Who provides the service
Doc2iXBRL is a cloud software service for converting financial reporting documents to iXBRL, with AI-assisted taxonomy mapping and validation.
The provider is Ontos B.V., operating as Doc2iXBRL. Chamber of Commerce: 42011303. VAT: NL869277571B01.
Doc2iXBRL provides software, not tax advice, audit services, or sign-off on financial statements. Where regulatory or professional judgement is required, the customer and its advisers remain responsible.
Processing scope and contractual limits
Processing locations
Primary application hosting, database storage, document persistence, and OCR run in EU regions for filing data. AI-assisted processing steps (extraction, taxonomy mapping, validation) may involve sub-processors with EU/US service locations, as identified in the public sub-processor list; the DPA describes approval, objection, and transfer safeguards.
AI training
The DPA prohibits using Customer Data to train, retrain, fine-tune, or otherwise improve our own or third-party AI/ML models, except with the customer's specific prior written consent for a defined purpose.
Published technical and organizational measures
Encryption
TLS 1.2 or higher in transit and AES-256 or an equivalent-strength algorithm at rest. Uploaded source files are encrypted at application level before storage.
Customer access
Users authenticate through Supabase Auth. Database row-level security and workspace scoping isolate customer data.
Provider access
Provider personnel receive role-based, least-privilege access limited to their responsibilities; security-relevant activity is logged and traceable to authenticated users.
Deletion instructions and breach response
Retention and deletion
During the agreement, Personal Data follows the customer's documented instructions. Uploaded documents are deleted within 30 days of account deletion or contract termination, subject to limited backup, recovery, and legal-retention exceptions. Individual documents can be deleted through the service.
Incident notification
For a Personal Data breach affecting Customer Personal Data, the DPA requires customer notification without undue delay and no later than 72 hours after awareness. Regulatory and affected-user notifications depend on the GDPR risk thresholds.
Public procurement documents
These documents are public and can be reviewed directly.
Provider-specific evidence and tailored review materials remain available for active procurement reviews. Contact us about your review
What this brief does not claim
The public record supports a qualified description, not broader assurances.
- Not EU-only: the current provider list includes EU/US and global service locations.
- Not an absolute no-training promise: the DPA contains a specific prior-written-consent exception.
- Not all-data deletion within 30 days: backup, recovery, and legal-retention exceptions apply.
- Not a 72-hour promise for every incident: the DPA timing applies to Personal Data breaches affecting Customer Personal Data.
- Not a universal SSO entitlement: SSO/SAML requires organization-specific domain and identity-provider configuration.
- Not a Doc2iXBRL security certification: referenced certifications apply to the relevant infrastructure providers.
Public source documents reviewed 22 July 2026.