Trasparenza, privacy e certezza del diritto.
Privacy Policy DealPiloot (Verne AI)
Version 4.3 • September 1, 2026 • Full GDPR & EU AI Act Compliance1. Identity and Contact Details of the Data Controller
This Privacy Statement applies to all processing of personal data by Verne AI, established in Utrecht, operating the product and trade name DealPiloot (Chamber of Commerce registration on request) (hereinafter: "DealPiloot", "Verne AI", "we" or "us").
For all inquiries regarding privacy, data protection, and the exercise of your rights, you can contact our Data Protection Officer (DPO / FG) directly at privacy@dealpiloot.nl.
2. Scope & Legal Role Allocation (GDPR Art. 4(7) and 4(8))
Under the General Data Protection Regulation (GDPR), DealPiloot distinguishes two separate processing roles:
a) DealPiloot as Data Controller: We independently determine the purposes and means for processing personal data of our website visitors, sales prospects, direct business contacts at partner advisory firms, billing, and account management.
b) DealPiloot as Data Processor: With respect to all client dossier data, financial statements, bank transactions, trade register data, and third-party personal data (end-client entrepreneurs) entered into the application by or on behalf of the advisory firm, the advisory firm acts as the Data Controller and DealPiloot acts solely as the Data Processor in accordance with Article 28 GDPR. Our standard Data Processing Agreement (DPA) applies in full.
3. Categories of Personal Data We Process
We only process personal data that is strictly necessary for operating the SaaS service and constructing administrative credit files:
• Advisor & User Information: Full name, professional email address, corporate telephone number, advisory firm name, Chamber of Commerce number, IP address, login timestamps, role privileges, and security audit logs.
• Financial Dossier Data (Processed on Behalf of Controller): Legal business name of the credit applicant, trade register number, historical financial statements, balance sheets, profit & loss accounts, cash flow patterns, indicative financing requests, collateral, and advisor notes.
• Voice Data (DealPiloot Light): Raw audio recordings of dictated intake conversations and the resulting structured draft text transcriptions.
4. Processing Purposes and Legal Bases (GDPR Art. 6(1))
Every processing of personal data relies on an explicit statutory legal basis under GDPR Article 6(1):
• Performance of a Contract (Art. 6(1)(b)): Providing portal access, transcribing speech recordings into intake reports (Light), generating credit files (CreditPack), and technical customer support.
• Compliance with Legal Obligations (Art. 6(1)(c)): Maintaining corporate records and complying with the 7-year statutory fiscal retention obligation under Dutch tax law (art. 52 AWR).
• Legitimate Interests (Art. 6(1)(f)): Ensuring network and information security, intrusion prevention, fraud mitigation, tenant isolation, and operational infrastructure monitoring.
• Consent (Art. 6(1)(a)): Strictly for optional analytical cookies managed via our Consent Manager.
5. Voice Data & Zero Model Training Guarantee
Our management of voice and financial data is anchored in privacy-by-design:
• Cryptographic Audio Purge: Voice recordings dictated via DealPiloot Light are used exclusively for real-time speech-to-text transcription. Within a maximum of 24 hours following transcription, the raw audio file is permanently and irrevocably purged from our servers.
• Zero Model Training Guarantee: No voice recording, transcription, financial document, or client information is ever used to train, fine-tune, or improve public, commercial, or generic third-party AI models. Our enterprise infrastructure agreements contractually and technically enforce zero data retention for training.
6. Explicit Prohibition of Citizen Service Numbers (BSN) & Automated Redaction
Under Article 46 of the Dutch GDPR Implementation Act (UAVG), processing Citizen Service Numbers (BSN) by commercial SaaS entities without specific statutory authority is strictly prohibited. DealPiloot provides SaaS software and has no legal mandate to process BSNs.
Strict Advisor Obligation: Users are expressly prohibited from entering, dictating, or uploading unredacted Citizen Service Numbers (BSN) into DealPiloot. As a technical defense-in-depth measure, DealPiloot applies automated heuristic pattern masking to sanitize any inadvertent BSN entries. DealPiloot accepts zero liability if a user inputs BSN data in violation of this prohibition.
7. Retention Periods & Data Retention Schedule
We never retain personal data longer than necessary for the intended processing purpose:
• Raw Voice Audio: Maximum 24 hours following transcription (automated deletion).
• Credit Dossiers & Analyses: Retained for the duration of the active subscription contract with the advisory firm, plus 30 days export window upon cancellation.
• Invoicing & Transaction Records: 7 years pursuant to statutory Dutch tax obligations.
• Session & Security Audit Logs: 90 days up to a maximum of 12 months, followed by automated log rotation.
8. Sub-processors & Strict EEA Data Residency
All application servers, databases, document storage, and backup repositories are physically hosted within the European Economic Area (EEA), specifically in tier-3 datacenters in the Amsterdam (Netherlands) and Frankfurt (Germany) regions. These datacenters maintain certified ISO 27001, ISO 27017, ISO 27018, and SOC 2 Type II compliance.
No data transfers take place to third countries outside the EEA without appropriate safeguards under GDPR Chapter V (such as EU Standard Contractual Clauses and Data Privacy Framework certifications).
9. No Automated Decision-Making & Profiling (GDPR Art. 22 & EU AI Act)
DealPiloot does not employ automated decision-making or profiling producing legal effects within the meaning of GDPR Article 22. The software does not autonomously approve, score, or reject credit applications.
DealPiloot operates strictly on a Human-in-the-Loop architecture under the European AI Act: the software generates draft indicative calculations (such as DSCR, EBITDA reconciliations) and structured text to assist professional human workflows. The licensed advisor and the credit risk underwriter at the financial institution remain 100% responsible for validating figures and making the final credit decision.
10. Data Subject Rights (GDPR Chapter III)
As a data subject, you hold the following statutory rights under the GDPR:
• Right of Access (Art. 15): Request verification of what personal data we hold about you.
• Right to Rectification (Art. 16): Correct inaccurate or incomplete records.
• Right to Erasure / Right to be Forgotten (Art. 17): Request deletion when processing grounds expire.
• Right to Restriction of Processing (Art. 18): Temporarily freeze processing.
• Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
• Right to Object (Art. 21): Object to processing founded upon legitimate interest.
Requests can be submitted via the online DSR portal below or by emailing privacy@dealpiloot.nl. Receipt is confirmed within 48 hours; statutory fulfillment occurs within 30 calendar days.
11. Technical and Organizational Security Measures (GDPR Art. 32)
DealPiloot maintains bank-grade security standards to prevent data loss and unauthorized disclosure:
• Encryption in transit via TLS 1.3 with Perfect Forward Secrecy;
• Encryption at rest utilizing AES-256 across all databases and file volumes;
• Logical tenant isolation ensuring partitioned cryptographic separation per advisory practice;
• Mandatory Multi-Factor Authentication (MFA / TOTP) for administrative console access;
• Continuous vulnerability monitoring and immutable security audit logging.
12. Supervisory Authority & Governing Law
If you believe DealPiloot is processing your personal data unlawfully, you have the right to lodge a complaint with the competent supervisory authority: Autoriteit Persoonsgegevens (AP), Postbus 93374, 2509 AJ The Hague, Netherlands (autoriteitpersoonsgegevens.nl).
This Privacy Statement is governed exclusively by Dutch law. The competent courts in the District of Central Netherlands (Utrecht), the Netherlands, hold exclusive jurisdiction.
Diritti GDPR / AVG: Richiesta Diritti dell'Interessato (DSR)
Desidera esercitare il Suo diritto di accesso, rettifica o cancellazione dei dati personali? Compili la seguente richiesta:
⚖️ La legge olandese prevale in ogni momento. In caso di discrepanze tra le traduzioni e l'originale olandese, prevarrà il testo in olandese.