{"page-breadcrumb.c766e66518":"Breadcrumb","privacy-policy.bf18ff9b91":"Autoriteit Persoonsgegevens. Web: autoriteitpersoonsgegevens.nl. Privacy line: +31 88 1805 250 (Mon to Thu, 10:00 to 12:00). General: +31 70 888 8500 (weekdays, 09:00 to 13:00). Postal: Postbus 93374, 2509 AJ Den Haag.","privacy-policy.0112d1cc24":"Supervisory authority.","privacy-policy.604ca15584":"Contact us first at privacy@dweve.com. Dweve will acknowledge within 48 hours. Investigation completed within 30 days. Written response with resolution. Appeal process is available if you are unsatisfied.","privacy-policy.1024561d80":"Complaint process.","privacy-policy.afae2ddd06":"Privacy rights: privacy@dweve.com. Data breaches: security@dweve.com (24/7). GDPR compliance: compliance@dweve.com. Legal matters: legal@dweve.com. General support: support@dweve.com.","privacy-policy.0118c3254d":"Specialised contacts.","privacy-policy.67a913f7cb":"Dweve B.V., DPO. Email: dpo@dweve.com. Phone: +31 (0)85 0041 022. Postal: Dweve B.V., Meander 251, 6825 MC Arnhem, Netherlands. KVK: 98215043.","privacy-policy.de7d4b1d70":"Data Protection Officer.","privacy-policy.8c24a2168d":"Write to the Dweve Data Protection Officer. You also have the unconditional right to lodge a complaint with the Dutch supervisory authority, without contacting us first.","privacy-policy.3d9b989fc5":"Questions, rights requests, and complaints.","privacy-policy.0c41230448":"§ 14, Contact and DPO","privacy-policy.35e23af405":"Review changes before the effective date. Object to specific changes by contacting privacy@dweve.com. Export your data. Close your account without penalty before the change takes effect. Existing agreements may be grandfathered for their current term.","privacy-policy.59dec51f22":"Your options on update.","privacy-policy.d699c2a5d9":"Minor changes: dashboard notification. Material changes: email 30 days before the effective date. Critical changes (those that materially reduce your rights or protections): explicit re-consent required before the change takes effect.","privacy-policy.f65e2e2857":"Notification by significance.","privacy-policy.406f62066c":"This policy is updated when legal or regulatory requirements change, when new features or services are added, when security enhancements require revised disclosures, and on an annual review at minimum. Version history is always available online.","privacy-policy.1dcc7163c3":"How and when this policy changes.","privacy-policy.63959caf6a":"§ 13, Policy updates","privacy-policy.c19b2fb588":"Dweve does not knowingly collect data from, or direct marketing to, anyone under 18.","privacy-policy.2817923a3b":"No marketing to minors.","privacy-policy.124fd3a970":"Where an approved educational institution manages student accounts: the institution carries GDPR controller responsibilities for student data, data collection is limited to what the institution authorises, no behavioural profiling applies, and enhanced privacy controls are active.","privacy-policy.7f1f2cee67":"Educational exceptions.","privacy-policy.aa4459d215":"The account will be suspended immediately. A parent or guardian will be notified. Data will be deleted within 48 hours. No data will be retained or used for any processing purpose.","privacy-policy.14f322b786":"If Dweve discovers a minor&rsquo;s data.","privacy-policy.bd17d1911b":"Dweve services are designed for professional use by adults. The minimum age is 18 years. Business accounts require legal capacity to contract. Educational-institution accounts are managed by the institution under a separate addendum, with parental consent handled at institution level.","privacy-policy.0e1f86ccfb":"Services are for adults (18+).","privacy-policy.c9aa10aa4f":"§ 12, Children&apos;s privacy","privacy-policy.5c6213dcd6":"Dedicated support during the period following notification. Regular updates on the investigation and remediation. Transparent reporting on improvements made. Compensation per applicable law.","privacy-policy.5c6836ef6a":"Post-breach.","privacy-policy.b8e93684fc":"The nature of the breach and the categories of data affected. The likely consequences and risks to your rights. The measures taken or proposed to address the breach. Recommendations for protective actions you can take. Contact information for questions.","privacy-policy.0ee7449040":"What Dweve will tell you.","privacy-policy.6cd7ae8510":"Supervisory authority (AP): within 72 hours of detection where risk threshold is met (GDPR Art. 33). Affected data subjects: without undue delay where high risk to rights and freedoms is established (GDPR Art. 34). Partners: per contractual obligations.","privacy-policy.b812ca1e82":"Notification timeline.","privacy-policy.3cf90955e8":"24/7 automated security monitoring. Immediate incident response team activation on detection. Containment targeted within 4 hours. Forensic analysis and scope determination. Law enforcement cooperation where required.","privacy-policy.5482fc92c3":"Detection and response.","privacy-policy.d7e98ed6ce":"In the event of a personal data breach, Dweve follows documented procedures to contain the incident, notify the relevant authority, and, where required, inform affected data subjects. GDPR Article 33 requires notification to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals.","privacy-policy.98f1d26874":"What happens if something goes wrong.","privacy-policy.fe27953317":"§ 11, Data breach procedures","privacy-policy.45ec69e3ca":"Transparency in AI decision-making processes. Human oversight requirements for high-risk AI applications are documented and passed to deploying customers. Bias monitoring, fairness assessments, and regular AI impact assessments are part of the release process. Documentation of AI system capabilities and limitations is published with each Loom release.","privacy-policy.93c37e21fe":"EU AI Act compliance.","privacy-policy.c84baf72bc":"All processing occurs within European boundaries. Local processing options with post-quantum security are available for sovereign deployments.","privacy-policy.064e28bb51":"European data sovereignty.","privacy-policy.8cff9649a0":"Your data is processed by AI only when you explicitly put it into prompts, training, or fine-tuning. Automated systems remove personal data when service usage ends.","privacy-policy.6a280fc2b3":"Customer-controlled processing.","privacy-policy.ea52f4a7a0":"The platform learns mathematical patterns (binary constraints), not personal information. These constraints contain zero personal data; they are pure mathematical discoveries that improve AI efficiency.","privacy-policy.b7c4096757":"Binary Constraint Discovery.","privacy-policy.536d86f37c":"Dweve never uses your data to train its AI models. Your data is processed only when you explicitly instruct the system.","privacy-policy.6c6a00afcc":"No training on personal data.","privacy-policy.a2f1eb6ee2":"Dweve&rsquo;s AI architecture is designed so that privacy is structural, not procedural. The platform learns from mathematical constraints discovered during processing, not from your personal data.","privacy-policy.21c7814863":"Privacy-first AI architecture.","privacy-policy.fec0c107d1":"§ 10, AI-specific protections","privacy-policy.12f55f47d4":"24/7 security monitoring and incident response. Regular penetration testing and vulnerability assessments. Employee security training. EU compliance frameworks (GDPR, NIS2, DORA, CRA). Secure development lifecycle.","privacy-policy.a26635f2e7":"Operational security.","privacy-policy.0e563bc84d":"Automated personal data removal systems, multi-factor authentication, constraint separation, and continuous automated access reviews.","privacy-policy.5835a4461f":"Zero-trust architecture.","privacy-policy.e215e1199f":"Post-quantum cryptographic algorithms for future-proof security. TLS 1.3 with quantum-resistant ciphers for data in transit. Hardware security modules (HSM) with PQC support. All stored data uses post-quantum cryptographic protection.","privacy-policy.305870e088":"Quantum-safe encryption.","privacy-policy.51ef1bce79":"Encryption in transit with TLS 1.3 and forward secrecy. Encryption at rest with AES-256 and post-quantum-ready key hierarchies. Role-based access control, least-privilege service accounts, hardware-backed secret storage, and continuous audit logging. Quarterly penetration testing, continuous dependency scanning, and automated vulnerability management. For the full controls matrix, SSDLC, incident-response posture, and vulnerability-disclosure policy, see the dedicated security page.","privacy-policy.24f7ba436a":"Technical and organisational measures.","privacy-policy.f0b3c81834":"§ 09, Security measures","privacy-policy.0f67dfed04":"Manage preferences in Account Settings. Browser controls are always respected. Detailed cookie list available on request.","privacy-policy.7b78155814":"Cookie management.","privacy-policy.d54cc85520":"Persona, language, and view-mode selection so the site does not re-ask on every visit. Cleared when you sign out or reset preferences.","privacy-policy.325c8c90ca":"Preference.","privacy-policy.cfcafcae08":"No analytics cookie is set. Aggregate traffic and security statistics come from Cloudflare's edge service and are not used for advertising or cross-site profiling.","privacy-policy.f74d27d880":"Aggregate site statistics.","privacy-policy.fa3e871372":"Session authentication, CSRF tokens, load balancing, language and accessibility preferences. Not subject to consent under ePrivacy Art. 5(3).","privacy-policy.33f7ef9d57":"Essential.","privacy-policy.1c064fc3f5":"Dweve uses only the storage needed to keep sessions secure and remember choices you make on the site. No analytics cookies. No third-party advertising trackers. No cross-site fingerprinting. No Google Analytics or Plausible. No social-media pixels. No supercookies.","privacy-policy.e396cfce7b":"Three buckets. Two you control.","privacy-policy.e0e010150e":"§ 08, Cookies and consent","privacy-policy.fb46e097cf":"Email: privacy@dweve.com. Response SLA: 30 days, extendable by 60 if complex. Identity verification: proportionate, minimum data. Cost: free for reasonable requests. Withdraw consent: Account &rarr; Privacy &rarr; Consent. Appeal: AP (Autoriteit Persoonsgegevens).","privacy-policy.dff3ea13af":"How to exercise.","privacy-policy.e239f63556":"Object to processing based on legitimate interest. Unconditional opt-out from direct marketing, honoured on first request.","privacy-policy.8dc10592c6":"Art. 21, Objection.","privacy-policy.e955db6eba":"Export of your personal data in a structured, commonly used, machine-readable format. Direct controller-to-controller transfer where technically feasible.","privacy-policy.466a8b5242":"Art. 20, Portability.","privacy-policy.f6733b78a3":"Where you contest accuracy, processing is restricted pending verification, without terminating account access.","privacy-policy.1bc70faa25":"Art. 18, Restriction.","privacy-policy.0eabeb27b8":"&ldquo;Right to be forgotten.&rdquo; Cryptographic erasure from primary systems; backups purged within 90 days. Statutory-retention records (e.g. invoices) are held under legal obligation.","privacy-policy.474575670a":"Art. 17, Erasure.","privacy-policy.1cef32c1a4":"Correction of inaccurate data and completion of incomplete data. In most cases, self-service through the account dashboard.","privacy-policy.e2afc97bf5":"Art. 16, Rectification.","privacy-policy.490e101719":"A copy of the personal data Dweve holds about you, plus the purposes, categories, recipients, retention, and the source where it was not collected from you.","privacy-policy.a76df165cf":"Art. 15, Right of access.","privacy-policy.d7e9aa8b12":"As a data subject in the EU/EEA you have the rights set out in GDPR Articles 15 to 22. Dweve responds within one calendar month from the moment identity is verified. The request itself is free; manifestly unfounded or excessive repeat requests may be refused or charged.","privacy-policy.09d7a0768f":"GDPR rights, exercised directly.","privacy-policy.b96f71b753":"§ 07, Data subject rights","privacy-policy.73403e983e":"Default: all processing inside EU/EEA, no onward transfer to third countries without the safeguards below. Adequacy: transfers only to countries with a current EU Commission adequacy decision, subject to a Transfer Impact Assessment on file. SCC: where adequacy does not apply, EU Commission 2021 SCCs plus technical and organisational supplementary measures. Prohibited: no transfer to entities subject to CLOUD Act, FISA 702, or equivalent extraterritorial surveillance reach without additional safeguards that defeat that reach. No transfer to countries without adequacy decisions. No sharing with entities subject to foreign surveillance laws. No processing by non-EU sub-processors without guarantees.","privacy-policy.e2667d3019":"Disclosure regime.","privacy-policy.4d7998f16d":"Cloudflare provides edge delivery, security and aggregate request statistics. Mollie processes payments. Brevo delivers transactional email. Dweve does not use Google Analytics, Plausible or another client-side analytics service.","privacy-policy.784558dfe4":"Operational sub-processors.","privacy-policy.01ae621e75":"Primary data centres: Netherlands, Germany, France. Backup facilities: Ireland, Sweden. CDN/edge: EU-only PoPs. Compute fabric: Dweve Mesh, sovereign nodes.","privacy-policy.0f7fe30523":"Hosting &amp; infrastructure.","privacy-policy.cb0a99845b":"Dweve appoints sub-processors only where necessary to operate the service. Each sub-processor is bound by a GDPR Article 28 data-processing agreement. No third-country transfer occurs by default; where a European-only alternative is unavailable, EU Commission 2021 Standard Contractual Clauses plus a documented Transfer Impact Assessment apply.","privacy-policy.9d179f91e2":"Sub-processors, named and located.","privacy-policy.d332bce714":"§ 06, Sub-processors","privacy-policy.d3bb5e7cc5":"Scheduled purge","privacy-policy.8e23583f77":"Art. 6(1)(f) + 6(1)(c)","privacy-policy.f11254a8fe":"Up to 5 years","privacy-policy.0cfdf789c1":"Fraud investigation records","privacy-policy.61fc8339ac":"Statutory hold","privacy-policy.9ab4cfb1c6":"Art. 6(1)(c), legal obligation","privacy-policy.61dbc14a30":"Contract duration + 10 years","privacy-policy.5540eeaec6":"Signed agreements","privacy-policy.0836d5782e":"One-click unsubscribe","privacy-policy.62e302d529":"Art. 6(1)(a), consent","privacy-policy.6411f70515":"Until consent withdrawn","privacy-policy.9a277c1da5":"Marketing contacts","privacy-policy.81779675e5":"Key destruction","privacy-policy.8459f93535":"Operational","privacy-policy.4f5087a98f":"Deleted within 90 days of primary deletion","privacy-policy.530cc25bdc":"Backups","privacy-policy.df0ea17dfc":"WORM, then purge","privacy-policy.dba8c9ab37":"12 months (5 yr for incidents)","privacy-policy.27ec3d2e2e":"Security event logs","privacy-policy.24d977b438":"7 years (NL tax law)","privacy-policy.8f62577f3c":"Billing &amp; invoices","privacy-policy.09645cc539":"Art. 6(1)(b) + 6(1)(c)","privacy-policy.dc459d80b6":"Ticket lifetime + 12 months","privacy-policy.46b7e6e0e2":"Support tickets","privacy-policy.c8e24a4e38":"Automatic expiry","privacy-policy.d7a1384a38":"Art. 6(1)(b), contract","privacy-policy.0cdefb91e5":"24 hours unless saved by user","privacy-policy.fea0171395":"Model outputs","privacy-policy.5885bec9f4":"Rolling purge","privacy-policy.57db56eea6":"Art. 6(1)(f), legitimate interest","privacy-policy.7d4278a875":"30 days","privacy-policy.2b93b932c3":"API request logs","privacy-policy.0a4c8dd9d1":"90 days rolling","privacy-policy.7f16d77990":"Usage telemetry","privacy-policy.848932964a":"Cryptographic erasure","privacy-policy.0b2901df43":"Account lifetime + 30 days","privacy-policy.944c637649":"Account information","privacy-policy.bdfe37b1fa":"Deletion mechanism","privacy-policy.83d956f4d1":"Basis","privacy-policy.a441e09d1a":"Retention window","privacy-policy.a3c686e711":"Category","privacy-policy.211ff448ba":"Personal data is kept only as long as necessary for the purpose for which it was collected, or as required by law. Deletion is cryptographic; backups are purged within the documented window.","privacy-policy.1e81c744f2":"Retention schedule, per category.","privacy-policy.837b5fd897":"§ 05, Retention schedule","privacy-policy.8f57f5e513":"Detecting and preventing fraudulent activity, monitoring for security threats, ensuring compliance with terms of service, responding to legal requests and obligations, and protecting intellectual property rights.","privacy-policy.0c3359ffe8":"Security and compliance.","privacy-policy.e93b7c2308":"Binary constraints (mathematical rules and patterns) discovered during AI processing contain no personal data; they are pure mathematical discoveries that make AI more efficient. Platform performance patterns are analysed in aggregated, anonymised form to enhance reliability. No personal data is retained after processing for this purpose.","privacy-policy.cb3b95a244":"Technical advancement.","privacy-policy.a64136c85e":"Dweve never uses your personal data to train its AI models. Your data is processed only when you explicitly put it into the system for your own purposes. What our systems learn from is mathematical constraints discovered during processing, not your personal information.","privacy-policy.3ea48ade3e":"Privacy guarantee.","privacy-policy.9cc0b769ce":"Providing access to the Dweve platform and APIs; processing your AI workloads only when you explicitly instruct us (via prompts, training requests, or fine-tuning); temporarily storing data in encrypted form during active service usage; delivering technical support; managing your account and billing; sending service-related notifications.","privacy-policy.0a22ba7320":"Service delivery.","privacy-policy.bf8b22fb09":"Dweve does not sell, rent, or trade your personal data. Data is used for the purposes stated at collection and no others. Three purpose groups apply across the platform.","privacy-policy.f29f171945":"Purposes, with privacy guarantee.","privacy-policy.b892f37865":"§ 04, How we use your data","privacy-policy.da0cb14fa4":"Dweve operates models; the customer operates decisions. Human oversight requirements under EU AI Act Annex III rest with the deploying party, with Dweve providing the technical substrate and constraint trace.","privacy-policy.ea821787e7":"Art. 22, Automated decisioning.","privacy-policy.84bf842784":"Dweve does not knowingly accept GDPR Article 9 special-category data in Managed Fabric unless the applicable agreement and data-processing terms expressly permit it. Customers requiring direct control for such data use an appropriately scoped licensed deployment under their own controllership.","privacy-policy.67ca93b154":"Art. 9, Special categories.","privacy-policy.4117974c46":"Tax and invoicing records, EU AI Act transparency documentation, security-incident and breach reporting under GDPR Art. 33/34, court and law-enforcement orders valid under EU law.","privacy-policy.240491caf9":"Art. 6(1)(c), Legal obligation.","privacy-policy.b4b1253031":"Marketing emails, newsletter subscriptions, non-essential cookies, beta-programme participation. Explicit, granular, logged, and withdrawable without detriment.","privacy-policy.e160ff17bc":"Art. 6(1)(a), Consent.","privacy-policy.6523c9f762":"Security monitoring, fraud prevention, platform reliability, capacity planning, and product improvement on pseudonymised or aggregated data. Balancing test on file.","privacy-policy.2b3d965cdf":"Art. 6(1)(f), Legitimate interest.","privacy-policy.69ba3b6e2d":"Account provisioning, service delivery, technical support, billing, service-related notifications. Without these, the contract cannot be performed.","privacy-policy.00b08fd8a6":"Art. 6(1)(b), Contract performance.","privacy-policy.2758bd4b07":"Every processing activity has a named legal basis. Where processing rests on legitimate interest, a documented balancing test is on file and available to the supervisory authority on request. Where processing rests on consent, that consent is granular, freely given, and withdrawable in one click.","privacy-policy.bc1119fc70":"GDPR Article 6 grounds, per purpose.","privacy-policy.bfe18fa17d":"§ 03, Legal basis","privacy-policy.43b7a991bb":"Platform usage analytics, performance monitoring, security logging, and error tracking and diagnostics. All automatic collection is bounded to the six categories listed in § 01; no additional categories are added without a policy update and, where required, prior consent.","privacy-policy.68e5d8c54a":"Automatic collection.","privacy-policy.fd58649ff8":"Account registration forms, contact and support requests, voluntary surveys and feedback, platform configuration settings. You choose what you share; the minimum required for each purpose is documented in the data inventory above.","privacy-policy.d4706f28eb":"Direct collection.","privacy-policy.e5a93bf7ba":"Data reaches Dweve through two channels only: what you provide directly, and what the platform records automatically during operation. Nothing is purchased from data brokers or inferred from third-party sources.","privacy-policy.f6e5591444":"Collection methods, direct and automatic.","privacy-policy.2a0e50ee22":"§ 02, How we collect","privacy-policy.0b5acc4c8a":"IP address for security and localisation, browser and device metadata, network performance data, and security event logs. Rolling retention; older entries hashed or deleted on schedule.","privacy-policy.a2a7106840":"Category 06, Technical logs.","privacy-policy.2cebfe81af":"Session cookies for authentication and CSRF, plus local language, audience and accessibility preferences. Dweve sets no analytics or advertising cookies.","privacy-policy.7b6e8b565d":"Category 05, Cookies &amp; preferences.","privacy-policy.46f6a8c9db":"Invoices, VAT identifiers, bank details, payment-processor transaction IDs, credit notes. Required by Dutch and EU tax law; retained on a statutory seven-year schedule under encryption.","privacy-policy.d88870a7ae":"Category 04, Financial &amp; billing.","privacy-policy.aef60c826d":"Tickets, call recordings (opt-in, announced), chat transcripts, feedback, and voluntary survey responses. Retained for the lifetime of the ticket plus a short post-closure window.","privacy-policy.e894848930":"Category 03, Support interactions.","privacy-policy.c4f1040312":"Feature usage, API call volumes and latency, model performance metrics, session duration and frequency. Pseudonymised by account ID, aggregated for operations and capacity planning.","privacy-policy.5fae07b874":"Category 02, Usage telemetry.","privacy-policy.fe87940211":"Name, professional title, business email, company, industry, country, optional phone. Collected directly from the data subject via the registration flow. Required to provision, authenticate, and invoice.","privacy-policy.19beaf73a1":"Category 01, Account data.","privacy-policy.d2a51d87ad":"Dweve collects only the data required to operate the platform, invoice customers, meet statutory obligations, and keep the service safe. Six categories, listed below, make up the entire personal-data surface Dweve B.V. processes as controller. No biometrics. No location tracking. No social-media monitoring. No secondary training on your content.","privacy-policy.e9f30d07f8":"Data inventory, by category.","privacy-policy.63bdf5b9cb":"§ 01, Data inventory","privacy-policy.823d6e93b8":"25 September 2025","privacy-policy.9db108ba6b":"Privacy Policy","privacy-policy.902c91d94e":"Legal","privacy-policy.dcddde2796":"EU/EEA, Schrems II-aligned","privacy-policy.c10e83c453":"Data residency","privacy-policy.32bb202f4b":"Netherlands, EU/EEA only","privacy-policy.5d1cc3c5c6":"Jurisdiction","privacy-policy.9c8d6c91e1":"Autoriteit Persoonsgegevens","privacy-policy.77cfd8cc3b":"Supervisory authority","privacy-policy.ef51589ebc":"DPO","privacy-policy.14f6e6571c":"Dweve B.V., KVK 98215043","privacy-policy.a36a5ffa6e":"Controller","privacy-policy.2da600bf94":"Version","privacy-policy.153c9b2157":"Effective date","privacy-policy.583c9e2357":"Last updated","privacy-policy.a5b7d57a85":"GDPR","privacy-policy.de9b9b58ba":"CONTROLLER NOTICE","privacy-policy.e5c6425f52":"Contact the DPO","privacy-policy.0b050596d0":"See what we collect","privacy-policy.ef9dbf85ff":"What Dweve B.V. collects, under which Article 6 basis, from whom, for how long, and how you exercise your data-subject rights. A controller notice your DPO can map onto your own ROPA. Data stays inside the EU, with no third-country transfer without Standard Contractual Clauses on file.","privacy-policy.3dffa447dd":"GDPR by construction. Auditable by design.","privacy-policy.9dd3f4ee6f":"Trust, Privacy Policy","privacy-policy.8b1d3097fa":"GDPR by construction.","privacy-policy.810e89ecd1":"Auditable by design.","prv-hero-glyph.843362864a":"CONTROLLER","prv-hero-glyph.602beeacd9":"EU / EEA RESIDENCY","template_tpl_legal.7e439c353e":"On this page","template_tpl_legal.583c9e2357":"Last updated"}
