You are the controller
You decide what is processed and why. SayFocus acts as a processor on your instructions.
Invoices carry bank details, salaries and customer names, so "where does this actually run?" is a fair first question. This page answers it in plain terms, including the parts that are not flattering.
processing happens on infrastructure in the European Union
you stay the controller; a DPA is available on request
we hold no certification and do not pretend otherwise
The short version: it stays in your systems, and passes through ours.
Documents arrive in your mailbox or channel and end up in your accounting system or CRM, with the original file attached to the record. We do not build a parallel document archive unless you specifically ask for one.
The pipeline that reads, validates and posts your documents runs on infrastructure located in the European Union.
Extracting fields from a scan means sending the document to an AI provider. We use business tiers where submitted content is not used to train models, and we name the provider and its terms during the audit so your DPO can check them.
No analytics on your document content, no sharing with third parties, no using your documents to improve anything we sell to someone else.
You decide what is processed and why. SayFocus acts as a processor on your instructions.
A data-processing agreement covering scope, sub-processors and deletion is available before the pilot starts.
The AI provider and hosting are named in the DPA; we tell you before any of them changes.
We keep only what is needed to trace a document through the pipeline, for a period fixed at the audit.
You can ask for processing records to be deleted at any time, and we confirm when it is done.
At the end of an engagement access is revoked and the rules and documentation stay with you.
A small studio has an advantage here: the list of people is short and nameable.
Access is granted to the people building your pipeline and nobody else. There is no shared support pool browsing client data.
We ask for a limited or test account first and only widen it when a step genuinely needs it. If your policy forbids a level of access, we design around it.
Exceptions are posted to a channel your team already uses. In practice we keep personal identity numbers and full client email addresses out of those messages — a review note should say what is wrong, not repeat the sensitive parts.
Every document that reaches your system carries its source file, so an auditor can see where a figure came from without asking us.
We hold no ISO certification, no SOC 2 report and no security seal. If your procurement requires one, tell us early — that is a reason to choose a certified platform, and we will say so rather than waste your time.
We do not promise an accuracy percentage before seeing your documents. Any number on this site comes from a project that produced it, and the pilot is where your own number is measured.
We do not claim the pipeline is unattended-safe on day one. Money-moving and customer-facing steps keep a human in the loop, and safety limits stop a run that looks wrong — in one project a reminder run halts by itself if it would send more than 40 letters or chase more than €20 000.
These come from projects that hit the problem, not from a checklist.
Every incoming file gets an identity and a lock, so a retry or a forwarded copy cannot post twice.
A document that does not add up is held for review instead of quietly entering the books.
Batch jobs stop and alert when volume or value crosses the agreed ceiling.
Anything that sends messages on your behalf can be paused by your team with one command.
Credentials live in the platform's secret store, never in code or in documents we exchange.
Rule and integration changes are announced before they run against live data.
Not by us, and not by the AI provider under the business terms we use, where submitted content is excluded from model training. We name the provider and link its terms during the audit so you can verify this rather than trust it.
The pipeline can, but reading documents means calling an AI provider, so a fully offline setup would need an on-premise model and a different cost conversation. Say so at the audit and we will scope it honestly.
You are. SayFocus processes documents on your instructions as a processor, under a data-processing agreement that names the sub-processors and the retention period.
We notify you without delay and with what we actually know — which data, which window, what we have done. As a processor our duty is to inform you promptly so you can meet your own notification obligations.
Yes, before the audit if you prefer. The audit involves looking at real documents, so it is a reasonable thing to want in place first.
Three working days, one stream mapped end to end. If a data question would block the project, better to find it now than after the pilot.
Get a free automation audit