Data & Security
01The short version
02Where your data goes
- Upload. Your files are transmitted over TLS directly from your browser to VAERG's processing environment, hosted in the EU (Amsterdam, Netherlands). They are not routed through our website host.
- Extraction. Documents are converted to structured text and data using a commercial document-AI service under terms that prohibit any use of your content for model training.
- Analysis. The extracted content is analysed by a frontier AI model via a commercial API under the same no-training terms, in an isolated workspace created for your engagement only.
- Delivery. Your report is retrieved from your secure status page by download link.
- Deletion. Uploaded materials are automatically and permanently deleted when your report is generated; nothing you upload is stored after delivery. If a screening fails, uploads are kept only for troubleshooting, never longer than 30 days. Your report is archived for quality control and re-download, and deleted on request within 7 days.
The complete list of service providers, with locations and transfer safeguards for each, is published on our sub-processors page.
03What we never do
- We never train AI models on your content, and our AI providers are contractually prohibited from doing so.
- We never use one customer's materials in another customer's analysis. There is no shared index, memory, or knowledge base containing customer content.
- We never claim rights to your materials or your reports. Your content remains yours; see our Terms of Service.
- We never sell or share your data for advertising or any purpose unrelated to delivering the service.
04Security measures
- Encryption: TLS 1.2+ in transit, encrypted storage at rest.
- Isolation: One workspace per engagement, no cross-customer access paths.
- Access control: Individually attributed credentials with multi-factor authentication; access to customer materials is limited to personnel with an operational need and is logged.
- Monitoring: System-level logging of jobs, access and errors, without customer content in logs beyond what error diagnosis strictly requires.
- Incident response: Documented procedure; affected customers are notified without undue delay and in any event within 48 hours of our becoming aware of a personal data breach.
05GDPR
For personal data contained in uploaded deal materials, you are the controller and VAERG is your processor. Our Data Processing Agreement, incorporating the requirements of Article 28 GDPR and EU Standard Contractual Clauses for transfers, is part of our Terms of Service, so it is in place from your first upload without separate paperwork. On request we provide the information needed for your transfer impact assessment.
06Data residency
Storage and orchestration are in the EU. AI inference currently runs on US-based provider infrastructure under Standard Contractual Clauses and strict no-training terms. For customers with hard EU-residency requirements, an EU-resident inference deployment of the same models is on our roadmap; contact us to discuss timing.
07Questions
Vendor due diligence questionnaire? Send it to contact@vaerg.com and we will complete it, typically within five business days.