CounzelAI

Privacy Policy

This policy explains what data Counzel AI collects, how we collect it, why we use it, how long we keep it, and how you can withdraw your consent or have your data deleted.

Last updated: July 29, 2026Version 1.0

1. Who we are

Counzel AI is an accounting and finance assistant for Belgian accounting firms and the companies they serve. It connects to your accounting system, drafts and codes purchase and sales invoices, runs your year-end close, prepares Belgian filings, and answers accounting and tax questions with sourced references.

Counzel AI is operated by Turing of Trust SRL, the data controller for the personal data described in this policy. You can reach us at any time using the contact details in the final section.

Where you are an accounting firm using Counzel to work on your clients' books, you remain the controller of your clients' data and we act as your processor, on your documented instructions. A data processing agreement is available on request.

2. What data we collect and keep

We collect only what the service needs in order to work. The categories below are exhaustive for the current product.

CategoryWhat it contains
Account and identity dataYour name, email address, sign-in credentials or single sign-on identity, profile image if you set one, session identifiers, interface language, and your role in the workspace.
Firm and company detailsYour firm's name, enterprise or VAT number, address, fiscal-year settings, and the identity of each company you manage in Counzel — including information retrieved from public registers (see section 3).
Accounting and financial dataData read from the accounting system you connect: general ledger entries and journals, purchase and sales invoices with their line detail, VAT figures, bank transactions, fixed-asset and depreciation schedules, and customer, supplier and partner records. Partner records can contain the name, address, enterprise or VAT number, email address and telephone number of individuals.
Documents and extracted textInvoices, bills and attachments that are processed by the service, together with the text and structured fields extracted from them.
Assistant conversationsThe questions you ask Counzelor, the answers returned with their sources, the review depth used, and which company the conversation concerned.
Review and correction historyWhich review lane each draft sits in and why, the corrections you make to a proposed coding, and the per-client coding patterns learned from those corrections.
Connection credentialsThe API key or authorisation token for your accounting system and, where you choose to supply your own, your AI provider key. These are held as secrets, not as ordinary application data.
Usage and technical dataWhich feature was used, at what time, on behalf of which company, which model ran and how many tokens it consumed, plus server and application logs containing IP address, browser type and error diagnostics.
Prospect and contact dataIf you use our contact or trial-registration forms: your name, email address, firm name, enterprise or VAT number, language, your message, and the fact and time of your consent.

We do not collect special categories of personal data (such as health, biometric or political data), and we ask you not to submit them. We do not knowingly collect data about children; Counzel is a business service.

3. How we collect it

  • Directly from you, when you create an account, complete onboarding, configure a company, upload a document, or write to us.
  • From the accounting system you connect, through its official API, and only after you have explicitly authorised the connection. We read the data the service needs and write back only what you approve.
  • Automatically as you use the service, through server and application logs and usage metering.
  • From public sources, when you add a company: the Belgian Crossroads Bank for Enterprises (KBO/BCE) for legal identity and directorships, the National Bank of Belgium's Central Balance Sheet Office for filed annual accounts, and the Belgian Official Gazette for published company acts.
  • From our authentication provider, which handles sign-in on our behalf and tells us who you are once you are signed in.

We do not buy personal data from data brokers, and we do not build profiles of you from sources outside the service.

4. Why we use it, and on what legal basis

PurposeLegal basis
Providing the service: reading your ledger, drafting and coding invoices, running closings, preparing filings, and answering your questions.Performance of our contract with you.
Improving accuracy for you: using your own past entries and corrections so that suggestions match how your firm actually books things. This happens inside your own workspace only.Legitimate interest in delivering an accurate service, and performance of our contract.
Keeping the service secure and available: authentication, access control, logging, abuse and fraud prevention, and diagnosing faults.Legitimate interest in the security of our service, and our legal obligation to secure personal data.
Metering and billing: recording which features ran and how much model capacity they used.Performance of our contract, and our legal obligation to keep accounting records.
Support and service communications: responding to your requests and notifying you about changes that affect you.Performance of our contract, and legitimate interest in supporting our users.
Sending you information about Counzel after you asked us to, and following up on a trial request.Your consent, which you can withdraw at any time.
Meeting our own legal obligations, and establishing or defending legal claims.Legal obligation, and legitimate interest.

What we do not do

  • We do not sell, rent or trade your data, and we do not share it for anyone else's advertising.
  • We do not use your content, your documents or your ledger to train foundation models. The AI models we use are consumed as enterprise services whose terms prohibit the provider from training on customer content.
  • We do not pool your data with another customer's. What Counzel learns from your corrections stays in your workspace and is never used to answer someone else's question.
  • We do not take automated decisions producing legal effects about you. Counzel proposes; a person approves. Nothing is posted or filed without a human decision.

5. Who we share it with

We use a small number of service providers to run Counzel. Each one is bound by a written contract, may process your data only on our instructions, and is listed below with the reason and the data involved.

ProviderWhyData involvedWhere
Microsoft AzureApplication hosting, database, file and secret storage, search index, and the AI models that power the assistant.All categories described in section 2.European Union (France Central) for hosting and storage. Some model inference runs on Azure OpenAI global deployments, which may process the prompt outside the EEA.
ClerkSign-in, session management and account security.Account and identity data only. No accounting data.United States, under standard contractual clauses.
BrevoSending transactional and notification email.Name and email address, and the content of the message sent to you.European Union.
GitHubSource control and our deployment pipeline.No customer data. Application code only.United States, under standard contractual clauses.
Your own AI providerOnly if you choose to supply your own model key instead of using ours.The content of the requests that model handles.As set by that provider, under your own agreement with them.

Your accounting system provider — for example Odoo or Exact Online — is not our sub-processor. You hold that relationship directly, and their own privacy policy governs the data held there. Counzel exchanges data with them only over the connection you authorise: we read the accounting records the service needs, and we write back drafts, codings and postings that you approve.

We disclose data to public authorities only where a valid legal obligation requires it, and we will tell you unless we are legally barred from doing so. If our business is ever transferred, your data may transfer with it, and you will be informed beforehand.

6. Transfers outside the EEA

Counzel is hosted in the European Union, in Microsoft's France Central region, and your accounting data is stored there. Two transfers outside the European Economic Area can occur, both covered by the European Commission's standard contractual clauses and by the provider's own data protection terms:

  • Sign-in and session data is handled by our authentication provider in the United States.
  • Some assistant requests are answered by Azure OpenAI global deployments, meaning the text of that request may be processed outside the EEA. The provider is contractually prohibited from retaining it for training.

You can ask us for a copy of the safeguards that apply to these transfers.

7. How long we keep it, and when we delete it

We keep each category only for as long as it serves the purpose it was collected for, then delete it. Deletion removes the data from our live systems immediately and from our encrypted backups within a further seven days, after which the backup itself expires.

DataRetention period
Account and identity dataFor as long as your account exists, then thirty days after it is closed.
Accounting data, review state and learned coding patternsFor as long as your subscription is active. Deleted within thirty days of the subscription ending, or within thirty days of your deletion request, whichever comes first.
Documents and extracted textTwenty-four months from processing, or sooner on request. The original document remains in your own accounting system, which we do not control.
Assistant conversationsTwenty-four months, or until you delete them yourself.
Usage and metering recordsTwenty-four months, so that billing can be audited.
Server and security logsThirty days.
Connection credentialsUntil you disconnect the accounting system or remove the key. Deleted immediately on disconnection.
Prospect and contact form dataTwenty-four months from our last contact with you, or immediately if you ask us to remove it.
Our own invoices and accounting records relating to youSeven years, as Belgian accounting and tax law requires.

Deleting your Counzel account does not delete anything inside your own accounting system. Entries that Counzel posted there remain your records, under your control, and you delete them there if you wish to.

8. Your rights, withdrawing consent, and deleting your data

Some of this you can do yourself, immediately, inside the application:

  • Delete a conversation: any Counzelor conversation can be deleted from the conversation list, at any time.
  • Withdraw marketing consent: use the unsubscribe link in any email we send, or write to us. Withdrawing consent does not affect processing that already took place.

Everything else — including disconnecting your accounting system so that we stop reading from it, and erasing the data we hold about a particular company — is done by writing to us at the address in the final section. We act on it promptly and confirm when it is done. You have the following rights under the General Data Protection Regulation:

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of data that is wrong or incomplete.
  • Erasure — deletion of your data, subject only to records we are legally obliged to keep.
  • Restriction — a pause on processing while a dispute is resolved.
  • Portability — your data in a structured, commonly used, machine-readable format.
  • Objection — to processing based on our legitimate interests, and at any time to direct marketing.
  • Withdrawal of consent — at any time, where consent is the basis we rely on.

We answer within one month and never charge for it. If you are not satisfied, you can lodge a complaint with the Belgian Data Protection Authority — Autorité de protection des données / Gegevensbeschermingsautoriteit, Rue de la Presse 35, 1000 Brussels, [email protected] — or with the supervisory authority where you live.

10. How we protect it

  • Data is encrypted in transit with TLS 1.2 or better, and encrypted at rest by the storage platform.
  • Connection keys and other secrets are held in a managed key vault, reached through a workload identity. They are never written into source code, and never displayed back to you once saved.
  • Access to the application requires an authenticated account; administrative surfaces require an additional server-side role that a user cannot grant themselves.
  • Each workspace is isolated: every query is scoped to the company you are working on, so one customer's data is not reachable from another's session.
  • Access to production systems is limited to the people who need it, over accounts protected by multi-factor authentication.
  • Every change to the service goes through version control and a reviewed pull request, and the automated test suite must pass before it can be deployed.
  • Physical security of the data centres is Microsoft's responsibility under its own audited controls; we operate no hardware of our own.

If a personal data breach ever affects you, we will notify the Belgian Data Protection Authority within seventy-two hours and tell you directly where the breach is likely to present a high risk to you.

11. Cookies

We use strictly necessary cookies only: one to keep you signed in, one to remember your interface language, and one to remember which company you were last working on. They are required for the service to function, so no consent banner is shown.

We run no advertising cookies, no third-party analytics and no tracking pixels on this site or in the application.

12. Changes to this policy

When we change this policy we publish the new text here with a new version number and date. For material changes we also tell you by email and ask you to accept the new version the next time you open the application.

13. Contact us

For any question about this policy, to exercise a right, or to ask for a data processing agreement, write to us. We reply within one working day and, for formal requests, within one month.

Turing of Trust SRL
Rue Sainte Renelde 47, 1430 Rebecq, Belgium
BE 0805.507.992
[email protected]