Legal
What we process, why we process it, and the rights you have.
Last updated: September 2026 · See also our Terms of Service
TomIT B.V., registered in the Netherlands, is the controller for personal data processed through this website and for the accounts that use the TomIT service. In the workspace itself, your organisation decides what is stored; for that data your organisation is the controller and TomIT acts as a processor (see section 8).
For any privacy question or request you can reach us through the contact page. We answer privacy requests within 30 days.
We keep this simple: we process what is needed to run the service, secure it, and answer you.
We use as little as possible. The workspace sets a session cookie so you stay signed in; that cookie is strictly necessary and cannot be switched off. Your theme preference (light/dark) is stored in your browser's local storage, not in a cookie.
We do not use advertising cookies, social-media pixels or cross-site trackers, and we do not sell data. Because no tracking cookies are placed, our website has no cookie consent wall.
The public website uses self-hosted, privacy-friendly analytics on our own EU infrastructure. It does not set cookies and does not follow you to other websites. We use it to see which pages are visited and where the site can be improved.
On the public marketing pages we may also record session interactions (such as clicks, scrolling and page flow) to find usability problems. These recordings are used only for improving the website and are not used to build profiles of you.
The AI features in TomIT — AI import, contract parsing and the knowledge-base assistant — run on self-hosted models on our own EU infrastructure. We do not send workspace content to third-party AI providers.
Content you submit for an AI feature (for example text to import, or a contract PDF) is processed to produce the result you asked for, and is not used to train models that are available to others. AI suggestions are just suggestions: you decide what is saved.
We rely on a small number of providers to run the service — for example our EU hosting provider, our email delivery provider, and the optional integrations you choose to connect.
The current list of subprocessors, with their purposes and locations, is available on request through the contact page and forms part of the data processing agreement.
Your workspace data is stored on servers in Germany (European Union) and in encrypted backups. We do not transfer workspace data outside the EEA.
If you enable an optional integration, limited data (such as a device serial number or an access token) may be sent to that provider outside the EEA. It is used only to return the requested information to your workspace.
Personal data about your colleagues — names, usernames, work email addresses and assignment history — is entered by your organisation. For that data, your organisation is the controller and TomIT processes it on your instructions: to provide the workspace you configured, to secure it, and to help you when you ask us to.
We isolate every workspace from every other at the database level, and we do not use one customer's data to serve another. A data processing agreement (DPA) is available on request through the contact page.
We take the security of your data seriously. Among other measures:
Workspace data is kept for as long as your workspace exists. When you delete your workspace, it is removed from the live systems and rotated out of encrypted backups within 30 days.
Contact-form messages and support email are kept until your question is handled and for a reasonable period afterwards so we can follow up, unless you ask us to delete them sooner.
Security logs and audit records are kept for a limited period, long enough to investigate incidents and meet our legal obligations.
Under the GDPR you have the right to:
If you are unhappy with how we handle your data, tell us first through the contact page — we will do our best to fix it. You also have the right to complain to your local supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens.
We do not make decisions with legal or similarly significant effects based solely on automated processing. TomIT is a business tool and is not intended for children; we do not knowingly create accounts for anyone under 16.
If the service changes in a way that affects your privacy, we will update this page and mention material changes in the workspace or by email. The date at the top shows when the policy was last updated.
Privacy question, data request or DPA? Contact us.