How we handle your data
Data minimization, EU residency, and a controlled AI pipeline — by design, not as an afterthought.
Data minimization at extraction
Server-side extraction pulls only the supplier name and item description from each row. Pricing, quantities, buyer identity, and contact details are never forwarded to any AI model.
EU data residency by default
Uploaded files are stored on EU infrastructure. Under Tier A (EU-Only), AI processing is restricted to EU-pinned endpoints and non-EU sub-processors are blocked in code.
90-day automatic deletion
Files are deleted automatically after 90 days via a storage lifecycle policy, backed by an application-level purge job as a safety net.
Controlled AI routing
Non-EU models are unreachable unless both a server configuration flag and a verified per-request consent are present. Neither alone is sufficient.
Consent audit trail
Every Tier B engagement records the tier, model, the exact consent text accepted, and a timestamp — creating an auditable record.
File validation
Uploads are validated server-side: extension and size checks, a row-count limit, and rejection of macro-enabled workbooks (.xlsm) to reduce risk.
Questions about data handling?
We're happy to walk your security or compliance team through the pipeline.