Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal data. Version 1.9. Effective: 6 October 2026
Last updated: 6 October 2026
Contents
Data Controller
Ontos B.V. (operating Doc2iXBRL) is the data controller responsible for your personal data. You can contact us at:
The iXBRL Reader (public tool)
Our iXBRL Reader is a free, public tool that anyone can use without an account. Opening it does require a company email address: we ask for it once, before your first upload, and remember that access in the browser. There is no way to use the Reader without leaving an address, and we do not accept personal mailbox providers such as Gmail, Outlook or Proton. When you upload a tagged iXBRL Report Package, that file is a financial report that may contain personal data of people other than you, such as directors, signatories, or auditors. This section explains how we process that data and the choices you have.
Purposes and legal basis
- Running the Reader on the file you upload
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) - to read, validate, and display the contents of the Report Package you ask us to open. Without the optional permission below, your file is processed transiently and is not kept beyond the limited window described under Retention.
- Storing your file to test and improve the product
- Legal basis: Consent (Art. 6(1)(a) GDPR), opt-in only and switched off by default. Only if you explicitly grant this permission do we keep your uploaded file to test and improve Doc2iXBRL. You can withdraw this consent at any time.
- Marketing email
- Legal basis: Consent (Art. 6(1)(a) GDPR), opt-in only and switched off by default. If you choose to receive product news and marketing email, we use the email address you provide for that purpose. You can withdraw this consent at any time, as easily as you gave it.
- Reader access and lead follow-up
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) - to understand which organisations use the public Reader and to avoid asking the same browser for access again. We reject common personal, free and throwaway email providers for this purpose, so the only address we hold is a business one. Contact about the Reader itself rests on the separate acknowledgement you give at the access step, which names that use; product news and marketing email are a different thing again and are sent only on the marketing opt-in described above.
Three things are asked of you and they are not the same thing. The company email address is required - it is how the Reader opens. Confirming you have the right to share the file is required too, because the file may contain other people's data. The storage and marketing permissions are optional, separate from each other, and switched off by default: the Reader works whether or not you grant them, and we record every consent choice so we can demonstrate it if asked.
Recipients and processors
We use Supabase as our processor for database and file storage. Supabase acts on our instructions under a data processing agreement and only to provide hosting and storage for the Reader. When you give your company email address to open the Reader, it is also stored as a contact record in Monaco, our CRM provider and processor, so that we can follow up the request. With marketing consent, the lead is also reported to Google, Microsoft, LinkedIn and OpenAI, as described in the 'Cookies' section.
Filing data is processed in EU regions for primary hosting, storage, OCR and document processing. Where any future approved processing involves a transfer outside the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards, as described in the 'International Data Transfers' section below.
How long we keep your upload
- Without the storage permission: your file itself is not retained - it is processed transiently and deleted as soon as the report has been rendered and checked against the validator. The technical metadata of the upload, and the company email address you gave to open the Reader, are purged within 30 days, subject only to limited backup retention and recovery windows. Giving us that address does not extend those 30 days. Each optional permission extends only what it covers, to a maximum of 12 months: the storage permission keeps your file and the record it belongs to, and the marketing opt-in keeps your email address so that we can send you what you asked for.
- With the storage permission: we keep your file for a maximum of 12 months (365 days), after which it is deleted, unless you withdraw consent or request erasure sooner.
- Erasure on request: you can ask us to delete an uploaded file and the personal data in it at any time, and we will do so without undue delay.
Personal data of other people in the file
A Report Package may contain personal data about people other than the person uploading it, for example the names and signatures of directors, board members, or auditors. We process that data only to run the Reader and, where you have opted in, to test and improve the product.
When you upload a file, you confirm and warrant that you have the right to share it and to grant us permission to process it for these purposes. You are responsible for ensuring you are allowed to share any personal data the file contains.
If you are an individual named in an uploaded report and you wish to exercise your data-protection rights or request erasure of your personal data, you can contact us at contact@doc2ixbrl.com. We will act on your request even though you did not upload the file yourself.
Your rights and how to exercise them
For data processed through the Reader you have the right to access, rectification, erasure, restriction of processing, objection, and data portability. To exercise any of these rights, contact us using the details in the 'Data Controller' and 'Contact Us' sections of this policy.
Where our processing is based on consent (storing your file to improve the product, or marketing email), you can withdraw that consent at any time, as easily as you gave it. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, if you believe your rights have been violated.
Data We Collect
We collect various types of information to provide and improve our service:
Personal Information
- Name and email address when you create an account
- Organization name and details
- Payment information when you subscribe (processed by our payment provider)
- Communications when you contact us
Documents and Content
- Financial documents you upload for conversion (PDF, DOCX)
- Generated iXBRL output files
Usage Data
- Log data including IP address, browser type, and access times
- Device information and identifiers
- How you interact with our service
How We Use Your Data
We process your personal data for the following purposes and legal bases:
- Providing our service
- Legal basis: Contract performance - to convert your documents to iXBRL format
- Account management
- Legal basis: Contract performance - to manage your account and subscriptions
- Service improvement
- Legal basis: Legitimate interest - to analyze usage and improve our service
- Communication
- Legal basis: Legitimate interest / Consent - to send service updates and marketing communications
AI Data Processing
Your documents are processed using AI technology to extract and map financial data. Important information about this processing:
- Document content may be shared with selected AI and OCR providers strictly as needed to extract text, analyze document structure, and suggest taxonomy mappings
- The specific providers we use may change over time. Detailed provider information, sub-processor details, and transfer safeguards are available on request
- Filing data processing runs in EU regions today; where any future approved provider outside the EEA is used, we rely on contractual and technical safeguards appropriate to the transfer
- We do not use your documents or generated output to train our own models, and product-improvement review stays off unless you or your workspace have enabled it
Data Sharing
We share your data with categories of service providers that help us operate the service:
- Infrastructure, hosting, and content delivery providers
- Run the web application, backend services, and secure network delivery
- Authentication, database, and encrypted storage providers
- Store account records, uploaded documents, and conversion results
- AI and OCR providers
- Support text extraction, document analysis, and taxonomy mapping
- Payment and billing providers
- Process payments, invoices, and related transactional records where applicable
- Development and operational tooling providers
- Support source code hosting, monitoring, and internal service operations
Data Retention
We retain data only as long as needed to provide the service, meet legal obligations, and support secure recovery processes:
- Account data: Retained while your account is active and generally for up to 30 days after account deletion or contract termination, unless longer retention is required by law
- Uploaded documents: Retained while your account is active and deleted within 30 days of account deletion or contract termination, subject to limited backup retention and recovery windows. You may delete individual documents through the Service
- Conversion results: Retained while your account is active and deleted on the same schedule as the related account or workspace, subject to limited backup retention
Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access
- Request a copy of all personal data we hold about you
- Right to Rectification
- Request correction of inaccurate or incomplete data
- Right to Erasure
- Request deletion of your personal data ('right to be forgotten')
- Right to Portability
- Receive your data in a structured, machine-readable format
- Right to Object
- Object to processing based on legitimate interests
- Right to Withdraw Consent
- Withdraw consent at any time where processing is based on consent
- Right to Restriction of Processing
- You can ask us to restrict the processing of your personal data in the circumstances provided by the GDPR
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe your rights have been violated.
Cookies
We use cookies and similar technologies to enhance your experience on our website. Cookies are small text files stored on your device that help us provide and improve our service.
Types of Cookies We Use
- Necessary Cookies
- Essential for website functionality, authentication, and security. Cannot be disabled.
- Analytics Cookies
- Help us understand how visitors use our website to improve the user experience. We use Google Analytics and Microsoft Clarity for this; Clarity records session replays and heatmaps, with sensitive content masked by default. These cookies are loaded only if you accept analytics cookies.
- Marketing and Ad Measurement
Used to deliver relevant advertisements and measure the results of our advertising. The LinkedIn, Microsoft and OpenAI tags described below load only if you accept marketing cookies, and only on our public pages, never inside the application or on your documents.
- If you accept marketing cookies, we may share your email address, hashed with SHA-256, with Google to attribute a form submission to an advertisement.
- Monaco
- Our marketing pages also use Monaco, a business-visitor identification service that determines the company behind a visit from its network (IP) address, the pages viewed and the time spent, aggregated at company level. Without marketing cookies this measurement is limited to the current browser session; with them, Monaco sets a first-party cookie to recognise returning business visits. Independently of these cookies, the details you submit through a contact, demo, course or Reader form are stored in Monaco as a contact record, so that we can respond to your request and see which campaign it came from.
- The LinkedIn Insight Tag measures the results of our LinkedIn advertising and helps us reach relevant professional audiences. It reports the page you are viewing, the referring page, your IP address, your browser and device characteristics and the time to LinkedIn, and LinkedIn sets cookies that may recognise you as a LinkedIn member.
- Microsoft
- The Microsoft Advertising tag (UET) measures the results of our Microsoft Advertising campaigns. It reports the page you are viewing, the referring page, your IP address, your browser and device characteristics and the time to Microsoft, and sets cookies on this website that recognise your visit and store the ad click identifier; Microsoft also sets its own cookies on its domains that may recognise you across websites.
- OpenAI
- The OpenAI Ads pixel measures the results of our advertising in ChatGPT. It stores two cookies on this website, the ChatGPT ad click reference and a browser reference, and reports only the forms you submit to OpenAI, with the page, your IP address, your browser characteristics and the time.
- Reporting by our server
- If you have accepted marketing cookies when you send a demo, contact (sales question), course or Reader form, and you are not already a customer, our server also reports that submission to Google, Microsoft, LinkedIn and OpenAI. The report contains an event identifier, the form, a value, the time, the ad click identifier, your email address as a SHA-256 hash, and technical details such as your IP address (or a hash of it) and browser; not every platform receives all of these. If our own customer records later show that your enquiry led to a sales opportunity or your organisation became a customer, our server may report that too, with the same details. We do this to measure the results of our advertising, to let each platform count a submission once and to let the platforms optimise our ad bidding. These hashes are still personal data. The legal basis is your consent (Art. 6(1)(a) GDPR); without it, nothing is sent.
- Withdrawal and retention
- You can withdraw your consent at any time in the cookie preferences below. We then remove the LinkedIn, Microsoft and OpenAI tags, delete the cookies they stored on this website, and cancel the undelivered server reports of forms you sent from this browser in the last 120 days; later forms are not reported. Reports are normally made within minutes; what a platform has already received, and the cookies it set on its own domains, stay with that platform. For forms sent from another browser or device, ask us to erase your data, which also cancels their undelivered reports. We keep the consent time, click identifiers, IP address, user agent and any outcome recorded for this purpose for at most 120 days. Your other rights are listed under Your Rights.
- Recipients and transfers
- Google receives the data as Google Ireland Limited, as our processor for your hashed email address, IP address and user agent and as an independent controller for ad click measurement; onward transfers to Google LLC in the United States rely on the EU-U.S. Data Privacy Framework. Microsoft (Microsoft Ireland Operations Limited), LinkedIn (LinkedIn Ireland Unlimited Company) and OpenAI (OpenAI Ireland Ltd) receive it as independent controllers. Microsoft processes it worldwide, and Microsoft Corporation is certified under the Data Privacy Framework. LinkedIn transfers it outside the EEA under Standard Contractual Clauses (SCCs), and LinkedIn Corporation is also certified under the Framework. OpenAI states that it processes data outside the EEA, including in the United States, relying on adequacy decisions or SCCs. Each platform may use what it receives as a controller for its own purposes, such as reporting and improving its advertising services, as described in its privacy statement: policies.google.com/privacy, microsoft.com/privacy/privacystatement, linkedin.com/legal/privacy-policy and openai.com/policies/eu-privacy-policy.
International Data Transfers
Filing data is processed in EU regions for primary hosting, storage, OCR and document processing. If a future approved sub-processor or support activity involves a transfer outside the European Economic Area (EEA), the transfer is handled under the safeguards described here.
Where non-EEA transfers occur, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards and can provide further detail on request. If you accept marketing cookies, the advertising platforms named under Cookies may process data in the United States; that section states the safeguard each relies on.
Security
We implement appropriate technical and organizational measures to protect your personal data:
- All data is encrypted in transit using TLS/SSL
- Data at rest is encrypted using industry-standard encryption
- Access to personal data is restricted to authorized personnel only
- Regular security assessments and monitoring are performed
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the 'last updated' date. We encourage you to review this policy periodically.
Contact Us
If you have any questions about this privacy policy or our data practices, please contact Ontos B.V.:
Ontos B.V.
- CoC
- 42011303
- VAT
- NL869277571B01


