What we do with your data, and what we don't
Item Value Status Hosting EU yes Storage EU yes AI processing EU yes EU processing for filing data
Hosting, database storage, document persistence, OCR and AI document processing run in EU regions for filing data. Model inference uses OpenRouter's EU data-region endpoint.
Item Value Status At rest AES-256 on In transit TLS 1.2+ on Keys AWS KMS · EU per document AES-256 at rest, TLS 1.2+ in transit
Each source document is encrypted inside the application before it reaches storage, under its own key from AWS KMS in the EU.
Item Value Status Cloud role · location listed AI role · location listed Updates versioned public Published cloud and AI providers
The current sub-processor list is public and names each provider's role and processing location.
Item Value Status Roles admin · member RBAC Admin log workspace recorded SSO / SAML on request available Role-based access control
RBAC, with administrative activity recorded in an audit log scoped to your workspace. SSO/SAML for configured organisations.
Item Value Status Suggestions editable always Package on request by a person Filing never automatic yours Human in the loop
Suggestions are always editable and overridable, and a package is only generated when a person asks for it. The platform never files on your behalf.
Item Value Status DPA public yes Security measures public yes Deletion 30 days after end GDPR-oriented controls
The DPA, sub-processor list and security measures are public. Uploaded documents are deleted within 30 days of account deletion or contract termination, subject to limited backup, recovery and legal-retention exceptions.
Everything procurement asks for, in one place.
- Data Processing AgreementStandard DPA covering processing, sub-processors, and security measures.
- Security measuresTechnical and organisational measures.
- Sub-processor listUp-to-date list with locations and roles.
- Acceptable Use PolicyWhat you can and can't do on the platform.
- Incident response processHow we assess, contain, and notify (GDPR Article 33).
Version 1.2, last updated 31 August 2026. Any audited security programs referenced apply to the relevant sub-processor's services and are not a certification of Doc2iXBRL itself.


