DATA & SECURITY

Data & Security

VAERG AB (STOCKHOLM, SWEDEN) · LAST UPDATED: AUGUST 10, 2026

01The short version

You upload confidential deal materials. We treat them accordingly: EU processing, engagement-level isolation, no model training on your content, and your uploaded documents deleted the moment your report is generated. Nothing you upload is stored after delivery. A Data Processing Agreement is in force from your first upload. This page describes exactly where your data goes and what happens to it.

02Where your data goes

  1. Upload. Your files are transmitted over TLS directly from your browser to VAERG's processing environment, hosted in the EU (Amsterdam, Netherlands). They are not routed through our website host.
  2. Extraction. Documents are converted to structured text and data using a commercial document-AI service under terms that prohibit any use of your content for model training.
  3. Analysis. The extracted content is analysed by a frontier AI model via a commercial API under the same no-training terms, in an isolated workspace created for your engagement only.
  4. Delivery. Your report is retrieved from your secure status page by download link.
  5. Deletion. Uploaded materials are automatically and permanently deleted when your report is generated; nothing you upload is stored after delivery. If a screening fails, uploads are kept only for troubleshooting, never longer than 30 days. Your report is archived for quality control and re-download, and deleted on request within 7 days.

The complete list of service providers, with locations and transfer safeguards for each, is published on our sub-processors page.

03What we never do

  • We never train AI models on your content, and our AI providers are contractually prohibited from doing so.
  • We never use one customer's materials in another customer's analysis. There is no shared index, memory, or knowledge base containing customer content.
  • We never claim rights to your materials or your reports. Your content remains yours; see our Terms of Service.
  • We never sell or share your data for advertising or any purpose unrelated to delivering the service.

04Security measures

  • Encryption: TLS 1.2+ in transit, encrypted storage at rest.
  • Isolation: One workspace per engagement, no cross-customer access paths.
  • Access control: Individually attributed credentials with multi-factor authentication; access to customer materials is limited to personnel with an operational need and is logged.
  • Monitoring: System-level logging of jobs, access and errors, without customer content in logs beyond what error diagnosis strictly requires.
  • Incident response: Documented procedure; affected customers are notified without undue delay and in any event within 48 hours of our becoming aware of a personal data breach.

05GDPR

For personal data contained in uploaded deal materials, you are the controller and VAERG is your processor. Our Data Processing Agreement, incorporating the requirements of Article 28 GDPR and EU Standard Contractual Clauses for transfers, is part of our Terms of Service, so it is in place from your first upload without separate paperwork. On request we provide the information needed for your transfer impact assessment.

06Data residency

Storage and orchestration are in the EU. AI inference currently runs on US-based provider infrastructure under Standard Contractual Clauses and strict no-training terms. For customers with hard EU-residency requirements, an EU-resident inference deployment of the same models is on our roadmap; contact us to discuss timing.

07Questions

Vendor due diligence questionnaire? Send it to contact@vaerg.com and we will complete it, typically within five business days.