1. Who is responsible
Castor Concepts BV is the controller for the personal data of visitors of www.amlr-monitor.com and of users of the workspace: accounts, billing, alerts, the contact form and support.
For the content an organisation puts into its workspace (company profile, uploaded documents, notes, tasks, questions to the AI consultant), the organisation itself is the controller and Castor Concepts BV is the processor working on its instructions. Contact that organisation for questions about that content; the data processing terms are in section 12 of the terms of service.
2. What we process, and why
- Visitors: the technical data the hosting provider logs for every request (IP address, browser type, page requested, time) to deliver the pages and to detect abuse. Basis: our legitimate interest in a working and secure site. We run no analytics trackers.
- Account: name, e-mail address, hashed password, two-factor secret and backup codes (encrypted), role, organisation, plan and time of last visit. Purpose: providing the workspace, securing access, showing who changed what. Basis: performance of the agreement.
- Workspace content: what you and your colleagues put in (profile, documents, readiness records, notes, tasks, consultation drafts, questions and answers, compliance log, audit log). Purpose: the functions of the workspace, including the AI features. Basis: performance of the agreement; the organisation decides which data it puts in.
- Billing: plan, trial dates, subscription status, the billing details you enter for invoices (company name, address, VAT number, purchase order number, billing e-mail) and the identifiers of our payment provider. Card and bank details are entered at the payment provider and never reach us. Purpose: billing and bookkeeping. Basis: performance of the agreement and legal obligations.
- Alerts: the e-mail address or webhook address you enter under Alerts and the framework blocks you follow. Purpose: sending the alerts and regulatory updates you asked for. Basis: your request; you can switch them off at any time.
- Contact form, plan requests and support: name, e-mail address, organisation, subject and message. Purpose: answering you and following up. Basis: our legitimate interest in answering you, or the agreement where you are a customer.
- Site overview: aggregated counts (users, organisations, plans, activity) that the site owner sees to run the Service. Basis: legitimate interest.
3. AI features
The AI consultant, the company lookup, the impact assessment, the country points, task briefs, document summaries and regulatory updates send the relevant content (your question, the company profile, the uploaded documents, the recorded readiness) to Anthropic, PBC, whose Claude models generate the answer. Anthropic processes this data as our processor under its commercial terms, which exclude using your data to train models.
Put no personal data into the workspace that is not needed for the compliance work, and remove documents you no longer need.
4. Who receives data (sub-processors)
- Vercel, Inc. (United States): hosting and delivery of the site and request logs; the application runs in Frankfurt (EU).
- Neon, Inc. (United States): the database that stores accounts and workspace content, encrypted field by field.
- Anthropic, PBC (United States): the AI processing described in section 3.
- Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (United States): subscriptions, payments, invoices and VAT identification.
- Resend, Inc. (United States): sending of e-mail (invitations, alerts, regulatory updates, contact messages).
- Google Ireland Ltd: advertising slots on the public front page, when enabled, under Google’s own cookie consent.
- Bing and other IndexNow search engines: only the public addresses of new blog articles, no personal data.
Some of these providers are established in the United States. Transfers rely on the European Commission’s standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework. We do not sell personal data and share it with nobody else, unless the law obliges us to.
5. Cookies and local storage
- A session cookie after signing in (necessary; valid for thirty days at most and removed when you sign out).
- A cookie of ten minutes during two-factor sign-in.
- Your browser’s local storage remembers the entity type you chose on the dashboard; it never leaves your browser.
- Advertising cookies of Google only on the public front page, when advertising is enabled and you consented.
We use no analytics or tracking cookies.
6. How long we keep data
- Account data: until you delete your account, or until an admin deletes the organisation.
- Workspace content and the audit log: until the organisation deletes them or is deleted.
- Deleted data disappears from the live database at once and from backup copies within thirty days.
- Billing records: seven years, as Dutch tax law requires.
- Contact messages and plan requests: until handled, and at most two years.
- Request logs of the hosting provider and delivery logs of the e-mail provider: the short periods those providers keep them.
7. How we protect data
- All personal data and workspace content is encrypted field by field (AES-256-GCM) before it is stored, on top of the encryption at rest of the database. Passwords are stored as scrypt hashes; two-factor secrets and backup codes are encrypted or hashed.
- Connections are encrypted (TLS). Two-factor authentication is available to every user, and an admin can require it for the whole organisation.
- Access to decrypted data is limited to the site owner and only for support, a deletion request or the site overview. Every change in a workspace is recorded in the organisation’s audit log.
- Should a security incident affect your data, we tell the affected organisations without undue delay and, where required, the supervisory authority.
8. Your rights
You can access, correct, export and delete your data yourself: your own account under Security, the organisation and its content under Team (admins), exports under Export and report. You also have the right to restriction, to object, to data portability and to withdraw consent for alerts at any time. Contact us for anything you cannot do yourself; we answer within one month.
You can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority of your own country.
9. Children
The Service is meant for professionals. We do not knowingly process data of persons under sixteen.
10. Changes
We may update this statement. The date at the top shows the last change; material changes are announced in the workspace or by e-mail.
11. Contact
AMLR Monitor is operated by Castor Concepts BV.
See also: Terms of service · Plans and prices · Dashboard