How we protect your data
Where your data goes
Your tools
Read-only access to what you selected — or an export you upload yourself.
De-identification
Identifying details detected and removed. Encrypted at rest and in transit.
Your review
You see a de-identified sample and approve it.
Licensed dataset
Buyers get the de-identified copy only. Originals deleted.
You choose, down to the folder
- Nothing is included by default
- Pick individual channels, folders, libraries, repositories and date ranges
- Exclude by client, matter or tag
- DMs, private channels and personal mailboxes excluded
- Recent work embargoed: nothing newer than 12 months
Removed before anything is licensed
Personal data
Business-confidential details
Special cases
Data you process for customers
Excluded. If you're a processor for your customers (for example as a SaaS company), only data you control as a company qualifies.
Source code & trade secrets
Per repository: discussion only (commits, reviews, issues) or code too. Secrets are scanned out. Buyers may not reproduce your code.
Regulated professions
Client files are excluded. Only your firm's internal know-how qualifies, and you can export it yourself.
Accountants, lawyers & healthcareAgencies & consultancies
Briefs, pitches and campaigns qualify: they're your agency's own work. We remove client and brand names, prices and unreleased details before anything is licensed. If a specific contract forbids sharing, leave that client out — send us the clause and we'll check it.
Engineering & construction
Bids, specs (including CCTP and DCE), plans and site reports qualify once de-sensitized: client, site and project names, addresses, prices and contract values are removed.
Technical details
- Access
- Read-only app permissions limited to what you select (e.g. Microsoft 365 Sites.Selected, chosen Slack channels, Google Drive read-only on chosen folders)
- No-access option
- Upload an export yourself — we never connect to your systems
- Hosting
- EU data centers in Amsterdam and Frankfurt
- Sub-processors
- Scaleway — hosting (Amsterdam) · OVHcloud — backups (Frankfurt) · Brevo — email (Paris)
- Encryption
- TLS 1.3 in transit, AES-256 at rest
- Security testing
- External penetration test before launch, then yearly
- Certification
- ISO 27001: in preparation
You set the buyer rules
- Approve every buyer by name
- Block competitors, sector software vendors or whole sectors
- Limit buyers by region
- No resale, no re-identification, no verbatim reproduction
Your staff and works council
We write the briefing in your language and can present it ourselves — ondernemingsraad (NL, consent right under art. 27 WOR), conseil d'entreprise / ondernemingsraad and CPPT / CPBW (BE), CSE (FR), délégation du personnel (LU). No works council? You get a short information note for your team.
Our commitments
- Signed data processing agreement (GDPR art. 28)
- Read-only access, revoked when the project ends
- Original data deleted after packaging
- You approve every folder and the de-identified sample
- Licenses limited to 3 years, then certified deletion
- Buyers contractually barred from re-identification and resale