The derivation looks at individual fields. The difference is not academic: a workflow that only reads a reference list is quickly classed as free of personal data — until someone notices the list holds named contacts. Of all the wrong labels, “no personal data” is the worst, because it says there is nothing to check.
- Transparency — wherever a result goes outside, it is visible that a system was involved.
- Assessment of people — workflows that evaluate individuals run on the device only and never without human release.
- Processing record — every run leaves behind what it drew on, who started it and who released it.
Operation
Two routes, the same software.
Hosted
Run by us in a European data centre. Setup, backups, updates and monitoring included. The usual route.
On your own infrastructure
Installed in your data centre, for organisations with their own infrastructure or particular obligations. Updates by arrangement, operation on your side.
A list of the subprocessors involved, with processing location and purpose, is part of the data processing agreement. You get it before signing, not after.
Reporting
If you find something.
If you find a vulnerability, please tell us before you publish it. We reply within three working days, keep you posted, and credit you by name if you want. We do not take legal action against people who report responsibly.