Back to the Data Processing Agreement
Security Measures
DPA Annex C. OntosCompile, operated by Ontos B.V.
Version 1.0 · In force since August 9, 2026
This document describes the technical and organisational security measures implemented by Ontos B.V. (operating as OntosCompile, the "Provider") to protect Personal Data and ensure the ongoing confidentiality, integrity, and availability of the Services. More detail is available on request. The Provider reserves the right to revise these measures from time to time, provided that no such revision shall materially reduce or weaken the protection provided for Personal Data that the Provider processes in the course of providing the Services.
How OntosCompile works
The Services comprise a cloud-based software-as-a-service platform, accessible via a web interface, for compiling Dutch statutory annual reports and preparing them for filing with the Kamer van Koophandel. The platform is used by accountancy firms, bookkeeping firms, tax advisory practices, and in-house finance departments.
Sub-processors
The Provider engages carefully vetted sub-processors for defined purposes. The current list is Annex B to the Data Processing Agreement, and changes to it are published on a feed customers can subscribe to.
Business continuity management
Automated daily database backups are performed, with point-in-time recovery in accordance with the platform capabilities of the database sub-processor. Source code is version-controlled and backed up continuously. Backups are encrypted in transit and at rest. Documented recovery procedures are in place and reviewed periodically.
Supplier relationship management
The Provider selects sub-processors based on their technical and organisational measures, and binds them by written agreement to confidentiality and data-protection obligations materially equivalent to those in the Provider's Data Processing Agreement. The Provider periodically reviews its sub-processors' continued compliance, and records each dependency with its licence, its risks, and the mitigations that apply.
Information security management
The Provider maintains documented information-security policies and procedures and reviews them periodically. The underlying cloud infrastructure is certified to recognised standards, including ISO/IEC 27001 and SOC 2, at the infrastructure level. The Provider's own compliance baseline (protected branches, dependency alerts, a software bill of materials with a licence gate, and secret scanning) is enforced by automation rather than by convention.
System access control
Provider personnel are granted access on a role-based, least-privilege basis; access is limited to what is necessary to fulfil their job responsibilities. Access rights are promptly revoked upon termination of employment or engagement.
Physical access control
Processing takes place in data centres operated by the Provider's infrastructure sub-processors, in EU regions. These data centres maintain industry-standard physical security controls, including continuous monitoring and controlled access by authorised personnel only.
Data access control
Users authenticate via the Provider's authentication layer; passwords are stored hashed and salted in accordance with industry best practice, and passkeys are supported so that a device's own screen lock can replace a password. Customer data is isolated at the database level through row-level security, so that each User can reach only the data belonging to their own organisation, and route authorisation enforces the same boundary a second time in the application layer.
Field-level encryption
Beyond encryption at rest, designated sensitive fields are encrypted individually, at the application layer, with a per-value key derived through a key-management service in the EU. The database stores only the ciphertext envelope, so a copy of the database without access to the key service does not yield the underlying values. Searchable encryption is used where a field must remain queryable, so that protecting a value does not force the application to decrypt the whole column to find it. The mechanism is in production today for the fields designated so far, and the Provider extends the designated set as further parts of the compilation pipeline are released. It is an additional layer: it does not replace encryption at rest, which covers all Customer Data.
Transmission access control
Data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256 or an algorithm of equivalent strength.
Entry control
Audit-relevant application and database activity is written to an append-only audit log, with entries traceable to individual authenticated users. Logs are retained for a period appropriate to detect and investigate security incidents.
Availability control
The Provider applies security patches in a timely manner, with expedited patching in response to disclosed critical vulnerabilities. Customer environments are logically separated through row-level security and organisation scoping; Customers cannot reach data belonging to other Customers.
Separation control
Development, preview, and production environments are logically separated. Customer data resides only in the production environment; preview environments are ephemeral and seeded with synthetic data.
AI processing
AI-assisted suggestions are routed through a single gateway configured to call its EU endpoint, using a key minted per user or organisation so that use is attributable, capped, and revocable. One gateway rather than several is itself a control: it is the one place where routing and retention policy can be set and audited. Customer Data is not used to train models, by the Provider or by its sub-processors, as Clause 2.8 of the Data Processing Agreement provides.
Telemetry privacy
Error tracking and performance tracing are configured so that client financial data does not leave the platform: personally identifying data is disabled in the SDK, local variables are never captured (they would carry filing values), and session replay is not merely switched off but removed from the application bundle so no code path can enable it. User-submitted feedback is the one deliberate exception and is handled as confidential intake with restricted access.
Risk management
The Provider periodically reviews its security posture, including the effectiveness of the measures set out in this document, and updates its policies and procedures accordingly.
Operations security
The Provider monitors software dependencies for known vulnerabilities using automated tooling and installs security updates in a timely manner. A software bill of materials is produced for every proposed and released change and on a recurring schedule, and the repository is scanned for committed secrets on every change. Provider personnel use enterprise-grade email and collaboration tools with standard anti-malware and anti-phishing protections.
Security regarding personnel
Provider personnel are bound by written confidentiality obligations and are informed of their obligations under the GDPR and the UAVG and of the Provider's internal security policies.
Incident response
The Provider maintains a documented procedure for detecting, containing, and notifying on security incidents. The procedure is aligned with Article 33 of the GDPR and the 72-hour notification obligation set out in Clause 7.1 of the Provider's Data Processing Agreement.
Retention of personal data
During the term of the Data Processing Agreement, Personal Data processed by the Provider is subject to the retention instructions issued from time to time by the Customer. Upon termination or expiration of the Data Processing Agreement, Clause 11 of that agreement applies.
Contact
- Legal entity:
- Ontos B.V.
- Address:
- Middelburg, the Netherlands
- CoC:
- 42011303
- VAT:
- NL869277571B01
- Email:
- contact@ontoscompile.com
Version history
Every published version of this document, newest first. The text of a published version is fixed: a change to the wording is published as a new version with its own date.
- Version 1.0 ·