Menu

Menu

Close

Close

(Legal)

Security & DPA compliance

Privacy by design

Multiple layers of privacy, none of them dependent on trust alone

For healthcare, finance, government and SMBs, data protection isn't a preference, it's a hard requirement. That's why we stack protective layers: legal (DPA), an AI model that runs in the EU, data on our own servers in the Netherlands and Germany, and a pseudonymization layer that masks personal data before the AI ever sees it.

Raw dataPseudonymizingTo EU modelResponseRestored locally
Your side (local)
NameSanne de Vries
Emailsanne@korenbloem.nl
IBANNL91 ABNA 0417 1643 00
Credit card4929 1234 5678 9012
CompanyBakkerij De Korenbloem
Key (token ↔ value)stays on our server · never goes to the model
Privacy gateway
EU modelno data sent to the US
Prompt the model sees

Summarize the customer: [PERSON_1] ([EMAIL_1]), pays with [CREDITCARD_1], IBAN [IBAN_1], at Bakkerij De Korenbloem.

Response

[PERSON_1] is an active customer at Bakkerij De Korenbloem with an open order. Send a follow-up email to [EMAIL_1].

The model only ever works with tokens. The link between token ↔ real value happens only locally, after the response. That gives you usable AI without sensitive data ever leaving your environment.

01Legal

DPA & data processing agreement

A signed data processing agreement (GDPR) with every subprocessor. Clear agreements on purpose, retention period and security.

02Model

LLM hosted in the EU

Prompts and responses never leave the EU. No training on your data, no data sent to the US.

03Infrastructure

Data on our own servers (NL + Germany)

Hosted on our own Hetzner servers in the Netherlands and Germany. AES-256 at rest, TLS in transit.

04Data

Pseudonymization layer

PII is masked before it reaches the model, exactly as in the live Twenty CRM demo at /playground2.

Step by step

How the masking works, explained simply

1 · You ask your question2 · We mask the risk words3 · The model only sees tokens4 · We restore the names
You
Send Sanne de Vries a payment reminder for invoice #2025-014 to IBAN NL91 ABNA 0417 1643 00.
Send ↵
What you see
NameSanne de Vries
Emailsanne@korenbloem.nl
IBANNL91 ABNA 0417 1643 00
CompanyBakkerij De Korenbloem
What the model gets
Name[PERSON_1]
Email[EMAIL_1]
IBAN[IBAN_1]
CompanyBakkerij De Korenbloem
EU model answers the masked question

Payment reminder drafted for [PERSON_1], ready to send to [EMAIL_1].

Names restored locally · only you see the real data

We assess the risk per field

Every field in the Twenty CRM gets a risk class. That determines whether and how we mask it in the prompt sent to the AI model.

FieldRiskIn the LLM prompt
NameHighMasked → [PERSON_n]
Email addressHighMasked → [EMAIL_n]
Phone numberHighMasked → [PHONE_n]
AddressMediumMasked → [ADDRESS_n]
IBAN / account numberCriticalMasked → [IBAN_n]
Credit cardCriticalMasked → [CREDITCARD_n]
National ID (BSN)CriticalNever sent to the model
Notes / free textVariableScanned for PII, then masked
Company nameLowVisible to the model
Job titleLowVisible
CityLowVisible

Why we take privacy seriously

One data breach costs trust you can't buy back. Our clients work with customer, patient and payment data that is legally required to stay within the EU. By building privacy into the design (not bolting it on at the end), you can deploy AI without legal risk or reputational damage. No training on your data, no American cloud, no surprises.

Last updated: December 2024

1. Introduction

Imora AI Automatisering places great importance on the security of your data and on full compliance with the General Data Protection Regulation (GDPR) and Dutch laws and regulations. On this page we explain which technical and organisational measures we take and how we meet data protection requirements.

2. Technical security

We deploy the following technical measures to protect your data:

  • Encryption: data at rest and in transit is encrypted with industry-standard protocols (TLS 1.3, AES-256).
  • Access security: strict access policy, multi-factor authentication (MFA) where possible, and role-based access rights.
  • Infrastructure: hosting with reliable providers holding certifications (including ISO 27001, SOC 2), with data preferably kept within the EEA.
  • Monitoring and logging: continuous monitoring, logging of access and changes, and alerting on abnormal behaviour.
  • Backups: regular, encrypted backups with tested recovery procedures.
  • Security updates: timely application of patches and updates to all systems and dependencies.

3. Organisational security

Alongside technical measures, we maintain strict internal processes:

  • Policy and procedures: written security and privacy policy, instructions and regular training.
  • Access on a need-to-know basis: staff only get access to data required for their work.
  • Confidentiality: non-disclosure agreements and data-use agreements with staff and processors.
  • Incidents and data breaches: a procedure for reporting and handling (potential) data breaches, including notification to the Dutch Data Protection Authority (AP) and affected individuals where required.
  • Audits and reviews: periodic assessment of security measures and risks.

4. GDPR and DPA compliance

We comply with the GDPR and follow the guidelines of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP). In practice this includes:

  • Lawful basis: we only process personal data on the basis of a valid legal ground.
  • Purpose limitation and data minimisation: data is only collected and used for clearly defined, legitimate purposes and no more than necessary.
  • Retention periods: personal data is not retained for longer than necessary or than required by law.
  • Rights of data subjects: we support access, rectification, erasure, restriction, data portability and objection.
  • Data processing agreements: we enter into GDPR-compliant data processing agreements with every party that processes personal data on our behalf.
  • DPIA: where necessary, we carry out a data protection impact assessment before starting high-risk processing activities.

5. Subprocessors and third parties

We work with carefully selected subprocessors (such as hosting, email and AI providers). We have agreements with each of them covering security, confidentiality and GDPR compliance. We remain responsible for the processing and only choose parties that can demonstrate appropriate measures.

6. Data breaches and notifications

In the event of a (suspected) data breach, we follow our internal procedure: assessment, limiting the impact, documentation and, where the law requires it, notification to the Dutch Data Protection Authority within 72 hours. Affected individuals are informed when there is a high risk to their rights and freedoms. Every incident and the measures taken are documented.

7. Questions and contact

Do you have questions about our security or about how we handle GDPR and DPA compliance? Get in touch: Imora AI Automatisering, info.imora@gmail.com, www.imora.ai, Netherlands. For complaints about the processing of your personal data, you can also contact the Dutch Data Protection Authority.

8. Changes

We may update this page from time to time, for example when we introduce new measures or when legislation changes. The current version is always available on this page.

Questions about security or compliance? Get in touch.

Get in touch
Security and GDPR/DPA compliance | Imora AI