Privacy Policy
OntosCompile, operated by Ontos B.V.
Version 1.0 · In force since August 9, 2026
Two roles, and which one applies to you
OntosCompile processes personal data in two distinct roles, and which one applies decides what governs the processing and who you should address.
- We are the controller
- For the data we decide about ourselves: your account, the organisation you belong to, what you send us through the contact and demo forms, the feedback you file, and the technical logs and measurement described below. This policy governs that processing.
- We are the processor
- For the personal data inside the administrations, audit files, and reports a customer processes through OntosCompile. There the customer, usually an accountancy firm, is the controller and decides the purposes; we act on their documented instructions. That processing is governed by our Data Processing Agreement, not by the legal bases in this policy. If you are a person named in such a report and you want to exercise a right, address the organisation that prepared it. Write to us anyway if you cannot reach them, and we will pass the request on.
Data controller
Ontos B.V., operating OntosCompile, is the data controller responsible for the processing described in this policy. You can reach us at:
Data we collect
As controller, we collect the following categories of personal data:
Account and organisation data
- Your name and email address when you create an account.
- Authentication data: a hashed password, and the public key and device label of any passkey you enrol.
- The organisation you belong to, your role in it, and the invitations sent to or by you.
- The record that you accepted the terms, with the moment you did so, taken from our clock rather than your device.
Data you bring into the platform
- Financial administrations and XAF audit files, prior-year financial statements and filings, trial balances, and the draft and final reports produced from them. These may contain personal data of directors, signatories, accountants, and, where the administration holds it, employees and counterparties.
- The mapping documentation: which rule produced a mapping, how confident it was, who approved it, and when. Approval records name a person by design, because that is what makes them evidence.
For this category we are the processor, not the controller. See the section above.
What you send us
- Contact and demo requests: your name, work email address, organisation, and anything you write in the message, plus the consent choices you made on the form.
- Product feedback you file from inside the application, including any screenshot, element reference, or recording you attach to it.
Technical data
- Server and application logs, including the IP address the request came from, the browser characteristics, and the time.
- Error and performance telemetry, configured so that it carries no client financial data.
- Audit records of security-relevant actions, traceable to the authenticated user who performed them.
- Anti-abuse signals on the public forms, among them the IP address and browser characteristics, used to tell a person from a bot.
Why we process it, and on what basis
Each purpose below names the legal basis under Article 6 of the GDPR that we rely on.
- Providing and securing the platform
- Legal basis: performance of a contract (Art. 6(1)(b)). Running your account, keeping the service available, and protecting it against misuse.
- Administering organisations and access
- Legal basis: performance of a contract (Art. 6(1)(b)). Managing membership, roles, and invitations, so that the right colleagues reach the right work and nobody else does.
- Answering a message you send through the contact form
- Legal basis: consent (Art. 6(1)(a)). The contact form asks for it explicitly and the server refuses a submission without it, so the consent is a recorded fact rather than an assumption. You can withdraw it at any time, as easily as you gave it.
- Improving the product
- Legal basis: legitimate interest (Art. 6(1)(f)). Understanding how the platform is used and acting on the feedback you file, so that the next release is better than this one. We use aggregate and technical signals for this, not the contents of your clients' administrations.
- Preventing abuse of the public forms
- Legal basis: legitimate interest (Art. 6(1)(f)). Screening submissions so that a mailbox is not filled by automated traffic. The signals used are technical and are kept with the submission.
- Product news and marketing
- Legal basis: consent (Art. 6(1)(a)), opt-in only and switched off by default. Withdrawing it is as easy as giving it and costs you nothing else.
- Meeting our own legal obligations
- Legal basis: legal obligation (Art. 6(1)(c)). Administrative and tax records, and the security records we must be able to produce.
AI processing
The platform uses AI models to suggest mappings, classifications, and checks. What that means for your data:
- Requests are routed through a single gateway configured to call its EU endpoint, and our agreement with that gateway does not permit prompts or completions to be retained for model training.
- Each user or organisation gets its own key at the gateway, which makes use attributable, capped, and revocable, and keeps one customer's spending and usage separate from another's.
- We do not use your data, your clients' administrations, or the Output the platform produces to train our own models.
- An AI suggestion is never a decision. Every suggestion is presented for review and carries its origin, so a person decides and the record shows who.
How long we keep it
We keep data only as long as the purpose requires, the law obliges, or a secure recovery process needs:
- Account and organisation data: while your account is active. On deletion of the account or the end of the contract we erase it, and we aim to complete that within 30 days; you can ask us to do it sooner and we will. Limited backup and recovery windows apply, after which the copies expire too.
- The administrations, audit files, and reports you process: for the term of the agreement, and on termination as Clause 11 of the Data Processing Agreement provides, which is deletion or return at the customer's choice.
- Contact and demo requests: at most 24 months from the request, unless it becomes part of a customer relationship, in which case it follows that relationship. Erasure runs against that boundary and on request, whichever comes first.
- Feedback and its attachments: kept while the issue it reports is open and for as long as the fix has to be traceable. Attachments have their own erasure path, so removing a report removes what was attached to it.
- Technical and audit logs: kept for a period appropriate to detect and investigate incidents and to demonstrate compliance, and no longer.
Your rights
Under the GDPR you have the following rights over your personal data. Where we act as processor for a customer, address the customer first, as explained at the top of this policy.
- Access
- Ask for a copy of the personal data we hold about you.
- Rectification
- Ask us to correct data that is inaccurate or incomplete.
- Erasure
- Ask us to delete your personal data, where no legal obligation requires us to keep it.
- Portability
- Receive the data you gave us in a structured, machine-readable format.
- Objection
- Object to processing we base on a legitimate interest, and we will stop unless we can show compelling grounds that override yours.
- Restriction
- Ask us to limit the processing while a dispute about accuracy or lawfulness is resolved.
- Withdrawal of consent
- Withdraw consent at any time where the processing is based on it. Withdrawal does not affect what was lawful before it.
To exercise a right, write to us at the address at the foot of this page. We answer within one month, and tell you if we need longer and why.
You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, if you believe your rights have been infringed.
International transfers
Client financial data is processed in EU regions: the database and storage, the application hosting, the worker machines, the key service, and the AI gateway are each pinned to an EU region.
Several of our sub-processors are companies established outside the EEA even though the processing itself happens inside it. For those relationships we rely on the European Commission's Standard Contractual Clauses, together with the technical measures described in our Security Measures. We can provide further detail on request.
Security
The full description is Annex C to our Data Processing Agreement. In short:
- All data in transit is encrypted with TLS 1.2 or higher.
- All data at rest is encrypted. On top of that, designated sensitive fields are encrypted a second time at the application layer with a key from a separate EU key service, so a copy of the database alone does not yield them. That second layer covers the fields designated so far and grows as the compilation pipeline is released.
- Every table enforces row-level security, and route authorisation enforces the same boundary again in the application.
- Access by our own personnel is role-based and least-privilege, and security-relevant actions are written to an append-only audit log.
- We are notified of vulnerable dependencies, scan for committed secrets on every change, and produce a bill of materials for every proposed and released change.
Changes to this policy
We may update this policy. Each version carries its own number and the date it came into force, and the previous versions stay listed at the foot of the page, so you can see that something changed and when. If a change is material we say so rather than relying on you to notice.
This policy is published in English and in Dutch. Both versions describe the same practices.
Contact
For any question about this policy or about how we handle personal data, write to us. A request about your rights reaches the right person at the same address.
- Legal entity:
- Ontos B.V.
- Address:
- Middelburg, the Netherlands
- CoC:
- 42011303
- VAT:
- NL869277571B01
- Email:
- contact@ontoscompile.com
Version history
Every published version of this document, newest first. The text of a published version is fixed: a change to the wording is published as a new version with its own date.
- Version 1.0 ·