Control and privacy

How we set it up. Your sensitive information stays safe.

Promises about security are easy. This is what we actually put on paper per solution. We describe how we set it up, not that it is “handled”. That difference is deliberate.

EU·Anonymous in·every step logged·human approves

1

Purpose and scope

One purpose per solution, in one sentence, captured before data comes into view. Every solution has a process sketch on one page: which data goes in, where it comes from, what the system does with it, what comes out, and where a human decides. That sketch is also the document a firm partner can show to their own clients. No scope expansion without a new sketch.

2

Which data, and no more

Data minimisation is a build rule, not an intention: only the fields the process needs. Personal data is replaced with a reference as soon as the process allows: client number instead of name, invoice number instead of description. No full file dumps, no “we take everything and filter later”. We do not process special-category personal data. If a process comes close, we do not build it without a legal review.

3

Where it runs

Processing in the EU. Our assumption is a Western-Europe cloud region, with data at rest in the EU. No consumer AI tools in the chain: no free chatbots, no browser plug-ins, no tools whose processor terms are not on paper. Per solution we keep a record of which services are in the chain and where they run.

4

No training on your data

Only business API endpoints with retention off and training off; set by default, not reasoned about per project. Your data is not used to improve models or prompts for other clients. What we take to the next client is the method, never the content. This is explicit in the processor agreement, not only on the site.

5

Access and retention

Named accounts with MFA; no shared logins, not even temporarily. Minimal rights: only the sources the process needs, read-only where writing is not needed. Our access ends at handover, unless there is a maintenance agreement. On the handover date it is demonstrably revoked. An overview of who has access is available on request.

The system is the retention policy, not an agreement: deletion is built in and scheduled.

Bewaartermijnen. Per klant bevestigd bij aanvang.
Wat Termijn
Tussenbestanden en verwerkingsdata 30 dagen, daarna automatisch verwijderd
Logging van geautomatiseerde stappen 12 maanden
Bronmateriaal uit de afbakening tot einde project, daarna verwijderd of teruggegeven
Verwijdering op verzoek binnen 30 dagen, met bevestiging

6

Traceability and human control

Every automated step logs: timestamp, input reference, output, version of the solution. Every outcome traces back to the source it came from. An outcome that cannot be traced back is a bug. Test protocol per step, delivered with the solution. That is also what the name Proofin stands for: proven rather than claimed.

The system proposes, a human approves. For anything that enters the admin, reaches a client, or goes to the tax authority, an approval step stays in place. Where that step sits is stated on the process sketch, and never implicit. Exceptions and low confidence go to a human, not through the standard path.

7

What you sign, and what you remain responsible for

At the start you sign a data processing agreement where you are the controller and we are the processor. Standard template, per client with the right annexes. The annexes contain a sub-processor list with name, role and country, and a change is notified in advance, with a right of objection. Confidentiality is explicit, with reference to the confidentiality obligations of your own firm (NBA in the Netherlands, ITAA in Belgium; subject to legal review).

In case of an incident there is one reporting line; we notify you within 24 hours so you can act within the statutory 72 hours. On termination you get the configuration, the documentation and the data; we delete our copies and confirm this in writing.

You remain controller for the data you supply and for how you use the solution inside your organisation. We take the processor role: building, running and making demonstrable what happens.

8

What you can explain to your own clients

For firms that want to explain this to their own clients, we deliver a process description on one page per solution. It states which data is used, where processing happens, how long things are retained, and where the human decides. Your client needs that text to answer the GDPR questions inside their own file.

Downloadable process description

One page, per solution, in the form you can hand to your client. The template is in the works.

Download the sample one-pager

Our claim

What we allow ourselves to say on our site

Four sentences. Not more. Anything beyond that we do not write, until it is arranged and tested.

Per solution we record which data is needed, where it lives, and where the human decides.

Your data is not used to train models.

Processing in the EU.

Every automated step is traceable and tested.

Ask on the call

The principles above are our build rules. For your specific situation we can walk through how they apply on the discovery call.