AI statement

Which models we use, where your data goes and what we log.

Version 2026-10, v0.1

Which models

For each task we pick the model that does the job best at the lowest cost, and we build every automation so that the model can be replaced. European providers (such as Mistral) where possible; the EU regions of Anthropic, OpenAI or Google where necessary. The documentation for each assignment states which model is used where.

Where data goes

Automations run on servers in the EU, on accounts in the client's name. Model requests go to EU regions or European providers. No data goes to providers outside the EU unless this is explicitly stated in the data processing agreement.

Personal data (name, address, phone, IBAN, BSN) is masked before a language model sees it, unless the task needs it and the client has signed off on that.

No training on your data

We only use providers and settings where your data is not used to train models. We do not train models on client data ourselves without a separate written assignment.

Human approval

Everything that goes out of the door (quotes, emails to clients, bookings, payments) is approved by a person, unless the client decides in writing, after a trial period, to let a specific step run without approval.

Logging

Every run is logged: what came in, what the model decided, what a person approved or changed. Logs are kept on the client's server and retained for 12 months by default.

Sub-processors

The list of sub-processors per assignment (hosting, model provider, email sending) is in annex 1 of the data processing agreement and is updated before anything changes.

DPIA and AI Act

For applications involving personal data we help prepare a DPIA. For the AI literacy obligation, workshops provide an attendance list and certificate. We are not lawyers; for high-risk applications within the meaning of the AI Act we refer you on.

This is a working draft, prepared without legal advice. Have the final text reviewed by a lawyer before the site goes live.