ShareSafe.aipart of
VaultLM

VaultLM — Privacy, Security & Verwerkersdocumentatie / Privacy, Security & Data Processing Documentation

Version / Versie: June / Juni 2026
VaultLM is a trademark of El Niño B.V.
VaultLM is een handelsmerk van El Niño B.V.


Nederlandse versie

Document 1 — Privacyverklaring VaultLM

Van toepassing op het gebruik van de website, de accountvrije anonimiseringsfunctionaliteit, het VaultLM-platform, betaalde abonnementen, team- en organisatieomgevingen, support, commerciële communicatie en veilig geanonimiseerd delen.

Artikel 1 — Wie wij zijn

1.1 VaultLM is een dienst van El Niño B.V., gevestigd te Enschede, kantoorhoudende aan Kuipersdijk 6c, 7512 CH Enschede en ingeschreven bij de Kamer van Koophandel onder nummer 08140115.

1.2 In deze privacyverklaring wordt El Niño B.V. aangeduid als “VaultLM”, “wij” of “ons”.

1.3 Voor vragen over privacy kun je contact opnemen via hi@sharesafe.ai. Voor supportvragen kun je contact opnemen via hi@sharesafe.ai.

1.4 VaultLM is een handelsmerk van El Niño B.V.

Artikel 2 — Wat VaultLM doet

2.1 VaultLM biedt een privacygerichte technische tussenlaag tussen vertrouwelijke documenten en AI-taalmodellen.

2.2 Het platform is ontworpen om gevoelige informatie in documenten te herkennen en te maskeren voordat relevante passages aan een AI-model worden aangeboden, antwoorden te koppelen aan bronverwijzingen en veilig geanonimiseerd delen mogelijk te maken.

2.3 VaultLM is geen AI-model, geen algemene cloudopslagdienst en geen professionele adviesdienst. AI-output kan fouten bevatten en moet door de gebruiker worden gecontroleerd.

Artikel 3 — Rollen onder privacywetgeving

3.1 Voor persoonsgegevens die VaultLM verwerkt voor het aanmaken en beheren van accounts, facturatie, klantcommunicatie, beveiliging, productverbetering, websiteanalyse en commerciële communicatie, treedt VaultLM in beginsel op als verwerkingsverantwoordelijke.

3.2 Voor documenten, documentinhoud, tokenkaarten, vragen, antwoorden, werkruimtes, vaultomgevingen en gedeelde geanonimiseerde bestanden die een klant in het platform verwerkt, treedt VaultLM in beginsel op als verwerker namens de klant, tenzij uitdrukkelijk anders is overeengekomen.

3.3 De klant blijft verwerkingsverantwoordelijke voor de rechtmatigheid van de documenten, persoonsgegevens en overige gegevens die hij of zij uploadt, verwerkt, deelt of laat verwerken via VaultLM.

3.4 Wanneer een organisatie VaultLM via API, B2B-integratie, white-label, embedded workflow of eigen product gebruikt, is die organisatie verantwoordelijk voor de informatievoorziening aan haar eigen eindgebruikers, de keuze van verwerkingsgrondslagen, de inrichting van rechten, de configuratie van maskerparameters en de beoordeling van de output.

Artikel 4 — Welke gegevens wij verwerken

4.1 Afhankelijk van het gebruik kunnen wij de volgende categorieën gegevens verwerken:

  • accountgegevens, zoals naam, e-mailadres, organisatie, rol, taalvoorkeur en authenticatiegegevens;
  • abonnements- en facturatiegegevens, zoals plan, seats, factuuradres, btw-nummer, betaalstatus en betaalhistorie;
  • gebruiksgegevens, zoals aantal documenten, aantal vragen, aantal maskeringen, aantal tokens, aantal deelacties, workspace-activiteit en activatiestatus;
  • technische gegevens, zoals IP-adres, browser, apparaat, sessiegegevens, logs, foutmeldingen, security-events en API-gebruik;
  • support- en communicatiegegevens, zoals berichten aan support, feedback, demo-aanvragen en commerciële voorkeuren;
  • documentgegevens die door gebruikers worden geüpload of verwerkt;
  • afgeleide objecten, zoals gemaskeerde tekst, tokenkaarten, retrievalindexen, bronverwijzingen, geanonimiseerde deelversies en auditlogs.

4.2 VaultLM gebruikt documentinhoud, vragen, antwoorden en tokenkaarten niet voor algemene marketingprofielen en verkoopt deze gegevens niet aan derden.

Artikel 5 — Documentinhoud, AI-verwerking en modelproviders

5.1 VaultLM is ontworpen volgens het principe: eerst afschermen, dan AI gebruiken. Relevante context wordt waar mogelijk geminimaliseerd en gemaskeerd voordat deze naar een AI-model wordt gestuurd.

5.2 De tokenkaart die gemaskeerde tokens koppelt aan oorspronkelijke waarden blijft binnen de beveiligde VaultLM-omgeving en wordt niet meegestuurd naar AI-modelproviders of gedeelde bestanden, tenzij de gebruiker of organisatie daarvoor uitdrukkelijk een geautoriseerde route heeft ingesteld.

5.3 VaultLM gebruikt de inhoud van geüploade documenten, vragen, antwoorden en tokenkaarten niet om eigen AI-modellen te trainen of te verfijnen.

5.4 Voor zover VaultLM gebruikmaakt van externe modelproviders, worden die providers contractueel of technisch zo gekozen en geconfigureerd dat klantdata niet wordt gebruikt voor training van algemene modellen, voor zover de betreffende provider en modelroute dat ondersteunen.

5.5 Wanneer een klant eigen API keys of een eigen modelroute gebruikt, is de klant zelf verantwoordelijk voor de voorwaarden, dataverwerking, kosten, bewaartermijnen, trainingsinstellingen, beveiligingsmaatregelen en policy van de betreffende provider. In dat geval gelden de voorwaarden en privacy- en securitydocumentatie van die provider voor de modelroute.

Artikel 6 — Doeleinden en grondslagen

6.1 Wij verwerken persoonsgegevens voor de volgende doeleinden:

  • het aanmaken en beheren van accounts;
  • het leveren, beveiligen, onderhouden en verbeteren van het platform;
  • het uitvoeren van abonnementen, betalingen, facturatie en support;
  • het verwerken van documenten, maskeringen, vragen, antwoorden, bronverwijzingen en deelacties;
  • het bewaken van fair use, tokengebruik, misbruik, fraude en beveiligingsrisico’s;
  • het voldoen aan wettelijke verplichtingen;
  • het verzenden van transactionele e-mails, serviceberichten en, indien toegestaan, product- of marketingcommunicatie;
  • het uitvoeren van analytics op geaggregeerd of geminimaliseerd niveau.

6.2 Afhankelijk van de context baseren wij de verwerking op uitvoering van een overeenkomst, gerechtvaardigd belang, toestemming, wettelijke verplichting of, waar wij als verwerker optreden, de instructie van de klant als verwerkingsverantwoordelijke.

Artikel 7 — Accountvrije anonimiseringsfunctionaliteit

7.1 Bij gebruik van accountvrije anonimiseringsfunctionaliteit verwerkt VaultLM het geüploade document tijdelijk om gevoelige informatie te herkennen, te maskeren en een afgeleide versie beschikbaar te maken.

7.2 Accountvrije verwerking is bedoeld als een beperkte, eenmalige productervaring. Tenzij anders vermeld, worden documenten uit accountvrije sessies niet langdurig opgeslagen en niet gebruikt voor modeltraining.

7.3 Om misbruik, fraude, excessief gebruik of beveiligingsincidenten te voorkomen, kan VaultLM technische metadata, limieten en logs verwerken.

7.4 Wanneer de gebruiker ervoor kiest de output per e-mail te ontvangen of een account aan te maken, verwerken wij het e-mailadres en de bijbehorende metadata voor dat doel.

Artikel 8 — Veilig geanonimiseerd delen

8.1 Gebruikers kunnen via VaultLM geanonimiseerde of gemaskeerde versies van documenten, analyses of antwoorden delen met derden.

8.2 De afzender is verantwoordelijk voor de keuze om te delen, de ontvangers, de rechten, de looptijd, het downloadbeleid en de controle van de maskeeroutput vóór verzending.

8.3 Ontvangers kunnen technische metadata achterlaten, zoals openingsmoment, IP-adres, apparaat, klikgedrag en eventueel e-mailadres wanneer zij dat invullen. Deze gegevens worden gebruikt voor beveiliging, audit, toegang, misbruikpreventie en, indien toegestaan, conversie naar eigen gebruik.

8.4 Geanonimiseerd delen is geen garantie dat de gedeelde informatie in juridische zin volledig anoniem is. Indirecte identificatie kan mogelijk blijven, afhankelijk van context en combinatie van gegevens.

Artikel 9 — Cookies, analytics en tracking

9.1 VaultLM kan functionele cookies of vergelijkbare technieken gebruiken voor login, beveiliging, taalvoorkeuren en sessiebeheer.

9.2 Voor analytics en productverbetering gebruiken wij bij voorkeur privacyvriendelijke, geaggregeerde of gepseudonimiseerde gegevens.

9.3 Voor marketingcookies of vergelijkbare trackingtechnieken vragen wij toestemming wanneer dat wettelijk vereist is.

Artikel 10 — Bewaartermijnen

10.1 Wij bewaren persoonsgegevens niet langer dan noodzakelijk voor het doel waarvoor zij zijn verzameld, tenzij een langere bewaartermijn wettelijk verplicht is of noodzakelijk is voor geschillen, beveiliging of naleving.

10.2 Account- en facturatiegegevens worden bewaard zolang het account actief is en daarna zolang nodig is voor wettelijke administratie, contractuele verplichtingen en geschilbeslechting.

10.3 Documenten in de Vault blijven bewaard zolang het account of de organisatie actief is of zolang de ingestelde bewaartermijn loopt.

10.4 Na beëindiging van een account worden documenten in productiesystemen verwijderd binnen de termijn die in de overeenkomst of productdocumentatie is vermeld. Back-ups worden verwijderd of overschreven binnen 35 dagen, tenzij een andere termijn is overeengekomen.

10.5 Auditlogs en securitylogs worden bewaard gedurende 30 dagen, tenzij een langere termijn nodig is voor beveiliging, compliance, fraudeonderzoek of wettelijke verplichtingen.

Artikel 11 — Subverwerkers en derden

11.1 VaultLM kan gebruikmaken van subverwerkers en dienstverleners voor hosting, beveiliging, e-mail, betalingen, support, analytics, logging, modelrouting en andere technische onderdelen van de dienst.

11.2 Een actuele lijst van subverwerkers is beschikbaar via sharesafe.ai/subprocessors of op verzoek via hi@sharesafe.ai.

11.3 Wij sluiten passende contractuele afspraken met subverwerkers, waaronder waar nodig verwerkersovereenkomsten, beveiligingsverplichtingen en afspraken over internationale doorgifte.

11.4 VaultLM verkoopt persoonsgegevens of documentinhoud niet aan derden.

Artikel 11a — Browseridentifier en eigen gebruiksmeting

11a.1 Wij plaatsen één willekeurige identifier in uw browser om uw eigen sessies te koppelen, ook wanneer u later een account aanmaakt. Deze identifier bevat niets over u of uw documenten en u kunt hem zelf verwijderen via uw browserinstellingen.

11a.2 Wij gebruiken geen third-party analytics. Gebruiksgegevens (welke stappen van de tool zijn gebruikt, documenttype-categorie, taal en aantallen gedetecteerde gegevens, nooit inhoud, waarden of bestandsnamen) verwerken wij op onze eigen infrastructuur binnen de EU.

Artikel 12 — Internationale doorgifte

12.1 VaultLM streeft naar EU-first verwerking en hosting waar dat redelijkerwijs mogelijk en passend is.

12.2 Wanneer persoonsgegevens buiten de Europese Economische Ruimte worden verwerkt, zorgen wij voor passende waarborgen, zoals standaardcontractbepalingen, aanvullende maatregelen of een adequaatheidsbesluit, voor zover wettelijk vereist.

12.3 Wanneer een klant eigen API keys of eigen modelproviders gebruikt, is de klant verantwoordelijk voor de keuze van regio, doorgifte, contractuele waarborgen en instellingen van die provider.

Artikel 13 — Beveiliging

13.1 VaultLM neemt passende technische en organisatorische maatregelen om persoonsgegevens en documentgegevens te beveiligen tegen verlies, misbruik, onbevoegde toegang, wijziging en ongeoorloofde openbaarmaking.

13.2 Deze maatregelen omvatten onder meer encryptie, toegangscontrole, logging, autorisatie per workspace, gescheiden omgevingen, beveiligde verbindingen, monitoring, back-ups en incidentprocedures.

13.3 Verdere details staan in Document 2 — Securitydocumentatie.

Artikel 14 — Rechten van betrokkenen

14.1 Betrokkenen hebben, afhankelijk van de omstandigheden, rechten op inzage, correctie, verwijdering, beperking, bezwaar, dataportabiliteit en intrekking van toestemming.

14.2 Wanneer VaultLM als verwerkingsverantwoordelijke optreedt, kun je verzoeken indienen via hi@sharesafe.ai.

14.3 Wanneer VaultLM als verwerker optreedt voor een klant, zal VaultLM verzoeken van betrokkenen in beginsel doorverwijzen naar de klant of de klant ondersteunen bij de afhandeling, voor zover wettelijk vereist en contractueel overeengekomen.

Artikel 15 — Datalekken en incidenten

15.1 Wanneer VaultLM een beveiligingsincident vaststelt dat persoonsgegevens betreft, onderzoeken wij het incident en nemen wij passende maatregelen.

15.2 Wanneer VaultLM als verwerker optreedt en er sprake is van een datalek dat relevant is voor de klant, informeren wij de klant zonder onredelijke vertraging conform de verwerkersovereenkomst.

15.3 De klant blijft verantwoordelijk voor eventuele meldingen aan toezichthouders en betrokkenen wanneer VaultLM als verwerker optreedt, tenzij anders overeengekomen of wettelijk vereist.

Artikel 16 — Wijzigingen

16.1 VaultLM kan deze privacyverklaring aanpassen. Bij wezenlijke wijzigingen informeren wij gebruikers via de website, het platform of per e-mail.

16.2 De meest recente versie is steeds van toepassing vanaf de vermelde ingangsdatum.


Document 2 — Securitydocumentatie VaultLM

Deze securitydocumentatie beschrijft de belangrijkste technische en organisatorische maatregelen van VaultLM. Zij is bedoeld als transparant overzicht voor eindgebruikers, teams, organisaties, security reviewers en B2B/API-klanten.

Artikel 1 — Security-principes

1.1 VaultLM is gebouwd rond het principe dat vertrouwelijke documenten niet onnodig aan AI-modellen of derden mogen worden blootgesteld.

1.2 De kernprincipes zijn:

  • eerst afschermen, dan AI gebruiken;
  • minimale context naar het model;
  • tokenkaarten blijven binnen de beveiligde omgeving;
  • gebruikers kunnen alleen ophalen wat zij mogen openen;
  • antwoorden moeten controleerbaar zijn via bronnen;
  • deelacties moeten begrensd, traceerbaar en intrekbaar zijn;
  • misbruik, fraude en excessief gebruik moeten detecteerbaar zijn.

Artikel 2 — Hosting en infrastructuur

2.1 VaultLM wordt gehost bij Hetzner Online GmbH in Duitsland (EU), tenzij anders overeengekomen voor specifieke organisatie- of self-hosted omgevingen.

2.2 Productieomgevingen zijn logisch gescheiden van ontwikkel- en testomgevingen.

2.3 Toegang tot productie-infrastructuur is beperkt tot geautoriseerd personeel met een functionele noodzaak.

2.4 Wij passen waar mogelijk least privilege, multi-factor authentication, logging en periodieke toegangscontrole toe.

Artikel 3 — Encryptie

3.1 Gegevens worden versleuteld verzonden via moderne TLS-verbindingen.

3.2 Bestanden, tokenkaarten, back-ups en gevoelige opslagobjecten worden versleuteld opgeslagen, voor zover technisch passend bij de betreffende component.

3.3 Encryptiesleutels worden niet gedeeld met AI-modelproviders.

3.4 Organisaties met aanvullende eisen kunnen, indien beschikbaar, afspraken maken over klantbeheerde sleutels, dedicated omgevingen of eigen hosting.

Artikel 4 — Toegangscontrole en autorisatie

4.1 VaultLM werkt met accounts, organisaties, workspaces, vaults, rollen en rechten.

4.2 Een gebruiker kan via AI-chat nooit méér ophalen dan die gebruiker volgens de ingestelde rechten in de Vault mag openen.

4.3 Toegang tot gedeelde documenten kan worden beperkt via rechten, looptijd, downloadbeleid, watermerk, intrekking en logging, afhankelijk van het gekozen plan en de instellingen.

4.4 Organisatieplannen kunnen aanvullende maatregelen ondersteunen, zoals SSO, SCIM, domeincontrole, verplichte MFA en aangepaste retentie, indien beschikbaar en overeengekomen.

Artikel 5 — Vault, retrieval en AI-routing

5.1 Bestanden in de Vault worden opgeslagen en geïndexeerd voor veilige retrieval.

5.2 Bij een AI-vraag haalt VaultLM uitsluitend relevante passages op uit bestanden waartoe de gebruiker toegang heeft.

5.3 Waar mogelijk worden relevante passages geminimaliseerd en gemaskeerd voordat zij naar het gekozen AI-model worden gestuurd.

5.4 VaultLM logt de route, actie, gebruiker, tijdstip, workspace, modelroute en relevante metadata voor audit en beveiliging. Logs bevatten niet meer inhoud dan noodzakelijk.

Artikel 6 — Masking Service en tokenkaarten

6.1 De Masking Service herkent en vervangt gevoelige waarden door stabiele tijdelijke tokens, zoals [PERSON_01], [IBAN_01], [EMAIL_01] of vergelijkbare tokens.

6.2 De koppeling tussen token en oorspronkelijke waarde wordt opgeslagen als tokenkaart.

6.3 Tokenkaarten verlaten de beveiligde VaultLM-omgeving niet en worden niet meegestuurd naar modelproviders of ontvangers van gedeelde bestanden, tenzij een geautoriseerde klantconfiguratie dat expliciet mogelijk maakt.

6.4 Automatische maskering is geen garantie dat alle gevoelige informatie wordt herkend. Gebruikers moeten output controleren, zeker bij juridische, privacygevoelige of risicovolle context.

Artikel 7 — Modelproviders en eigen API keys

7.1 VaultLM kan gebruikmaken van externe modelproviders of klantgestuurde modelroutes.

7.2 Bij standaard VaultLM-modelroutes configureert VaultLM de route zodanig dat ruwe documentdata zo veel mogelijk wordt geminimaliseerd en gemaskeerd voordat zij wordt aangeboden.

7.3 Bij gebruik van eigen API keys, eigen endpoints, self-hosted modellen of klantgestuurde modelroutes is de klant verantwoordelijk voor providerkeuze, regio, kosten, bewaartermijnen, trainingsinstellingen, beveiliging en policy van die provider.

7.4 Fair use-limieten op VaultLM-tokengebruik gelden niet voor modelkosten die rechtstreeks via eigen API keys van de klant lopen. Daarvoor gelden de voorwaarden, kosten en policies van de betreffende provider.

Artikel 8 — Logging, monitoring en audit

8.1 VaultLM registreert relevante gebeurtenissen zoals login, documentupload, maskering, AI-vraag, bronopening, deelactie, intrekking, API-gebruik, mislukte toegangspoging en administratieve wijzigingen.

8.2 Logs worden gebruikt voor beveiliging, audit, support, facturatie, fair use, fraudeonderzoek en compliance.

8.3 Logs worden bewaard gedurende 30 dagen, tenzij een andere termijn is overeengekomen.

8.4 Organisatieklanten kunnen, afhankelijk van het plan, auditlogs exporteren of koppelen aan eigen securityprocessen.

Artikel 9 — Back-ups, herstel en continuïteit

9.1 VaultLM maakt back-ups om herstel na incidenten mogelijk te maken.

9.2 Back-ups zijn beveiligd en worden verwijderd of overschreven binnen 35 dagen, tenzij anders overeengekomen.

9.3 VaultLM streeft naar hoge beschikbaarheid, maar garandeert geen ononderbroken werking, tenzij een aparte SLA is overeengekomen.

Artikel 10 — Kwetsbaarheden en securitymeldingen

10.1 Vermoedelijke kwetsbaarheden kunnen worden gemeld via hi@sharesafe.ai.

10.2 Zonder voorafgaande toestemming is het niet toegestaan om destructieve tests, social engineering, datatoegang buiten eigen account, denial-of-service, exfiltratie of privacy-invasieve tests uit te voeren.

10.3 VaultLM onderzoekt meldingen naar redelijkheid en prioriteit en kan aanvullende informatie vragen.

Artikel 11 — Misbruik, fraude en beëindiging

11.1 Bij oneigenlijk gebruik, fraude, vermoedelijke fraude, excessief geautomatiseerd gebruik, ongeautoriseerde toegang, policy-omzeiling of gedrag dat de veiligheid, beschikbaarheid, kostenstructuur of reputatie van VaultLM schaadt, kan VaultLM maatregelen nemen.

11.2 Maatregelen kunnen bestaan uit waarschuwing, beperking, throttling, opschorting, beëindiging, blokkering van API-toegang, verwijdering van gedeelde links, nader onderzoek of schadeverhaal.

11.3 VaultLM behoudt zich het recht voor schade, providerkosten, onderzoekskosten, juridische kosten en andere redelijke kosten op de klant te verhalen voor zover wettelijk toegestaan.

Artikel 12 — Beperkingen

12.1 Geen enkel beveiligingssysteem is foutloos. VaultLM treft passende maatregelen, maar kan niet garanderen dat incidenten, kwetsbaarheden, dataverlies, onbeschikbaarheid of ongeautoriseerde toegang nooit zullen plaatsvinden.

12.2 AI-modellen kunnen fouten maken, hallucineren of onjuiste conclusies trekken. Securitymaatregelen en bronverwijzingen vervangen geen menselijke controle.


Document 3 — Verwerkersovereenkomst / Data Processing Agreement VaultLM

Deze verwerkersovereenkomst is van toepassing wanneer VaultLM persoonsgegevens verwerkt namens een klant als verwerker in de zin van de AVG. Zij is bedoeld voor betaalde klanten, teams, organisaties, B2B/API-integraties en andere zakelijke verwerkingen waarbij de klant verwerkingsverantwoordelijke is.

Artikel 1 — Partijen en toepasselijkheid

1.1 Deze verwerkersovereenkomst maakt onderdeel uit van de overeenkomst tussen El Niño B.V., handelend onder de naam VaultLM, en de klant.

1.2 De klant is de verwerkingsverantwoordelijke. VaultLM is de verwerker, voor zover VaultLM persoonsgegevens verwerkt in documenten, workspaces, vaults, tokenkaarten, vragen, antwoorden, gedeelde objecten, logs of API-workflows namens de klant.

1.3 Wanneer de klant VaultLM inbouwt in een eigen product, workflow of API-integratie, blijft de klant verantwoordelijk voor zijn eigen eindgebruikers, informatieplichten, rechtsgrondslagen, configuratie en instructies.

Artikel 2 — Onderwerp en duur

2.1 VaultLM verwerkt persoonsgegevens voor het leveren van het platform, waaronder documentopslag, maskering, retrieval, AI-routing, bronverwijzingen, veilig geanonimiseerd delen, logging, support, security en API-functionaliteit.

2.2 De verwerking duurt zolang de overeenkomst loopt en zolang daarna nodig is voor verwijdering, export, back-upverloop, wettelijke verplichtingen of geschilbeslechting.

Artikel 3 — Aard en doel van de verwerking

3.1 De aard van de verwerking omvat onder meer verzamelen, ontvangen, opslaan, structureren, indexeren, maskeren, tokeniseren, ophalen, doorgeven aan modelroutes, weergeven, delen, loggen, verwijderen en beveiligen.

3.2 Het doel is het mogelijk maken van privacygerichte document-AI: eerst afschermen, dan AI gebruiken, daarna veilig geanonimiseerd delen.

3.3 VaultLM verwerkt persoonsgegevens uitsluitend op basis van gedocumenteerde instructies van de klant, tenzij VaultLM wettelijk verplicht is anders te handelen.

Artikel 4 — Categorieën persoonsgegevens en betrokkenen

4.1 De klant bepaalt welke persoonsgegevens worden verwerkt. Afhankelijk van de documenten kunnen dit onder meer zijn:

  • identificatiegegevens;
  • contactgegevens;
  • financiële gegevens;
  • contractuele gegevens;
  • bedrijfsgegevens die tot personen herleidbaar zijn;
  • personeelsgegevens;
  • onderwijsgegevens;
  • juridische of dossiergegevens;
  • bijzondere categorieën persoonsgegevens of strafrechtelijke gegevens, indien de klant die uploadt en daarvoor een wettelijke grondslag heeft.

4.2 Betrokkenen kunnen onder meer zijn: klanten, cliënten, medewerkers, sollicitanten, studenten, leerlingen, leveranciers, aandeelhouders, investeerders, contractpartijen, bronnen, patiënten of andere personen die in documenten voorkomen.

Artikel 5 — Instructies van de klant

5.1 De overeenkomst, productinstellingen, API-configuratie, workspace-instellingen, modelroutekeuze, maskerparameters en schriftelijke afspraken gelden als instructies van de klant.

5.2 VaultLM informeert de klant wanneer een instructie naar haar oordeel in strijd is met toepasselijke privacywetgeving, tenzij dit wettelijk verboden is.

5.3 De klant is verantwoordelijk voor de juistheid, rechtmatigheid en proportionaliteit van zijn instructies.

Artikel 6 — B2B/API, eigen product en ontwikkelaarsgebruik

6.1 Wanneer de klant VaultLM via API, SDK, white-label, embedded workflow of eigen product gebruikt, is de klant verantwoordelijk voor de eindgebruikerservaring, toestemming, privacyverklaring, gebruiksvoorwaarden, toegangsbeheer, documentselectie, modelroute en outputcontrole binnen dat product.

6.2 De klant moet zijn eindgebruikers duidelijk informeren dat automatische maskering en AI-output beperkingen hebben en geen garantie bieden op volledige anonimiteit, juistheid of geschiktheid.

6.3 De klant mag VaultLM niet inzetten voor een hoger risicoprofiel, bijzondere categorieën persoonsgegevens, strafrechtelijke gegevens of high-risk besluitvorming zonder passende aanvullende afspraken, grondslagen, beveiliging en menselijke controle.

Artikel 7 — Beveiligingsmaatregelen

7.1 VaultLM neemt passende technische en organisatorische maatregelen, waaronder encryptie, toegangscontrole, logging, autorisatie, gescheiden omgevingen, back-ups, monitoring, beveiligde verbindingen en incidentprocedures.

7.2 De maatregelen zijn nader beschreven in Document 2 — Securitydocumentatie.

7.3 De klant is verantwoordelijk voor veilig beheer van eigen accounts, wachtwoorden, API keys, rollen, toegangsrechten, gedeelde links en eindgebruikers.

Artikel 8 — Vertrouwelijkheid

8.1 VaultLM zorgt ervoor dat personen die toegang hebben tot persoonsgegevens gebonden zijn aan passende vertrouwelijkheidsverplichtingen.

8.2 Toegang tot klantdata door VaultLM-medewerkers is beperkt tot wat noodzakelijk is voor support, security, onderhoud, incidentrespons of wettelijke verplichtingen.

Artikel 9 — Subverwerkers

9.1 De klant geeft VaultLM algemene toestemming om subverwerkers in te schakelen voor het leveren van de dienst.

9.2 VaultLM houdt een actuele lijst van subverwerkers beschikbaar via sharesafe.ai/subprocessors of op verzoek.

9.3 VaultLM informeert zakelijke klanten over wezenlijke wijzigingen in subverwerkers voor zover wettelijk of contractueel vereist.

9.4 VaultLM legt aan subverwerkers verplichtingen op die in essentie gelijkwaardig zijn aan de verplichtingen uit deze verwerkersovereenkomst.

Artikel 10 — Internationale doorgifte

10.1 VaultLM streeft naar verwerking binnen de EER waar redelijkerwijs mogelijk.

10.2 Wanneer persoonsgegevens buiten de EER worden verwerkt, zorgt VaultLM voor passende waarborgen, zoals standaardcontractbepalingen, aanvullende maatregelen of een adequaatheidsbesluit, voor zover wettelijk vereist.

10.3 Bij eigen API keys, eigen providers of klantgestuurde modelroutes is de klant verantwoordelijk voor internationale doorgifte via die route.

Artikel 11 — Assistentie bij rechten van betrokkenen

11.1 VaultLM ondersteunt de klant, voor zover redelijk en mogelijk, bij verzoeken van betrokkenen met betrekking tot persoonsgegevens die VaultLM als verwerker verwerkt.

11.2 Indien een betrokkene rechtstreeks contact opneemt met VaultLM over data waarvoor de klant verwerkingsverantwoordelijke is, verwijst VaultLM het verzoek in beginsel door naar de klant, tenzij wettelijk anders vereist.

Artikel 12 — Datalekken

12.1 VaultLM informeert de klant zonder onredelijke vertraging nadat VaultLM kennis heeft genomen van een datalek dat betrekking heeft op persoonsgegevens die VaultLM namens de klant verwerkt.

12.2 De melding bevat, voor zover beschikbaar, informatie over de aard van het incident, de vermoedelijke gevolgen, de getroffen of voorgestelde maatregelen en contactinformatie.

12.3 De klant blijft verantwoordelijk voor meldingen aan toezichthouders en betrokkenen, tenzij anders overeengekomen of wettelijk vereist.

Artikel 13 — Audit en informatie

13.1 VaultLM stelt informatie beschikbaar die redelijkerwijs nodig is om naleving van deze verwerkersovereenkomst aan te tonen.

13.2 Audits vinden plaats op redelijke voorafgaande aankondiging, tijdens normale kantooruren, zonder verstoring van de bedrijfsvoering en onder passende vertrouwelijkheid.

13.3 VaultLM kan auditverzoeken beperken of weigeren wanneer zij de veiligheid, privacy of vertrouwelijkheid van andere klanten, systemen of bedrijfsgeheimen in gevaar brengen.

Artikel 14 — Verwijdering en teruggave

14.1 Na beëindiging van de overeenkomst verwijdert of retourneert VaultLM persoonsgegevens volgens de overeenkomst, productinstellingen en toepasselijke bewaartermijnen.

14.2 Verwijdering uit back-ups vindt plaats binnen 35 dagen, tenzij een langere termijn wettelijk of technisch noodzakelijk is.

14.3 De klant is verantwoordelijk voor tijdige export van data vóór beëindiging van het account of abonnement.

Artikel 15 — Aansprakelijkheid

15.1 Aansprakelijkheid wordt geregeld in de hoofdovereenkomst en algemene voorwaarden.

15.2 VaultLM is niet aansprakelijk voor directe of indirecte schade die voortvloeit uit AI-fouten, hallucinaties, onvolledige maskering, indirecte identificatie, gebruik van eigen API keys, onjuiste klantinstructies, onrechtmatige uploads, onjuiste outputcontrole of delen door de klant, voor zover wettelijk toegestaan.

15.3 De klant vrijwaart VaultLM voor aanspraken van derden die voortvloeien uit onrechtmatige of onjuiste verwerking door of namens de klant, tenzij de aanspraak het gevolg is van een toerekenbare tekortkoming van VaultLM.


English version

Document 1 — VaultLM Privacy Notice

Applies to the website, the account-free anonymisation feature, the VaultLM platform, paid subscriptions, team and organisation workspaces, support, commercial communications and secure anonymised sharing.

Article 1 — Who we are

1.1 VaultLM is a service of El Niño B.V., established in Enschede, with offices at Kuipersdijk 6c, 7512 CH Enschede and registered with the Dutch Chamber of Commerce under number 08140115.

1.2 In this Privacy Notice, El Niño B.V. is referred to as “VaultLM”, “we”, “us” or “our”.

1.3 For privacy questions, contact hi@sharesafe.ai. For support questions, contact hi@sharesafe.ai.

1.4 VaultLM is a trademark of El Niño B.V.

Article 2 — What VaultLM does

2.1 VaultLM provides a privacy-focused technical layer between confidential documents and AI language models.

2.2 The platform is designed to detect and mask sensitive information in documents before relevant passages are provided to an AI model, link answers to source references and enable secure anonymised sharing.

2.3 VaultLM is not an AI model, not a general cloud storage service and not a professional advisory service. AI output may contain errors and must be reviewed by the user.

Article 3 — Roles under privacy law

3.1 For personal data processed for account management, billing, customer communication, security, product improvement, website analytics and commercial communications, VaultLM generally acts as controller.

3.2 For documents, document content, token maps, questions, answers, workspaces, vault environments and shared anonymised files processed by a customer in the platform, VaultLM generally acts as processor on behalf of the customer, unless expressly agreed otherwise.

3.3 The customer remains the controller for the lawfulness of documents, personal data and other data uploaded, processed, shared or otherwise handled through VaultLM.

3.4 Where an organisation uses VaultLM through an API, B2B integration, white-label solution, embedded workflow or its own product, that organisation is responsible for notices to its own end users, legal bases, permissions, masking configuration and output review.

Article 4 — Data we process

4.1 Depending on use, we may process the following categories of data:

  • account data, such as name, email address, organisation, role, language preference and authentication data;
  • subscription and billing data, such as plan, seats, invoice address, VAT number, payment status and payment history;
  • usage data, such as number of documents, questions, masking actions, tokens, sharing actions, workspace activity and activation status;
  • technical data, such as IP address, browser, device, session data, logs, error messages, security events and API usage;
  • support and communication data, such as support messages, feedback, demo requests and communication preferences;
  • document data uploaded or processed by users;
  • derived objects, such as masked text, token maps, retrieval indexes, source references, anonymised share versions and audit logs.

4.2 VaultLM does not use document content, questions, answers or token maps for general marketing profiles and does not sell such data to third parties.

Article 5 — Document content, AI processing and model providers

5.1 VaultLM is designed around the principle: mask first, then use AI. Relevant context is minimised and masked where possible before it is sent to an AI model.

5.2 The token map linking masked tokens to original values remains inside the secure VaultLM environment and is not sent to AI model providers or shared files, unless the user or organisation has expressly configured an authorised route.

5.3 VaultLM does not use uploaded documents, questions, answers or token maps to train or fine-tune its own AI models.

5.4 Where VaultLM uses external model providers, those providers are contractually or technically selected and configured so that customer data is not used to train general models, to the extent supported by the relevant provider and model route.

5.5 Where a customer uses its own API keys or model route, the customer is responsible for the terms, data processing, costs, retention, training settings, security measures and policies of the relevant provider. In that case, the provider’s terms and privacy and security documentation apply to that model route.

Article 6 — Purposes and legal bases

6.1 We process personal data for the following purposes:

  • creating and managing accounts;
  • providing, securing, maintaining and improving the platform;
  • performing subscriptions, payments, billing and support;
  • processing documents, masking actions, questions, answers, source references and sharing actions;
  • monitoring fair use, token usage, misuse, fraud and security risks;
  • complying with legal obligations;
  • sending transactional emails, service messages and, where permitted, product or marketing communications;
  • performing analytics on an aggregated or minimised basis.

6.2 Depending on the context, we rely on performance of a contract, legitimate interests, consent, legal obligation or, where we act as processor, the instruction of the customer as controller.

Article 7 — Account-free anonymisation feature

7.1 When using the account-free anonymisation feature, VaultLM temporarily processes the uploaded document to detect and mask sensitive information and make a derived version available.

7.2 Account-free processing is intended as a limited, one-off product experience. Unless stated otherwise, documents from account-free sessions are not stored long-term and are not used for model training.

7.3 To prevent misuse, fraud, excessive use or security incidents, VaultLM may process technical metadata, limits and logs.

7.4 Where the user chooses to receive the output by email or create an account, we process the email address and related metadata for that purpose.

Article 8 — Secure anonymised sharing

8.1 Users can use VaultLM to share anonymised or masked versions of documents, analyses or answers with third parties.

8.2 The sender is responsible for the decision to share, recipients, permissions, duration, download policy and review of the masking output before sending.

8.3 Recipients may leave technical metadata, such as opening time, IP address, device, click behaviour and email address where provided. This data is used for security, audit, access, misuse prevention and, where permitted, conversion to own use.

8.4 Anonymised sharing does not guarantee that shared information is legally fully anonymous. Indirect identification may remain possible depending on context and combination of data.

Article 9 — Cookies, analytics and tracking

9.1 VaultLM may use functional cookies or similar technologies for login, security, language preferences and session management.

9.2 For analytics and product improvement, we prefer privacy-friendly, aggregated or pseudonymised data.

9.3 For marketing cookies or similar tracking technologies, we request consent where legally required.

Article 10 — Retention

10.1 We do not retain personal data longer than necessary for the purpose for which it was collected, unless a longer retention period is legally required or necessary for disputes, security or compliance.

10.2 Account and billing data is retained while the account is active and afterwards as needed for legal administration, contractual obligations and dispute resolution.

10.3 Documents in the Vault are retained while the account or organisation is active or while the configured retention period applies.

10.4 After account termination, documents in production systems are deleted within the period stated in the agreement or product documentation. Backups are deleted or overwritten within 35 days, unless another period has been agreed.

10.5 Audit logs and security logs are retained for 30 days, unless a longer period is needed for security, compliance, fraud investigation or legal obligations.

Article 11 — Subprocessors and third parties

11.1 VaultLM may use subprocessors and service providers for hosting, security, email, payments, support, analytics, logging, model routing and other technical parts of the service.

11.2 An up-to-date list of subprocessors is available at sharesafe.ai/subprocessors or on request via hi@sharesafe.ai.

11.3 We enter into appropriate contractual arrangements with subprocessors, including data processing agreements, security obligations and international transfer safeguards where required.

11.4 VaultLM does not sell personal data or document content to third parties.

Article 11a — Browser identifier and own usage measurement

11a.1 We store a single random identifier in your browser to link your own sessions, including if you later create an account. It contains nothing about you or your documents, and you can delete it yourself via your browser settings.

11a.2 We use no third-party analytics. Usage data (which steps of the tool were used, document type category, language and counts of detected items, never content, values or filenames) is processed on our own infrastructure within the EU.

Article 12 — International transfers

12.1 VaultLM aims for EU-first processing and hosting where reasonably possible and appropriate.

12.2 Where personal data is processed outside the European Economic Area, we ensure appropriate safeguards, such as standard contractual clauses, supplementary measures or an adequacy decision, where legally required.

12.3 Where a customer uses its own API keys or model providers, the customer is responsible for the region, transfers, contractual safeguards and settings of that provider.

Article 13 — Security

13.1 VaultLM takes appropriate technical and organisational measures to protect personal data and document data against loss, misuse, unauthorised access, alteration and unauthorised disclosure.

13.2 These measures include encryption, access control, logging, workspace-level authorisation, separated environments, secure connections, monitoring, backups and incident procedures.

13.3 Further details are set out in Document 2 — Security Documentation.

Article 14 — Data subject rights

14.1 Depending on the circumstances, data subjects have rights of access, correction, deletion, restriction, objection, portability and withdrawal of consent.

14.2 Where VaultLM acts as controller, requests can be submitted via hi@sharesafe.ai.

14.3 Where VaultLM acts as processor for a customer, VaultLM will generally refer data subject requests to the customer or assist the customer in handling them, where legally required and contractually agreed.

Article 15 — Data breaches and incidents

15.1 If VaultLM identifies a security incident involving personal data, we investigate the incident and take appropriate measures.

15.2 Where VaultLM acts as processor and a data breach is relevant to the customer, we inform the customer without undue delay in accordance with the Data Processing Agreement.

15.3 The customer remains responsible for any notifications to authorities and data subjects where VaultLM acts as processor, unless otherwise agreed or legally required.

Article 16 — Changes

16.1 VaultLM may update this Privacy Notice. In case of material changes, we inform users through the website, platform or by email.

16.2 The latest version applies from the stated effective date.


Document 2 — VaultLM Security Documentation

This Security Documentation describes the main technical and organisational measures of VaultLM. It is intended as a transparent overview for end users, teams, organisations, security reviewers and B2B/API customers.

Article 1 — Security principles

1.1 VaultLM is built around the principle that confidential documents should not be unnecessarily exposed to AI models or third parties.

1.2 The core principles are:

  • mask first, then use AI;
  • minimum context to the model;
  • token maps stay inside the secure environment;
  • users can only retrieve what they are authorised to open;
  • answers should be verifiable through sources;
  • sharing actions should be bounded, traceable and revocable;
  • misuse, fraud and excessive use should be detectable.

Article 2 — Hosting and infrastructure

2.1 VaultLM is hosted with Hetzner Online GmbH in Germany (EU), unless otherwise agreed for specific organisation or self-hosted environments.

2.2 Production environments are logically separated from development and test environments.

2.3 Access to production infrastructure is limited to authorised personnel with a functional need.

2.4 We apply least privilege, multi-factor authentication, logging and periodic access reviews where possible.

Article 3 — Encryption

3.1 Data is encrypted in transit using modern TLS connections.

3.2 Files, token maps, backups and sensitive storage objects are encrypted at rest, where technically appropriate for the relevant component.

3.3 Encryption keys are not shared with AI model providers.

3.4 Organisations with additional requirements may, where available, agree on customer-managed keys, dedicated environments or own hosting.

Article 4 — Access control and authorisation

4.1 VaultLM uses accounts, organisations, workspaces, vaults, roles and permissions.

4.2 A user can never retrieve more through AI chat than that user is authorised to open in the Vault.

4.3 Access to shared documents can be limited by permissions, duration, download policy, watermark, revocation and logging, depending on the selected plan and settings.

4.4 Organisation plans may support additional measures such as SSO, SCIM, domain control, mandatory MFA and custom retention, where available and agreed.

Article 5 — Vault, retrieval and AI routing

5.1 Files in the Vault are stored and indexed for secure retrieval.

5.2 When an AI question is asked, VaultLM retrieves only relevant passages from files the user is authorised to access.

5.3 Where possible, relevant passages are minimised and masked before they are sent to the selected AI model.

5.4 VaultLM logs the route, action, user, timestamp, workspace, model route and relevant metadata for audit and security. Logs contain no more content than necessary.

Article 6 — Masking Service and token maps

6.1 The Masking Service detects and replaces sensitive values with stable temporary tokens, such as [PERSON_01], [IBAN_01], [EMAIL_01] or similar tokens.

6.2 The mapping between token and original value is stored as a token map.

6.3 Token maps do not leave the secure VaultLM environment and are not sent to model providers or recipients of shared files, unless an authorised customer configuration expressly enables this.

6.4 Automatic masking does not guarantee that all sensitive information is detected. Users must review output, especially in legal, privacy-sensitive or high-risk contexts.

Article 7 — Model providers and own API keys

7.1 VaultLM may use external model providers or customer-controlled model routes.

7.2 For standard VaultLM model routes, VaultLM configures the route so that raw document data is minimised and masked as much as possible before it is provided.

7.3 When using own API keys, own endpoints, self-hosted models or customer-controlled model routes, the customer is responsible for provider choice, region, costs, retention, training settings, security and policy of that provider.

7.4 Fair use limits on VaultLM token usage do not apply to model costs that run directly through the customer’s own API keys. The terms, costs and policies of the relevant provider apply to those costs.

Article 8 — Logging, monitoring and audit

8.1 VaultLM records relevant events such as login, document upload, masking, AI question, source opening, sharing action, revocation, API usage, failed access attempt and administrative changes.

8.2 Logs are used for security, audit, support, billing, fair use, fraud investigation and compliance.

8.3 Logs are retained for 30 days, unless another period has been agreed.

8.4 Depending on the plan, organisation customers may export audit logs or connect them to their own security processes.

Article 9 — Backups, recovery and continuity

9.1 VaultLM makes backups to enable recovery after incidents.

9.2 Backups are secured and deleted or overwritten within 35 days, unless otherwise agreed.

9.3 VaultLM aims for high availability, but does not guarantee uninterrupted operation unless a separate SLA has been agreed.

Article 10 — Vulnerabilities and security reports

10.1 Suspected vulnerabilities can be reported via hi@sharesafe.ai.

10.2 Without prior permission, destructive testing, social engineering, data access outside your own account, denial-of-service, exfiltration or privacy-invasive testing is not permitted.

10.3 VaultLM investigates reports reasonably and according to priority and may request additional information.

Article 11 — Misuse, fraud and termination

11.1 In case of misuse, fraud, suspected fraud, excessive automated use, unauthorised access, policy circumvention or behaviour that harms the security, availability, cost structure or reputation of VaultLM, VaultLM may take measures.

11.2 Measures may include warning, limitation, throttling, suspension, termination, blocking API access, removal of shared links, further investigation or recovery of damages.

11.3 VaultLM reserves the right to recover damages, provider costs, investigation costs, legal costs and other reasonable costs from the customer to the extent permitted by law.

Article 12 — Limitations

12.1 No security system is flawless. VaultLM takes appropriate measures but cannot guarantee that incidents, vulnerabilities, data loss, unavailability or unauthorised access will never occur.

12.2 AI models can make mistakes, hallucinate or draw incorrect conclusions. Security measures and source references do not replace human review.


Document 3 — VaultLM Data Processing Agreement

This Data Processing Agreement applies where VaultLM processes personal data on behalf of a customer as processor under the GDPR. It is intended for paid customers, teams, organisations, B2B/API integrations and other business processing where the customer is controller.

Article 1 — Parties and applicability

1.1 This Data Processing Agreement forms part of the agreement between El Niño B.V., trading as VaultLM, and the customer.

1.2 The customer is the controller. VaultLM is the processor to the extent VaultLM processes personal data in documents, workspaces, vaults, token maps, questions, answers, shared objects, logs or API workflows on behalf of the customer.

1.3 Where the customer embeds VaultLM in its own product, workflow or API integration, the customer remains responsible for its own end users, notices, legal bases, configuration and instructions.

Article 2 — Subject matter and duration

2.1 VaultLM processes personal data to provide the platform, including document storage, masking, retrieval, AI routing, source references, secure anonymised sharing, logging, support, security and API functionality.

2.2 Processing lasts for the duration of the agreement and afterwards as needed for deletion, export, backup expiry, legal obligations or dispute resolution.

Article 3 — Nature and purpose of processing

3.1 The nature of processing includes collecting, receiving, storing, structuring, indexing, masking, tokenising, retrieving, transmitting to model routes, displaying, sharing, logging, deleting and securing.

3.2 The purpose is enabling privacy-focused document AI: mask first, then use AI, then share securely and anonymously.

3.3 VaultLM processes personal data only on documented instructions from the customer, unless VaultLM is legally required to act otherwise.

Article 4 — Categories of personal data and data subjects

4.1 The customer determines which personal data is processed. Depending on the documents, this may include:

  • identification data;
  • contact data;
  • financial data;
  • contractual data;
  • business data traceable to individuals;
  • employee data;
  • education data;
  • legal or case file data;
  • special categories of personal data or criminal offence data, if the customer uploads such data and has a legal basis.

4.2 Data subjects may include customers, clients, employees, applicants, students, pupils, suppliers, shareholders, investors, contract parties, sources, patients or other individuals appearing in documents.

Article 5 — Customer instructions

5.1 The agreement, product settings, API configuration, workspace settings, model route selection, masking parameters and written arrangements constitute the customer’s instructions.

5.2 VaultLM informs the customer if an instruction, in its opinion, infringes applicable privacy law, unless legally prohibited from doing so.

5.3 The customer is responsible for the accuracy, lawfulness and proportionality of its instructions.

Article 6 — B2B/API, own product and developer use

6.1 Where the customer uses VaultLM through an API, SDK, white-label solution, embedded workflow or own product, the customer is responsible for the end-user experience, consent, privacy notice, terms of use, access control, document selection, model route and output review within that product.

6.2 The customer must clearly inform its end users that automatic masking and AI output have limitations and do not guarantee full anonymity, correctness or suitability.

6.3 The customer must not use VaultLM for a higher risk profile, special categories of personal data, criminal offence data or high-risk decision-making without appropriate additional arrangements, legal bases, security and human review.

Article 7 — Security measures

7.1 VaultLM takes appropriate technical and organisational measures, including encryption, access control, logging, authorisation, separated environments, backups, monitoring, secure connections and incident procedures.

7.2 The measures are further described in Document 2 — Security Documentation.

7.3 The customer is responsible for secure management of its own accounts, passwords, API keys, roles, permissions, shared links and end users.

Article 8 — Confidentiality

8.1 VaultLM ensures that persons authorised to process personal data are bound by appropriate confidentiality obligations.

8.2 Access to customer data by VaultLM staff is limited to what is necessary for support, security, maintenance, incident response or legal obligations.

Article 9 — Subprocessors

9.1 The customer gives VaultLM general authorisation to engage subprocessors to provide the service.

9.2 VaultLM maintains an up-to-date list of subprocessors at sharesafe.ai/subprocessors or on request.

9.3 VaultLM informs business customers of material changes in subprocessors to the extent legally or contractually required.

9.4 VaultLM imposes obligations on subprocessors that are essentially equivalent to those in this Data Processing Agreement.

Article 10 — International transfers

10.1 VaultLM aims to process data within the EEA where reasonably possible.

10.2 Where personal data is processed outside the EEA, VaultLM ensures appropriate safeguards, such as standard contractual clauses, supplementary measures or an adequacy decision, where legally required.

10.3 For own API keys, own providers or customer-controlled model routes, the customer is responsible for international transfers through that route.

Article 11 — Assistance with data subject rights

11.1 VaultLM assists the customer, where reasonable and possible, with data subject requests relating to personal data that VaultLM processes as processor.

11.2 If a data subject contacts VaultLM directly about data for which the customer is controller, VaultLM will generally refer the request to the customer, unless legally required otherwise.

Article 12 — Data breaches

12.1 VaultLM informs the customer without undue delay after becoming aware of a personal data breach relating to personal data processed on behalf of the customer.

12.2 The notification includes, where available, information about the nature of the incident, likely consequences, measures taken or proposed and contact details.

12.3 The customer remains responsible for notifications to authorities and data subjects, unless otherwise agreed or legally required.

Article 13 — Audit and information

13.1 VaultLM makes available information reasonably necessary to demonstrate compliance with this Data Processing Agreement.

13.2 Audits take place on reasonable prior notice, during normal business hours, without disruption to operations and under appropriate confidentiality.

13.3 VaultLM may limit or refuse audit requests where they would endanger the security, privacy or confidentiality of other customers, systems or trade secrets.

Article 14 — Deletion and return

14.1 After termination of the agreement, VaultLM deletes or returns personal data in accordance with the agreement, product settings and applicable retention periods.

14.2 Deletion from backups takes place within 35 days, unless a longer period is legally or technically necessary.

14.3 The customer is responsible for timely export of data before termination of the account or subscription.

Article 15 — Liability

15.1 Liability is governed by the main agreement and terms.

15.2 VaultLM is not liable for direct or indirect damage arising from AI errors, hallucinations, incomplete masking, indirect identification, use of own API keys, incorrect customer instructions, unlawful uploads, inadequate output review or sharing by the customer, to the extent permitted by law.

15.3 The customer indemnifies VaultLM against third-party claims arising from unlawful or incorrect processing by or on behalf of the customer, unless the claim results from an attributable breach by VaultLM.


Analytics & cookies

ShareSafe and VaultLM use first-party analytics only — there are no third-party trackers (no Google Analytics, Meta pixel, advertising networks, or cross-site tracking). Measurement data stays on our own EU infrastructure and is never sold or shared.

  • Anonymous audience measurement. We count unique and returning visits using a first-party identifier (mid) stored in a cookie with a maximum lifetime of 13 months. It is never linked to your identity, never used to build a profile, and is used only for aggregate statistics. You can object at any time using the toggle below — it stops the measurement and deletes the local id.
  • Session funnel. Within a single browsing session we measure which steps of the tool were used, with a session-scoped id that is discarded when the session ends.
  • Linking a signup to your session (opt-in). If — and only if — you tick the optional box when joining the waitlist, we link that signup to that session so we can see how you found us. It is off by default; leaving it unticked does not affect your signup.
  • Functional cookies. Your sign-in session, language, and display preferences are stored in strictly-necessary / functional cookies that the product needs to work.

End of document / Einde document.