CounzelAI

Privacy Policy

This policy explains what data Counzel AI collects, how we collect it, why we use it, how long we keep it, and how you can withdraw your consent or have your data deleted.

Last updated: September 21, 2026Version 1.1

1. Who we are

Counzel AI is an accounting and finance assistant for Belgian accounting firms and the companies they serve. It connects to your accounting system, drafts and codes purchase and sales invoices, runs your year-end close, prepares Belgian filings, and answers accounting and tax questions with sourced references.

Counzel AI is operated by Turing of Trust SRL, the data controller for the personal data described in this policy. You can reach us at any time using the contact details in the final section.

Where you are an accounting firm using Counzel to work on your clients' books, you remain the controller of your clients' data and we act as your processor, on your documented instructions. A data processing agreement is available on request.

2. What data we collect and keep

We collect only what the service needs in order to work. The categories below are exhaustive for the current product.

CategoryWhat it contains
Account and identity dataYour name, email address, sign-in credentials or single sign-on identity, profile image if you set one, session identifiers, interface language, and your role in the workspace.
Firm and company detailsYour firm's name, enterprise or VAT number, address, fiscal-year settings, and the identity of each company you manage in Counzel — including information retrieved from public registers (see section 3).
Accounting and financial dataData read from the accounting system you connect: general ledger entries and journals, purchase and sales invoices with their line detail, VAT figures, bank transactions, fixed-asset and depreciation schedules, and customer, supplier and partner records. Partner records can contain the name, address, enterprise or VAT number, email address and telephone number of individuals.
Documents and extracted textInvoices, bills and attachments that are processed by the service, together with the text and structured fields extracted from them.
Assistant conversationsThe questions you ask Counzelor, the answers returned with their sources, the review depth used, and which company the conversation concerned.
Review and correction historyWhich review lane each draft sits in and why, the corrections you make to a proposed coding, and the per-client coding patterns learned from those corrections.
Connection credentialsThe API key or authorisation token for your accounting system and, where you choose to supply your own, your AI provider key. These are held as secrets, not as ordinary application data.
Usage and technical dataWhich feature was used, at what time, on behalf of which company, which model ran and how many tokens it consumed, plus server and application logs containing IP address, browser type and error diagnostics.
Business contacts and company relationshipsFor the companies you deal with or research: the people we can identify by a business email address or a public professional profile (name, job title, business email, telephone, profile link, employer). For your own company and the companies around it: directors, shareholders, auditors and advisers. For each company, what it is to yours (customer, supplier, open or lost opportunity), worked out from your own books. Every fact is kept with where it came from, and what was only read from an email is marked as unconfirmed until you confirm it.
Prospect and contact dataIf you use our contact or trial-registration forms: your name, email address, firm name, enterprise or VAT number, language, your message, and the fact and time of your consent.

We do not collect special categories of personal data (such as health, biometric or political data), and we ask you not to submit them. We do not knowingly collect data about children; Counzel is a business service.

3. How we collect it

  • Directly from you, when you create an account, complete onboarding, configure a company, upload a document, or write to us.
  • From the accounting system you connect, through its official API, and only after you have explicitly authorised the connection. We read the data the service needs and write back only what you approve.
  • Automatically as you use the service, through server and application logs and usage metering.
  • From public sources, when you add a company: the Belgian Crossroads Bank for Enterprises (KBO/BCE) for legal identity and directorships, the National Bank of Belgium's Central Balance Sheet Office for filed annual accounts, and the Belgian Official Gazette for published company acts.
  • From our authentication provider, which handles sign-in on our behalf and tells us who you are once you are signed in.
  • From contact-data providers, in the Sales module only: when you ask us who to contact at a company and approve the purchase, we obtain business contact details for the people you selected from the providers listed in section 5.
  • From emails sent to a mailbox you connect: the sender's address, and the name, role and company they state. What the assistant reads from an email is kept as unconfirmed until you confirm it.
  • From public professional profiles and company websites, when you ask us to research a company.

We never buy data about you, our user, and we do not build profiles of you from sources outside the service. In the Sales module, and only when you ask for it and approve the spend, we buy business contact details of people at the companies you want to approach, from the providers listed in section 5. We keep a person only if we can identify them by a business email address, a public professional profile, or a record in your own accounting system: a name on a staff list is not kept. Shared mailboxes such as info@ are never treated as a person.

4. Why we use it, and on what legal basis

PurposeLegal basis
Providing the service: reading your ledger, drafting and coding invoices, running closings, preparing filings, and answering your questions.Performance of our contract with you.
Improving accuracy for you: using your own past entries and corrections so that suggestions match how your firm actually books things. This happens inside your own workspace only.Legitimate interest in delivering an accurate service, and performance of our contract.
Keeping one record of the people and companies around your business: who runs, owns, audits and advises your company, who you sell to, buy from and are approaching, and who your contacts there are, so that the assistant answers from what is already known instead of looking it up again.Performance of our contract with you. For the people concerned you decide why and how their details are used, and we act on your instructions; the basis is ordinarily your legitimate interest in business-to-business contact.
Keeping the service secure and available: authentication, access control, logging, abuse and fraud prevention, and diagnosing faults.Legitimate interest in the security of our service, and our legal obligation to secure personal data.
Metering and billing: recording which features ran and how much model capacity they used.Performance of our contract, and our legal obligation to keep accounting records.
Support and service communications: responding to your requests and notifying you about changes that affect you.Performance of our contract, and legitimate interest in supporting our users.
Sending you information about Counzel after you asked us to, and following up on a trial request.Your consent, which you can withdraw at any time.
Meeting our own legal obligations, and establishing or defending legal claims.Legal obligation, and legitimate interest.

What we do not do

  • We do not sell, rent or trade your data, and we do not share it for anyone else's advertising.
  • We do not use your content, your documents or your ledger to train foundation models. The AI models we use are consumed as enterprise services whose terms prohibit the provider from training on customer content.
  • We do not pool your data with another customer's. What Counzel learns from your corrections stays in your workspace and is never used to answer someone else's question.
  • We do not take automated decisions producing legal effects about you. Counzel proposes; a person approves. Nothing is posted or filed without a human decision.

5. Who we share it with

We use a small number of service providers to run Counzel. Each one is bound by a written contract, may process your data only on our instructions, and is listed below with the reason and the data involved.

ProviderWhyData involvedWhere
Microsoft AzureApplication hosting, database, file and secret storage, search index, and the AI models that power the assistant.All categories described in section 2.European Union (France Central) for hosting and storage. Some model inference runs on Azure OpenAI global deployments, which may process the prompt outside the EEA.
ClerkSign-in, session management and account security.Account and identity data only. No accounting data.United States, under standard contractual clauses.
BrevoSending transactional and notification email.Name and email address, and the content of the message sent to you.European Union.
GitHubSource control and our deployment pipeline.No customer data. Application code only.United States, under standard contractual clauses.
LushaSales module only, at your request: who to contact at a company, and their business contact details.The company's name and website, and the name of the person looked up. No accounting data.United States (hosted on Amazon Web Services) and Israel. Israel is recognised by the European Commission as adequate; transfers to the United States under the standard contractual clauses in Lusha's data processing agreement.
FullEnrichSales module only, at your request: a work email or telephone number for a person you selected.The person's name and the company's website. No accounting data.Data stored in the European Union. The provider and some of its sub-processors are in the United States, under the standard contractual clauses in FullEnrich's data processing agreement.
Bright DataSales module only, at your request: public professional profiles and public posts.The company's name and the public profile address. No accounting data.Israel, recognised by the European Commission as adequate. Any onward transfer to a country without that recognition is under the standard contractual clauses in Bright Data's data protection addendum.
Your own AI providerOnly if you choose to supply your own model key instead of using ours.The content of the requests that model handles.As set by that provider, under your own agreement with them.

Your accounting system provider — for example Odoo or Exact Online — is not our sub-processor. You hold that relationship directly, and their own privacy policy governs the data held there. Counzel exchanges data with them only over the connection you authorise: we read the accounting records the service needs, and we write back drafts, codings and postings that you approve.

We disclose data to public authorities only where a valid legal obligation requires it, and we will tell you unless we are legally barred from doing so. If our business is ever transferred, your data may transfer with it, and you will be informed beforehand.

6. Transfers outside the EEA

Counzel is hosted in the European Union, in Microsoft's France Central region, and your accounting data is stored there. Two transfers outside the European Economic Area can occur, both covered by the European Commission's standard contractual clauses and by the provider's own data protection terms:

  • Sign-in and session data is handled by our authentication provider in the United States.
  • Some assistant requests are answered by Azure OpenAI global deployments, meaning the text of that request may be processed outside the EEA. The provider is contractually prohibited from retaining it for training.

You can ask us for a copy of the safeguards that apply to these transfers.

7. How long we keep it, and when we delete it

We keep each category only for as long as it serves the purpose it was collected for, then delete it. Deletion removes the data from our live systems immediately and from our encrypted backups within a further seven days, after which the backup itself expires.

DataRetention period
Account and identity dataFor as long as your account exists, then thirty days after it is closed.
Accounting data, review state and learned coding patternsFor as long as your subscription is active. Deleted within thirty days of the subscription ending, or within thirty days of your deletion request, whichever comes first.
Documents and extracted textTwenty-four months from processing, or sooner on request. The original document remains in your own accounting system, which we do not control.
Assistant conversationsTwenty-four months, or until you delete them yourself.
Usage and metering recordsTwenty-four months, so that billing can be audited.
Server and security logsThirty days.
Connection credentialsUntil you disconnect the accounting system or remove the key. Deleted immediately on disconnection.
Business contacts and company relationshipsPeople at other companies: twelve months after we last saw them (in a brief, an email, a public register, or a change you made), then deleted automatically. People at your own company, and anything you confirmed: for as long as your subscription is active. Any person, on request: deleted at once; we keep only a one-way fingerprint of their address, which cannot be turned back into it, so that a later search does not bring them back. What a company is to yours is recomputed from your books every week and deleted with your subscription.
Prospect and contact form dataTwenty-four months from our last contact with you, or immediately if you ask us to remove it.
Our own invoices and accounting records relating to youSeven years, as Belgian accounting and tax law requires.

Deleting your Counzel account does not delete anything inside your own accounting system. Entries that Counzel posted there remain your records, under your control, and you delete them there if you wish to.

8. Your rights, withdrawing consent, and deleting your data

Some of this you can do yourself, immediately, inside the application:

  • Delete a conversation: any Counzelor conversation can be deleted from the conversation list, at any time.
  • Remove a person or a company: in Settings, under People and ownership, any entry can be removed, and what you remove is not brought back by a later reading of the public register.
  • Withdraw marketing consent: use the unsubscribe link in any email we send, or write to us. Withdrawing consent does not affect processing that already took place.

Everything else — including disconnecting your accounting system so that we stop reading from it, and erasing the data we hold about a particular company — is done by writing to us at the address in the final section. We act on it promptly and confirm when it is done. You have the following rights under the General Data Protection Regulation:

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of data that is wrong or incomplete.
  • Erasure — deletion of your data, subject only to records we are legally obliged to keep.
  • Restriction — a pause on processing while a dispute is resolved.
  • Portability — your data in a structured, commonly used, machine-readable format.
  • Objection — to processing based on our legitimate interests, and at any time to direct marketing.
  • Withdrawal of consent — at any time, where consent is the basis we rely on.

We answer within one month and never charge for it. If you are not satisfied, you can lodge a complaint with the Belgian Data Protection Authority — Autorité de protection des données / Gegevensbeschermingsautoriteit, Rue de la Presse 35, 1000 Brussels, [email protected] — or with the supervisory authority where you live.

If you are a person whose business contact details are held by a Counzel customer, write to us at the address in the final section. We will identify the customer concerned and see that your request to access, correct or erase your details is acted on.

10. How we protect it

  • Data is encrypted in transit with TLS 1.2 or better, and encrypted at rest by the storage platform.
  • Connection keys and other secrets are held in a managed key vault, reached through a workload identity. They are never written into source code, and never displayed back to you once saved.
  • Access to the application requires an authenticated account; administrative surfaces require an additional server-side role that a user cannot grant themselves.
  • Each workspace is isolated: every query is scoped to the company you are working on, so one customer's data is not reachable from another's session.
  • Access to production systems is limited to the people who need it, over accounts protected by multi-factor authentication.
  • Every change to the service goes through version control and a reviewed pull request, and the automated test suite must pass before it can be deployed.
  • Physical security of the data centres is Microsoft's responsibility under its own audited controls; we operate no hardware of our own.

If a personal data breach ever affects you, we will notify the Belgian Data Protection Authority within seventy-two hours and tell you directly where the breach is likely to present a high risk to you.

11. Cookies

We use strictly necessary cookies only: one to keep you signed in, one to remember your interface language, and one to remember which company you were last working on. They are required for the service to function, so no consent banner is shown.

We run no advertising cookies, no third-party analytics and no tracking pixels on this site or in the application.

12. Changes to this policy

When we change this policy we publish the new text here with a new version number and date. For material changes we also tell you by email and ask you to accept the new version the next time you open the application.

13. Contact us

For any question about this policy, to exercise a right, or to ask for a data processing agreement, write to us. We reply within one working day and, for formal requests, within one month.

Turing of Trust SRL
Rue Sainte Renelde 47, 1430 Rebecq, Belgium
BE 0805.507.992
[email protected]