How we protect your data

Where your data goes

Your tools

Read-only access to what you selected — or an export you upload yourself.

De-identification

Identifying details detected and removed. Encrypted at rest and in transit.

Your review

You see a de-identified sample and approve it.

Licensed dataset

Buyers get the de-identified copy only. Originals deleted.

You choose, down to the folder

  • Nothing is included by default
  • Pick individual channels, folders, libraries, repositories and date ranges
  • Exclude by client, matter or tag
  • DMs, private channels and personal mailboxes excluded
  • Recent work embargoed: nothing newer than 12 months

Removed before anything is licensed

Personal data

NamesEmail addressesPhone numbersIBANs & card numbersNational IDsHome addressesSecrets & API keys

Business-confidential details

Client, supplier & partner namesCompany numbers (KBO/BCE, KvK, SIREN, VAT)Brand, product & project namesPrices, rates & contract valuesSite locationsInvoice, booking & file numbersEORI, MRN, container & B/L numbers

Special cases

Data you process for customers

Excluded. If you're a processor for your customers (for example as a SaaS company), only data you control as a company qualifies.

Source code & trade secrets

Per repository: discussion only (commits, reviews, issues) or code too. Secrets are scanned out. Buyers may not reproduce your code.

Regulated professions

Client files are excluded. Only your firm's internal know-how qualifies, and you can export it yourself.

Accountants, lawyers & healthcare

Agencies & consultancies

Briefs, pitches and campaigns qualify: they're your agency's own work. We remove client and brand names, prices and unreleased details before anything is licensed. If a specific contract forbids sharing, leave that client out — send us the clause and we'll check it.

Engineering & construction

Bids, specs (including CCTP and DCE), plans and site reports qualify once de-sensitized: client, site and project names, addresses, prices and contract values are removed.

Technical details

Access
Read-only app permissions limited to what you select (e.g. Microsoft 365 Sites.Selected, chosen Slack channels, Google Drive read-only on chosen folders)
No-access option
Upload an export yourself — we never connect to your systems
Hosting
EU data centers in Amsterdam and Frankfurt
Sub-processors
Scaleway — hosting (Amsterdam) · OVHcloud — backups (Frankfurt) · Brevo — email (Paris)
Encryption
TLS 1.3 in transit, AES-256 at rest
Security testing
External penetration test before launch, then yearly
Certification
ISO 27001: in preparation

You set the buyer rules

  • Approve every buyer by name
  • Block competitors, sector software vendors or whole sectors
  • Limit buyers by region
  • No resale, no re-identification, no verbatim reproduction

Your staff and works council

We write the briefing in your language and can present it ourselves — ondernemingsraad (NL, consent right under art. 27 WOR), conseil d'entreprise / ondernemingsraad and CPPT / CPBW (BE), CSE (FR), délégation du personnel (LU). No works council? You get a short information note for your team.

Our commitments

  • Signed data processing agreement (GDPR art. 28)
  • Read-only access, revoked when the project ends
  • Original data deleted after packaging
  • You approve every folder and the de-identified sample
  • Licenses limited to 3 years, then certified deletion
  • Buyers contractually barred from re-identification and resale