Home › Security & data
Security & data

Where your documents go, and what we do not keep

Invoices carry bank details, salaries and customer names, so "where does this actually run?" is a fair first question. This page answers it in plain terms, including the parts that are not flattering.

EU

processing happens on infrastructure in the European Union

Processor

you stay the controller; a DPA is available on request

No ISO

we hold no certification and do not pretend otherwise

Where the data is

The short version: it stays in your systems, and passes through ours.

Your systems remain the home

Documents arrive in your mailbox or channel and end up in your accounting system or CRM, with the original file attached to the record. We do not build a parallel document archive unless you specifically ask for one.

Processing runs in the EU

The pipeline that reads, validates and posts your documents runs on infrastructure located in the European Union.

Reading is done by an AI provider

Extracting fields from a scan means sending the document to an AI provider. We use business tiers where submitted content is not used to train models, and we name the provider and its terms during the audit so your DPO can check them.

Nothing goes anywhere else

No analytics on your document content, no sharing with third parties, no using your documents to improve anything we sell to someone else.

Roles, agreements and retention

You are the controller

You decide what is processed and why. SayFocus acts as a processor on your instructions.

DPA on request

A data-processing agreement covering scope, sub-processors and deletion is available before the pilot starts.

Sub-processors listed

The AI provider and hosting are named in the DPA; we tell you before any of them changes.

Retention agreed in writing

We keep only what is needed to trace a document through the pipeline, for a period fixed at the audit.

Deletion on request

You can ask for processing records to be deleted at any time, and we confirm when it is done.

Exit is clean

At the end of an engagement access is revoked and the rules and documentation stay with you.

Who can see your documents

A small studio has an advantage here: the list of people is short and nameable.

Named people, per project

Access is granted to the people building your pipeline and nobody else. There is no shared support pool browsing client data.

Least access that works

We ask for a limited or test account first and only widen it when a step genuinely needs it. If your policy forbids a level of access, we design around it.

Review queues are careful

Exceptions are posted to a channel your team already uses. In practice we keep personal identity numbers and full client email addresses out of those messages — a review note should say what is wrong, not repeat the sensitive parts.

Actions are traceable

Every document that reaches your system carries its source file, so an auditor can see where a figure came from without asking us.

What we do not claim

We hold no ISO certification, no SOC 2 report and no security seal. If your procurement requires one, tell us early — that is a reason to choose a certified platform, and we will say so rather than waste your time.

We do not promise an accuracy percentage before seeing your documents. Any number on this site comes from a project that produced it, and the pilot is where your own number is measured.

We do not claim the pipeline is unattended-safe on day one. Money-moving and customer-facing steps keep a human in the loop, and safety limits stop a run that looks wrong — in one project a reminder run halts by itself if it would send more than 40 letters or chase more than €20 000.

Practical safeguards we build in

These come from projects that hit the problem, not from a checklist.

Duplicate protection

Every incoming file gets an identity and a lock, so a retry or a forwarded copy cannot post twice.

Validation before posting

A document that does not add up is held for review instead of quietly entering the books.

Run limits

Batch jobs stop and alert when volume or value crosses the agreed ceiling.

Pause switch

Anything that sends messages on your behalf can be paused by your team with one command.

No secrets in the repo

Credentials live in the platform's secret store, never in code or in documents we exchange.

Change notice

Rule and integration changes are announced before they run against live data.

Frequently asked questions

Are our invoices used to train an AI model?

Not by us, and not by the AI provider under the business terms we use, where submitted content is excluded from model training. We name the provider and link its terms during the audit so you can verify this rather than trust it.

Can everything run on our own servers?

The pipeline can, but reading documents means calling an AI provider, so a fully offline setup would need an on-premise model and a different cost conversation. Say so at the audit and we will scope it honestly.

Who is the data controller?

You are. SayFocus processes documents on your instructions as a processor, under a data-processing agreement that names the sub-processors and the retention period.

What happens if there is a breach?

We notify you without delay and with what we actually know — which data, which window, what we have done. As a processor our duty is to inform you promptly so you can meet your own notification obligations.

Do you sign NDAs?

Yes, before the audit if you prefer. The audit involves looking at real documents, so it is a reasonable thing to want in place first.

Bring your security questions to the audit

Three working days, one stream mapped end to end. If a data question would block the project, better to find it now than after the pilot.

Get a free automation audit