Privacy and data handling

Privacy notice

Last updated: 26 July 2026 · Version 2026-07-26

The important part

DutchDecoded does not save your raw upload or generated explanation in its own database. To analyse it, the file passes through our Vercel-hosted server function and is sent to Anthropic’s commercial Claude API. Anthropic’s standard API policy says inputs and outputs are automatically deleted within 30 days, subject to usage-policy and legal exceptions. DutchDecoded does not have a documented zero-data-retention agreement with Anthropic.

1. Controller and contact

DutchDecoded is operated by Siya Ntombela, trading as Cleareyed Software, a Dutch sole proprietorship (eenmanszaak) registered in the Netherlands under KVK number 42117349. Siya Ntombela is the data controller for the processing described in this notice.

Privacy questions and rights requests: privacy@dutchdecoded.com. We do not currently appoint a data protection officer.

2. What happens when you analyse a document

    1

    You choose a PDF or image

    The selected file remains in your browser until you clear it, replace it, navigate away or close the page.

    2

    The file reaches our application

    Your browser sends it over HTTPS to a serverless function hosted by Vercel. The function reads it in request memory.

    3

    Anthropic performs the analysis

    The function converts the file to base64 and sends the document, prompt and document type to Anthropic’s commercial Claude API.

    4

    The explanation returns to your browser

    The generated explanation is shown in browser state. DutchDecoded does not write the raw file or explanation to Neon or object storage.

    5

    A usage count is updated

    After a completed analysis, Neon stores the month and document count used to apply the free-tier limit.

    6

    Optional features use separate data

    Deadline Guardian, reminder email and payment data are only processed when you use those features.

Anthropic states that commercial API inputs and outputs are not used to train its models by default. That is separate from retention: the standard retention window is still up to 30 days unless a customer has an approved zero-data-retention arrangement.

3. Data, purposes, legal bases and retention

The table below covers the personal data used by the current product. Provider security, fraud, and legal records can outlive the product data where the provider has an independent legal obligation.

Account and authentication

Email address, Clerk user ID, authentication and session data

Create and secure an account, keep you signed in, and associate your product data with you

Legal basis
Contract (GDPR Article 6(1)(b))
Where it is processed
Clerk; user ID and email are also stored in Neon
Retention and deletion
For the life of the account, plus limited provider security and legal recordsDeleted or de-identified after a verified deletion request, except records a provider must keep by law

Uploaded document and generated explanation

The selected PDF or image, its contents, the selected document type, analysis prompt, and generated explanation

Return the document explanation requested by the user

Legal basis
Contract (GDPR Article 6(1)(b)); the user initiates each analysis
Where it is processed
Held in browser and Vercel request memory; transmitted to the Anthropic commercial API; not written to DutchDecoded’s Neon database or object storage
Retention and deletion
DutchDecoded does not persist the raw file or explanation. Anthropic’s standard API policy says inputs and outputs are automatically deleted within 30 days, subject to usage-policy and legal exceptionsThe browser copy disappears when cleared or the page is closed. DutchDecoded cannot shorten Anthropic’s standard provider retention for an individual request

Usage metering

Calendar month and number of completed analyses

Apply the free-tier limit and operate the service

Legal basis
Legitimate interests (GDPR Article 6(1)(f))
Where it is processed
Neon
Retention and deletion
Retained with the account; there is currently no separate automatic monthly-row deletion jobDeleted from Neon after a verified account-deletion request

Deadline profile and reminder state

Arrival and employment dates, expat-scheme status and start date, partner/children/rental flags, permit expiry, dismissed deadlines, reminder preference, and reminder send log

Calculate personal reminder dates, remember dismissals, send requested emails, and prevent duplicate sends

Legal basis
Contract (GDPR Article 6(1)(b)); email reminders are optional and can be disabled
Where it is processed
Neon
Retention and deletion
Retained while the account remains activeDeleted from Neon after a verified account-deletion request

Reminder delivery

Email address, deadline name, due date, consequence text, delivery metadata, and an unsubscribe link containing a user identifier and signed token

Deliver requested deadline reminders and process unsubscribe requests

Legal basis
Contract (GDPR Article 6(1)(b)); legitimate interests for delivery integrity (Article 6(1)(f))
Where it is processed
Resend; send status is also recorded in Neon
Retention and deletion
Neon send logs are retained with the account. Resend retains delivery data under its service terms and account configurationDutchDecoded deletes its send log after a verified account-deletion request and requests provider deletion where applicable

Subscription and payment

Email address, Clerk user ID in checkout metadata, Stripe customer ID, subscription status and dates; Stripe receives payment method, billing, transaction, fraud-prevention, device, and IP data

Create and administer a subscription, process payment, prevent fraud, and keep required accounting records

Legal basis
Contract (GDPR Article 6(1)(b)); legal obligation (Article 6(1)(c)); legitimate interests in fraud prevention (Article 6(1)(f))
Where it is processed
Stripe; customer reference and subscription state are also stored in Neon
Retention and deletion
Operational subscription data is kept while needed for the account. Transaction and accounting records may be kept for at least seven years where Dutch tax law requires it; Stripe applies its own financial-services retention dutiesOperational Neon data can be deleted after account closure. Required transaction, tax, fraud, and dispute records are not erased before their lawful retention period ends

Hosting and security metadata

IP address, request time, URL, headers, device/browser information, response status, and technical error information

Serve and secure the website, investigate failures and abuse, and maintain availability

Legal basis
Legitimate interests (GDPR Article 6(1)(f))
Where it is processed
Vercel and relevant infrastructure providers; DutchDecoded application logs do not intentionally include document bodies
Retention and deletion
For the provider-configured logging period and longer only where needed for security, abuse prevention, or legal obligationsExpires under provider settings; specific security or legal records may be retained while the underlying need remains

4. Service providers and recipients

These are the external services in the current product data flow. We do not sell personal data and the application contains no advertising or behavioural-analytics SDK.

Vercel

Hosting processor; controller for some service-generated data

Website delivery, serverless request processing, deployment and platform logging

Data
Uploaded file during the analysis request; IP address, headers, request and error metadata
Retention
Request memory is temporary; platform metadata follows the configured Vercel plan and security/legal requirements
Processing locations
United States and other subprocessor locations
Provider terms →

Anthropic

Processor for the commercial Claude API

Document analysis and explanation generation

Data
Uploaded document, selected document type, prompts and generated output
Retention
Standard API inputs and outputs are automatically deleted within 30 days, except where Anthropic must retain them for usage-policy enforcement or law. DutchDecoded has no documented zero-data-retention agreement
Processing locations
United States
Provider terms →

Clerk

Authentication processor; controller for its account and service data

Account creation, authentication and session security

Data
Email, user ID, session tokens, authentication events, device and security data
Retention
For the account and session lifecycle, plus limited security and legal records under Clerk’s terms
Processing locations
United States and other subprocessor locations
Provider terms →

Neon

Database processor

Store application account, usage, deadline, reminder and subscription-reference data

Data
The DutchDecoded data categories marked as stored in Neon; no raw document or generated explanation
Retention
For the account lifecycle unless a longer legal period applies to a specific record
Processing locations
Configured cloud database region and Neon subprocessor locations
Provider terms →

Stripe

Payment processor and independent controller for regulated payment, fraud and compliance activities

Checkout, subscription administration, payment processing, fraud prevention and financial compliance

Data
Email, customer and subscription data, Clerk user ID in metadata, payment method, billing, transaction, device and IP data
Retention
Under applicable financial, fraud, dispute and legal requirements; Stripe says retention varies by service and jurisdiction
Processing locations
European Economic Area, United States and other service locations
Provider terms →

Resend

Email delivery processor; controller for its account and service data

Send deadline reminders and manage delivery events

Data
Recipient email, message subject and body, unsubscribe URL, delivery and security metadata
Retention
Under the Resend service agreement, account settings and legal/security requirements
Processing locations
United States and other subprocessor locations
Provider terms →

5. International transfers

Some providers process data in the United States or use subprocessors outside the European Economic Area. Depending on the provider and processing, transfers are covered by an adequacy decision such as the EU–US Data Privacy Framework, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism described in the linked provider terms. You can request information about the safeguards relevant to your data by contacting us.

6. Deletion and retention requests

Account deletion is currently handled as a verified privacy request. Email privacy@dutchdecoded.com from the address attached to your account. We will remove DutchDecoded application records and coordinate deletion or restriction with Clerk, Stripe, Resend and other providers where applicable. We may ask for additional verification before acting.

Deletion does not erase transaction, tax, security, fraud-prevention or dispute records that we or a provider must retain by law. We normally respond within one month. If a request is complex, GDPR permits an extension; we will explain the extension within the first month.

7. Your GDPR rights

Subject to the conditions and exceptions in GDPR, you can ask us to:

  • give you access to your personal data;
  • correct inaccurate or incomplete data;
  • erase data or restrict how it is processed;
  • provide portable data you supplied to us where the right applies;
  • object to processing based on legitimate interests;
  • withdraw consent where consent is the legal basis, without affecting earlier processing.

Send requests to privacy@dutchdecoded.com. You may also complain to the Autoriteit Persoonsgegevens.

8. Cookies and similar technology

Clerk sets cookies and short-lived session tokens required for authentication and fraud prevention. They cannot be disabled while using a signed-in account. DutchDecoded does not currently use advertising cookies or a product analytics SDK. If optional analytics or marketing technology is added, this notice and the consent controls will be updated before that technology is enabled.

9. Automated analysis

The document explanation is generated automatically by an AI model and is not reviewed by a human before it is shown. DutchDecoded does not make a decision that changes your legal rights or status. The explanation is informational and can be wrong; verify important dates, amounts and instructions against the original document or the relevant authority.

10. Changes to this notice

We will change the date and version when this notice changes. Material changes that affect active account holders will also be communicated through the product or by email where appropriate. A privacy notice describes processing; it is not a contract that users accept merely by continuing to use the service.