Buyer brief

Security and procurement buyer brief.

A concise starting point for vendor review. Each section states the current public scope and links to the governing documents.

Provider and service

Who provides the service

Doc2iXBRL is a cloud software service for converting financial reporting documents to iXBRL, with AI-assisted taxonomy mapping and validation.

The provider is Ontos B.V., operating as Doc2iXBRL. Chamber of Commerce: 42011303. VAT: NL869277571B01.

Doc2iXBRL provides software, not tax advice, audit services, or sign-off on financial statements. Where regulatory or professional judgement is required, the customer and its advisers remain responsible.

Read the General Terms
Data and AI

Processing scope and contractual limits

Processing locations

Primary application hosting, database storage, document persistence, and OCR run in EU regions for filing data. AI-assisted processing steps (extraction, taxonomy mapping, validation) may involve sub-processors with EU/US service locations, as identified in the public sub-processor list; the DPA describes approval, objection, and transfer safeguards.

AI training

The DPA prohibits using Customer Data to train, retrain, fine-tune, or otherwise improve our own or third-party AI/ML models, except with the customer's specific prior written consent for a defined purpose.

View current sub-processors
Security and access

Published technical and organizational measures

  • Encryption

    TLS 1.2 or higher in transit and AES-256 or an equivalent-strength algorithm at rest. Uploaded source files are encrypted at application level before storage.

  • Customer access

    Users authenticate through Supabase Auth. Database row-level security and workspace scoping isolate customer data.

  • Provider access

    Provider personnel receive role-based, least-privilege access limited to their responsibilities; security-relevant activity is logged and traceable to authenticated users.

Read the security measures
Retention and incidents

Deletion instructions and breach response

Retention and deletion

During the agreement, Personal Data follows the customer's documented instructions. Uploaded documents are deleted within 30 days of account deletion or contract termination, subject to limited backup, recovery, and legal-retention exceptions. Individual documents can be deleted through the service.

Incident notification

For a Personal Data breach affecting Customer Personal Data, the DPA requires customer notification without undue delay and no later than 72 hours after awareness. Regulatory and affected-user notifications depend on the GDPR risk thresholds.

Read the incident response procedure
Scope

What this brief does not claim

The public record supports a qualified description, not broader assurances.

  • Not EU-only: the current provider list includes EU/US and global service locations.
  • Not an absolute no-training promise: the DPA contains a specific prior-written-consent exception.
  • Not all-data deletion within 30 days: backup, recovery, and legal-retention exceptions apply.
  • Not a 72-hour promise for every incident: the DPA timing applies to Personal Data breaches affecting Customer Personal Data.
  • Not a universal SSO entitlement: SSO/SAML requires organization-specific domain and identity-provider configuration.
  • Not a Doc2iXBRL security certification: referenced certifications apply to the relevant infrastructure providers.
Browse all legal documents

Public source documents reviewed 22 July 2026.