All legal documents

Two roles, and which one applies to you

OntosCompile processes personal data in two distinct roles, and which one applies decides what governs the processing and who you should address.

We are the controller
For the data we decide about ourselves: your account, the organisation you belong to, what you send us through the contact and demo forms, the feedback you file, and the technical logs and measurement described below. This policy governs that processing.
We are the processor
For the personal data inside the administrations, audit files, and reports a customer processes through OntosCompile. There the customer, usually an accountancy firm, is the controller and decides the purposes; we act on their documented instructions. That processing is governed by our Data Processing Agreement, not by the legal bases in this policy. If you are a person named in such a report and you want to exercise a right, address the organisation that prepared it. Write to us anyway if you cannot reach them, and we will pass the request on.

Data controller

Ontos B.V., operating OntosCompile, is the data controller responsible for the processing described in this policy. You can reach us at:

Data we collect

As controller, we collect the following categories of personal data:

Account and organisation data

Data you bring into the platform

For this category we are the processor, not the controller. See the section above.

What you send us

Technical data

Why we process it, and on what basis

Each purpose below names the legal basis under Article 6 of the GDPR that we rely on.

Providing and securing the platform
Legal basis: performance of a contract (Art. 6(1)(b)). Running your account, keeping the service available, and protecting it against misuse.
Administering organisations and access
Legal basis: performance of a contract (Art. 6(1)(b)). Managing membership, roles, and invitations, so that the right colleagues reach the right work and nobody else does.
Answering a message you send through the contact form
Legal basis: consent (Art. 6(1)(a)). The contact form asks for it explicitly and the server refuses a submission without it, so the consent is a recorded fact rather than an assumption. You can withdraw it at any time, as easily as you gave it.
Improving the product
Legal basis: legitimate interest (Art. 6(1)(f)). Understanding how the platform is used and acting on the feedback you file, so that the next release is better than this one. We use aggregate and technical signals for this, not the contents of your clients' administrations.
Preventing abuse of the public forms
Legal basis: legitimate interest (Art. 6(1)(f)). Screening submissions so that a mailbox is not filled by automated traffic. The signals used are technical and are kept with the submission.
Product news and marketing
Legal basis: consent (Art. 6(1)(a)), opt-in only and switched off by default. Withdrawing it is as easy as giving it and costs you nothing else.
Meeting our own legal obligations
Legal basis: legal obligation (Art. 6(1)(c)). Administrative and tax records, and the security records we must be able to produce.

AI processing

The platform uses AI models to suggest mappings, classifications, and checks. What that means for your data:

Who else processes your data

We engage a small number of sub-processors, each for a defined purpose and each bound by a written agreement. The full list, with the purpose and the location of each, is Annex B to our Data Processing Agreement, and changes to it are published on a feed you can subscribe to. In summary:

We do not sell personal data, and we do not share it for another party's own purposes.

How long we keep it

We keep data only as long as the purpose requires, the law obliges, or a secure recovery process needs:

Your rights

Under the GDPR you have the following rights over your personal data. Where we act as processor for a customer, address the customer first, as explained at the top of this policy.

Access
Ask for a copy of the personal data we hold about you.
Rectification
Ask us to correct data that is inaccurate or incomplete.
Erasure
Ask us to delete your personal data, where no legal obligation requires us to keep it.
Portability
Receive the data you gave us in a structured, machine-readable format.
Objection
Object to processing we base on a legitimate interest, and we will stop unless we can show compelling grounds that override yours.
Restriction
Ask us to limit the processing while a dispute about accuracy or lawfulness is resolved.
Withdrawal of consent
Withdraw consent at any time where the processing is based on it. Withdrawal does not affect what was lawful before it.

To exercise a right, write to us at the address at the foot of this page. We answer within one month, and tell you if we need longer and why.

You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, if you believe your rights have been infringed.

Cookies and measurement

Nothing that needs consent runs before you give it. Until you make a choice, or if you decline, no measurement or advertising script is loaded and no request goes to a measurement provider.

Necessary
Required for the site to work: your session, security, and the record of the cookie choice itself, which we keep for 182 days so we do not have to ask again. These cannot be switched off, and they are the only cookies present if you decline the rest.
Analytics
Helps us see how the site is used, so we can improve it. Loaded only after you accept analytics cookies.
Marketing
Used to measure whether an advertisement led to a request. If you accept marketing cookies, we store the click identifiers from the URL you arrived with for 30 days and attach them to a request you submit. Without that consent, nothing is stored and nothing is shared.

You can change or withdraw your choice at any time through the cookie preferences, reachable from the footer of every page. Withdrawing takes effect immediately.

International transfers

Client financial data is processed in EU regions: the database and storage, the application hosting, the worker machines, the key service, and the AI gateway are each pinned to an EU region.

Several of our sub-processors are companies established outside the EEA even though the processing itself happens inside it. For those relationships we rely on the European Commission's Standard Contractual Clauses, together with the technical measures described in our Security Measures. We can provide further detail on request.

Security

The full description is Annex C to our Data Processing Agreement. In short:

Changes to this policy

We may update this policy. Each version carries its own number and the date it came into force, and the previous versions stay listed at the foot of the page, so you can see that something changed and when. If a change is material we say so rather than relying on you to notice.