Privacy Policy
This policy explains what data Counzel AI collects, how we collect it, why we use it, how long we keep it, and how you can withdraw your consent or have your data deleted.
1. Who we are
Counzel AI is an accounting and finance assistant for Belgian accounting firms and the companies they serve. It connects to your accounting system, drafts and codes purchase and sales invoices, runs your year-end close, prepares Belgian filings, and answers accounting and tax questions with sourced references.
Counzel AI is operated by Turing of Trust SRL, the data controller for the personal data described in this policy. You can reach us at any time using the contact details in the final section.
Where you are an accounting firm using Counzel to work on your clients' books, you remain the controller of your clients' data and we act as your processor, on your documented instructions. A data processing agreement is available on request.
2. What data we collect and keep
We collect only what the service needs in order to work. The categories below are exhaustive for the current product.
| Category | What it contains |
|---|---|
| Account and identity data | Your name, email address, sign-in credentials or single sign-on identity, profile image if you set one, session identifiers, interface language, and your role in the workspace. |
| Firm and company details | Your firm's name, enterprise or VAT number, address, fiscal-year settings, and the identity of each company you manage in Counzel — including information retrieved from public registers (see section 3). |
| Accounting and financial data | Data read from the accounting system you connect: general ledger entries and journals, purchase and sales invoices with their line detail, VAT figures, bank transactions, fixed-asset and depreciation schedules, and customer, supplier and partner records. Partner records can contain the name, address, enterprise or VAT number, email address and telephone number of individuals. |
| Documents and extracted text | Invoices, bills and attachments that are processed by the service, together with the text and structured fields extracted from them. |
| Assistant conversations | The questions you ask Counzelor, the answers returned with their sources, the review depth used, and which company the conversation concerned. |
| Review and correction history | Which review lane each draft sits in and why, the corrections you make to a proposed coding, and the per-client coding patterns learned from those corrections. |
| Connection credentials | The API key or authorisation token for your accounting system and, where you choose to supply your own, your AI provider key. These are held as secrets, not as ordinary application data. |
| Usage and technical data | Which feature was used, at what time, on behalf of which company, which model ran and how many tokens it consumed, plus server and application logs containing IP address, browser type and error diagnostics. |
| Prospect and contact data | If you use our contact or trial-registration forms: your name, email address, firm name, enterprise or VAT number, language, your message, and the fact and time of your consent. |
We do not collect special categories of personal data (such as health, biometric or political data), and we ask you not to submit them. We do not knowingly collect data about children; Counzel is a business service.
3. How we collect it
- Directly from you, when you create an account, complete onboarding, configure a company, upload a document, or write to us.
- From the accounting system you connect, through its official API, and only after you have explicitly authorised the connection. We read the data the service needs and write back only what you approve.
- Automatically as you use the service, through server and application logs and usage metering.
- From public sources, when you add a company: the Belgian Crossroads Bank for Enterprises (KBO/BCE) for legal identity and directorships, the National Bank of Belgium's Central Balance Sheet Office for filed annual accounts, and the Belgian Official Gazette for published company acts.
- From our authentication provider, which handles sign-in on our behalf and tells us who you are once you are signed in.
We do not buy personal data from data brokers, and we do not build profiles of you from sources outside the service.
4. Why we use it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the service: reading your ledger, drafting and coding invoices, running closings, preparing filings, and answering your questions. | Performance of our contract with you. |
| Improving accuracy for you: using your own past entries and corrections so that suggestions match how your firm actually books things. This happens inside your own workspace only. | Legitimate interest in delivering an accurate service, and performance of our contract. |
| Keeping the service secure and available: authentication, access control, logging, abuse and fraud prevention, and diagnosing faults. | Legitimate interest in the security of our service, and our legal obligation to secure personal data. |
| Metering and billing: recording which features ran and how much model capacity they used. | Performance of our contract, and our legal obligation to keep accounting records. |
| Support and service communications: responding to your requests and notifying you about changes that affect you. | Performance of our contract, and legitimate interest in supporting our users. |
| Sending you information about Counzel after you asked us to, and following up on a trial request. | Your consent, which you can withdraw at any time. |
| Meeting our own legal obligations, and establishing or defending legal claims. | Legal obligation, and legitimate interest. |
What we do not do
- We do not sell, rent or trade your data, and we do not share it for anyone else's advertising.
- We do not use your content, your documents or your ledger to train foundation models. The AI models we use are consumed as enterprise services whose terms prohibit the provider from training on customer content.
- We do not pool your data with another customer's. What Counzel learns from your corrections stays in your workspace and is never used to answer someone else's question.
- We do not take automated decisions producing legal effects about you. Counzel proposes; a person approves. Nothing is posted or filed without a human decision.
6. Transfers outside the EEA
Counzel is hosted in the European Union, in Microsoft's France Central region, and your accounting data is stored there. Two transfers outside the European Economic Area can occur, both covered by the European Commission's standard contractual clauses and by the provider's own data protection terms:
- Sign-in and session data is handled by our authentication provider in the United States.
- Some assistant requests are answered by Azure OpenAI global deployments, meaning the text of that request may be processed outside the EEA. The provider is contractually prohibited from retaining it for training.
You can ask us for a copy of the safeguards that apply to these transfers.
7. How long we keep it, and when we delete it
We keep each category only for as long as it serves the purpose it was collected for, then delete it. Deletion removes the data from our live systems immediately and from our encrypted backups within a further seven days, after which the backup itself expires.
| Data | Retention period |
|---|---|
| Account and identity data | For as long as your account exists, then thirty days after it is closed. |
| Accounting data, review state and learned coding patterns | For as long as your subscription is active. Deleted within thirty days of the subscription ending, or within thirty days of your deletion request, whichever comes first. |
| Documents and extracted text | Twenty-four months from processing, or sooner on request. The original document remains in your own accounting system, which we do not control. |
| Assistant conversations | Twenty-four months, or until you delete them yourself. |
| Usage and metering records | Twenty-four months, so that billing can be audited. |
| Server and security logs | Thirty days. |
| Connection credentials | Until you disconnect the accounting system or remove the key. Deleted immediately on disconnection. |
| Prospect and contact form data | Twenty-four months from our last contact with you, or immediately if you ask us to remove it. |
| Our own invoices and accounting records relating to you | Seven years, as Belgian accounting and tax law requires. |
Deleting your Counzel account does not delete anything inside your own accounting system. Entries that Counzel posted there remain your records, under your control, and you delete them there if you wish to.
8. Your rights, withdrawing consent, and deleting your data
Some of this you can do yourself, immediately, inside the application:
- Delete a conversation: any Counzelor conversation can be deleted from the conversation list, at any time.
- Withdraw marketing consent: use the unsubscribe link in any email we send, or write to us. Withdrawing consent does not affect processing that already took place.
Everything else — including disconnecting your accounting system so that we stop reading from it, and erasing the data we hold about a particular company — is done by writing to us at the address in the final section. We act on it promptly and confirm when it is done. You have the following rights under the General Data Protection Regulation:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of data that is wrong or incomplete.
- Erasure — deletion of your data, subject only to records we are legally obliged to keep.
- Restriction — a pause on processing while a dispute is resolved.
- Portability — your data in a structured, commonly used, machine-readable format.
- Objection — to processing based on our legitimate interests, and at any time to direct marketing.
- Withdrawal of consent — at any time, where consent is the basis we rely on.
We answer within one month and never charge for it. If you are not satisfied, you can lodge a complaint with the Belgian Data Protection Authority — Autorité de protection des données / Gegevensbeschermingsautoriteit, Rue de la Presse 35, 1000 Brussels, [email protected] — or with the supervisory authority where you live.
9. Consent
Before you can use Counzel, we ask you to read this policy and to confirm, by an explicit action, that you accept it and consent to the processing it describes. We record which version you accepted and when. If we make a material change, we ask you to accept the new version before you continue.
Consent to receive information about Counzel is asked separately, is never bundled with using the service, and is never a condition of it.
10. How we protect it
- Data is encrypted in transit with TLS 1.2 or better, and encrypted at rest by the storage platform.
- Connection keys and other secrets are held in a managed key vault, reached through a workload identity. They are never written into source code, and never displayed back to you once saved.
- Access to the application requires an authenticated account; administrative surfaces require an additional server-side role that a user cannot grant themselves.
- Each workspace is isolated: every query is scoped to the company you are working on, so one customer's data is not reachable from another's session.
- Access to production systems is limited to the people who need it, over accounts protected by multi-factor authentication.
- Every change to the service goes through version control and a reviewed pull request, and the automated test suite must pass before it can be deployed.
- Physical security of the data centres is Microsoft's responsibility under its own audited controls; we operate no hardware of our own.
If a personal data breach ever affects you, we will notify the Belgian Data Protection Authority within seventy-two hours and tell you directly where the breach is likely to present a high risk to you.
12. Changes to this policy
When we change this policy we publish the new text here with a new version number and date. For material changes we also tell you by email and ask you to accept the new version the next time you open the application.
13. Contact us
For any question about this policy, to exercise a right, or to ask for a data processing agreement, write to us. We reply within one working day and, for formal requests, within one month.