Legal
Privacy statement
Version 1.6, in force from 16 August 2026. Processor: New Generation Company B.V. (trading as Agentancy). Controller: the accountancy firm (client).
This English text is a translation provided for convenience. The Dutch version is the legally binding one; in the event of any discrepancy, the Dutch text prevails. Use the NL/EN switch in the header to read the Dutch original.
1. Our EU data boundary
Agentancy hosts the core of the service in the EU and makes any deviating processing routes explicit. Specifically:
- Core hosting and the encrypted database are in the Netherlands, Amsterdam region (EU); document storage and queue remain within European regions.
- Document and text AI runs via Google Vertex AI in the fixed EU multi-region, via EUrouter with a selected upstream provider, or via OpenAI. For OpenAI we contract with OpenAI Ireland Ltd and transfers are safeguarded by the EU-US Data Privacy Framework plus EU Standard Contractual Clauses. On the EUrouter and OpenAI routes content may be retained for up to 30 days; training and data collection are switched off.
- Optional support voice uses Gemini Live worldwide and is started by the user per session. Google does not use paid service content to improve models, but may retain content for abuse detection for up to 55 days. Screen sharing also requires a separate choice in the browser.
- Our authentication layer is self-hosted within the EU. No US cloud for login. No Auth0/Clerk without an EU region.
- In the application we use only functional session cookies and no session recording. Marketing pixels are limited to the marketing website and load only after your consent via the cookie banner (see section 8).
2. Which personal data do we process?
In line with our DPIA (Data Protection Impact Assessment):
| Processing | Categories of personal data |
|---|---|
| Invoice OCR + AI extraction | Name, address, contact details of suppliers/customers on the invoice |
| Stored contact details + KvK lookup | Company name, KvK number, IBAN, VAT number |
| Audit trail | Who made which posting and when |
| Auth + sessions | Email, password hash, MFA secret, IP address (last login) |
| AI prompt cache | No directly identifying data, only hashes |
| Digital support | Text questions, browser captions and optionally live audio or shared screen content |
3. AI decision-making and transparency
We use AI for invoice recognition and for suggesting the general ledger and VAT code. Important:
- No automated decision-making with legal effect (art. 22 GDPR). The final posting is always checked by a human.
- Automatic posting is allowed only after explicit consent per administration + contact learning rule, and can always be undone by the user.
- For every posting the AI reasoning is visible in the audit trail: which prompt level, which model, which confidence scores.
4. Sub-processors
Our sub-processors are publicly listed in line with art. 28 GDPR. The full list:
| Sub-processor | Purpose | Region |
|---|---|---|
| Fly.io | Compute, worker, Postgres database, job queue (ids/metadata) | Amsterdam (EU) |
| Tigris | Object storage (invoice documents) | EU |
| Google Cloud / Vertex AI | Document and text AI | Fixed EU multi-region |
| EUrouter + selected upstream | Optional AI inference; provider retention of up to 30 days | EU route |
| OpenAI Ireland Ltd | Document and text AI; training off, provider retention of up to 30 days | EU contracting party; processing partly in the US under the EU-US Data Privacy Framework + SCCs |
| Google Gemini Live | Optional support voice and screen sharing | Worldwide, after a per-session choice |
| KVK (Dutch government) | Looking up company information | NL |
| Stripe | Subscription billing | Ireland (EU HQ) |
| Mailgun (Sinch) | Email inbound + outbound, including emailed documents | EU region |
| Google Workspace (SMTP relay + Calendar) | Alternative sending transport for system email; also the appointment planner, which records name, email address, company name, telephone number and comment as a calendar item | EU |
| Cloudflare (Turnstile) | Bot protection on the live demo of this website; receives the visitor's IP address | Global edge network |
| Google Analytics 4 + Tag Manager | Visit statistics on this marketing website; loads only after consent | EU endpoints |
| Better Auth (self-hosted) | Auth layer for login | Fly.io (EU) |
Changes of sub-processors are announced 30 days in advance by email. The client has the right to object within that period.
Deliberate limits
- In the application (app.agentancy.nl) we use functional session cookies and no measurement or advertising tag whatsoever: no Analytics, no Tag Manager, no session recording. Statistics and marketing tags run only on this marketing website, and only after you have given your consent for them.
- US-only hosted authentication (Clerk, Auth0 without an EU region)
- Unconfigured AI routes or silent provider fallback for tenant documents
On the marketing website (agentancy.nl) marketing pixels can be active after your explicit consent; see section 8 and the cookie statement. Without consent no advertising pixel loads at all. Two things do happen there without consent, both without anything being placed on or read from your device: the Google tag runs in consent mode and then sends a cookieless signal without identification, and we count the number of visits ourselves using a code that is made unusable every night. Your IP address is not retained in the process. Both are explained in the cookie statement (sections 2 and 3).
5. Access by Agentancy for support
Besides the sub-processors listed above, authorised Agentancy staff (system administration) can temporarily log in as your firm for support, administration and troubleshooting, to look along and, where needed, carry out actions. This happens under confidentiality, is limited to your firm, expires automatically, is visible through a banner, and is recorded in full (start/end, with user, time and IP address). The conditions and safeguards are set out in the Data Processing Agreement (DPA).
6. Retention periods
| Category | Period | Legal basis |
|---|---|---|
| Source documents (invoices, receipts) | 7 years (10 years for immovable property) | AWR art. 52 |
| Audit trail (posting actions) | 7 years | Same |
| User-action logs | 7 years | Burden of proof |
| T&C acceptance trail | 7 years | Burden of proof |
| Session cookies | 30 days sliding | Security |
| AI prompt cache (hashes only) | 90 days | Operations |
7. Your rights as a data subject
- Right of access: the client can download an export of all data relating to their administrations from the app.
- Rectification: editable in-app for contact details; source documents themselves remain immutable (only through an audit-trail correction).
- Erasure: on termination of the contract → a 90-day grace period, then redact-but-retain (PII pseudonymised, source documents kept for the statutory retention obligation).
- Data portability: export format (CSV/JSON) for contacts, prompt rules and postings.
8. Cookies
In the application we set only functional session cookies when you log in. These functional cookies do not require a separate consent banner.
On the marketing website (agentancy.nl) we ask for your consent via a cookie banner for Google Analytics 4 and marketing cookies from advertising platforms (Google, Meta, LinkedIn, TikTok). With those we measure website use and can show visitors relevant advertisements. Cookies are placed or read only after you agree; via "More details" you choose per category (statistics and marketing separately), refusing takes one click and the site then works fully. Exactly which cookies these are, their retention periods and how to withdraw your consent are set out in the cookie statement.
Without consent we only measure numbers, and that can be done without cookies: the Google tag then runs in consent mode (a cookieless signal without identification) and our own visit counter recognises a returning visit within one day through a code derived from your IP address and browser type, with a key that changes every night. Your IP address and browser type are not stored and the key is destroyed after two days, after which that code can no longer be traced back. Legal basis: legitimate interest (article 6(1)(f) GDPR) in understanding the traffic to our own website. You can object via info@agentancy.nl.
9. Contact
Questions about privacy? Send us an email at info@agentancy.nl. We reply within 5 working days.
This privacy statement (version 1.6) is in force from 16 August 2026. Please also read the full data processing agreement.