Privacyverklaring AGTT SmartSuite
Hoe de Excel-invoegtoepassing AGTT SmartSuite met gegevens omgaat: wat in uw werkmap blijft, wat naar Microsoft Azure gaat en wat AGTT zelf bewaart.
1Inleiding#
AGTT SmartSuite (hierna: SmartSuite) is een invoegtoepassing (add-in) voor Microsoft Excel van AGTT. SmartSuite is een professioneel hulpmiddel voor accountants- en auditkantoren. Deze verklaring beschrijft welke gegevens SmartSuite verwerkt, waarom, waar en hoe lang.
SmartSuite bestaat uit deze onderdelen:
- Documentation en Questions
- Werkprogramma's documenteren en klantvragen bijhouden.
- Data Integrity
- Controles op de volledigheid en juistheid van gegevens in de werkmap.
- Test of Details
- Een selectie toetsen aan facturen, met uitlezen van facturen en AI-voorstellen per stap.
- Sampling
- Steekproeven opzetten, trekken en evalueren (euro-, posten- en SRA-steekproef).
- SmartTie
- Rekenkundige en onderlinge aansluitingen in een jaarrekening controleren.
- DocSense Snap en Sense
- Documenten bekijken, waarden aan cellen koppelen (Snap) en documenten laten uitlezen (Sense).
- Snelkoppelingen
- Knoppen in het lint, onder meer om de klantmap op OneDrive of SharePoint te openen.
Technisch bestaat SmartSuite uit de add-in, die in Excel draait, en de SmartSuite-API. De API is een server van AGTT in Microsoft Azure. De add-in gebruikt de API alleen voor aanmelding en licentie, voor het uitlezen van documenten, voor AI-beoordelingen en voor de koppeling met OneDrive of SharePoint.
2Wie is verantwoordelijk?#
- AGTT is verwerkingsverantwoordelijke voor account- en licentiegegevens, gebruiksgegevens (tellers), technische logboeken en contact met u (bijvoorbeeld bij vragen of facturen).
- AGTT is verwerker voor de documenten en gegevens die u, in opdracht van uw kantoor, laat uitlezen of beoordelen (artikel 3.2 tot en met 3.4). Uw kantoor is daarvoor verwerkingsverantwoordelijke. AGTT verwerkt die gegevens alleen om de functie uit te voeren waar u om vraagt. De verwerkersovereenkomst van AGTT is een bijlage bij de Algemene Licentievoorwaarden en geldt ook voor dit gebruik; op verzoek ondertekenen wij een afzonderlijk exemplaar.
- Gegevens in uw werkmap verwerkt AGTT niet. Die beheert uw kantoor zelf.
- Bedrijfsnaam
- AGTT B.V. (KvK 82713111)
- Adres
- Lange Kleiweg 14, Unit 1.15
2288 GK Rijswijk - info@agtt.nl
- Website
- www.agtt.nl
3Welke gegevens en waarom#
3.1In uw werkmap#
- Wat u in SmartSuite vastlegt, komt in tabellen en bladen in de werkmap zelf. Denk aan documentatie, antwoorden, klantvragen, steekproeven, beoordelingen, koppelingen tussen documenten en cellen, en de uitkomsten van uitgelezen documenten. De taal van de add-in staat in een documenteigenschap.
- Deze gegevens staan waar uw werkmap staat: op uw computer, op OneDrive of op SharePoint. AGTT heeft er geen toegang toe.
- Documenten (pdf of afbeelding) die u toevoegt, kunt u in de werkmap zelf bewaren, of in een map die u koppelt (artikel 3.2).
- Snap toont documenten en herkent tekst (OCR) op uw eigen computer. Daarvoor gaat niets naar AGTT of Microsoft Azure.
3.2Koppeling met OneDrive of SharePoint#
- U kunt een OneDrive- of SharePoint-map aan een werkmap koppelen om documenten daar te bewaren. Een knop in het lint opent de klantmap.
- Hiervoor vraagt SmartSuite via uw Microsoft-aanmelding deze rechten:
openid,profileenUser.Read(aanmelden),Files.Read.AllenSites.Read.All(mappen en documenten lezen), enFiles.ReadWrite.AllenSites.ReadWrite.All(documenten opslaan in de gekoppelde map). - SmartSuite gebruikt deze rechten alleen om de mappen te tonen die u doorbladert, de klantmap te openen, en de documenten te lezen, op te slaan of terug te halen die u zelf kiest. Andere bestanden opent of wijzigt SmartSuite niet.
- De verzoeken lopen namens u via de SmartSuite-API naar Microsoft Graph. Het toegangstoken voor Microsoft Graph blijft op de server en wordt niet bewaard. Documenten gaan door de API heen, maar de API bewaart ze niet.
3.3Documenten laten uitlezen#
- Kiest u in Sense, Test of Details of SmartTie voor uitlezen, herkennen of analyseren, dan stuurt SmartSuite het document via de SmartSuite-API naar Microsoft Azure:
- Azure AI Document Intelligence (regio West-Europa) voor facturen, bonnen en tabellen;
- Azure AI Content Understanding (regio Zweden Centraal) voor de tabellen van een jaarrekening (SmartTie). Lukt dat niet, dan gebruikt SmartTie Document Intelligence.
- Het resultaat (tekst, bedragen, posities op de pagina) komt terug en wordt in uw werkmap bewaard.
- Documenten kunnen persoonsgegevens bevatten, zoals namen, adressen en rekeningnummers op facturen.
- AGTT bewaart de documenten en de uitkomsten niet op eigen servers. Microsoft verwerkt ze volgens de voorwaarden van Azure en gebruikt ze niet om modellen te trainen. Microsoft bewaart het document en het analyseresultaat tijdelijk in dezelfde regio, zodat de API het kan ophalen, en verwijdert beide automatisch na 24 uur.
3.4AI-beoordeling (Test of Details)#
- Voor de AI-stappen in Test of Details (tenaamstelling, crediteur, grootboekrekening en toerekening aan het boekjaar) stuurt SmartSuite via de SmartSuite-API gegevens naar Azure OpenAI (model gpt-5-mini, regio Zweden Centraal).
- Het gaat alleen om de velden die een stap nodig heeft: de omschrijving en de tenaamstelling van de factuur, de crediteur op de factuur, de factuurdatum, en uit de selectie de grootboekrekening, de geboekte tegenpartij, de naam van de gecontroleerde entiteit en het boekjaar. Het document zelf gaat niet mee.
- Het oordeel komt terug in de pane als voorstel. De AI geeft nooit zelf akkoord. Bij twijfel, ontbrekende gegevens of een storing wordt de stap "te controleren". De auditor beslist.
- Microsoft gebruikt deze gegevens niet om modellen te trainen. Voor misbruikbewaking kan Microsoft vragen en antwoorden tot 30 dagen bewaren in de regio van de dienst (EU); alleen bij een vermoeden van misbruik kan een medewerker van Microsoft in de EER ze inzien.
3.5Aanmelding en licentie#
- SmartSuite gebruikt uw Microsoft 365-aanmelding (single sign-on). U hoeft niet apart in te loggen.
- De API leest uit het aanmeldtoken van Microsoft uw e-mailadres, uw gebruikers-ID en de ID van uw organisatie (tenant). Het token bevat ook uw naam; die slaan wij niet op. De add-in houdt het token alleen in het geheugen.
- Met deze gegevens controleert de API of u een licentie hebt voor Snap en Sense. De andere onderdelen vragen geen licentie.
- De licentiegegevens bewaart AGTT in Azure Table Storage (regio West-Europa): e-mailadres, of Snap en Sense aan staan, de einddata, de status, de datum van toekennen, wie toekende en eventueel een notitie (bijvoorbeeld de naam van het kantoor of een factuurnummer).
3.6Gebruik tellen en limieten#
- Uitlezen en AI-beoordelingen kosten AGTT geld per pagina of aanroep. Daarom telt de API het gebruik per gebruiker en per organisatie, per dag en per maand.
- Wij slaan op: uw gebruikers-ID, uw e-mailadres, de ID van uw organisatie, uw gebruikstier, en per dienst het aantal aanroepen, pagina's, documenten en AI-tekstdelen (tokens), het aantal geweigerde aanroepen en het eerste en laatste gebruik.
- Wij slaan geen documentinhoud en geen bestandsnamen op.
- Boven de limiet van uw licentie krijgt u een melding en is de functie tijdelijk niet beschikbaar.
3.7Technische logboeken#
- De API houdt technische logboeken bij in Azure Application Insights: tijdstip, aangeroepen functie, duur, foutcode, een gebruikers-ID en de verbruikstellers uit artikel 3.6.
- Er staat geen documentinhoud in en er staan geen aanmeld- of toegangstokens in.
- Wij gebruiken de logboeken om storingen op te lossen en misbruik op te sporen.
3.8Voorkeuren in de add-in#
- De add-in onthoudt enkele voorkeuren in de lokale opslag (localStorage) van Excel op uw apparaat, zoals de taal en de laatst gekozen weergave. Die gegevens verlaten uw apparaat niet.
- De add-in plaatst zelf geen cookies en gebruikt geen analyse- of trackingdiensten.
- Bij het openen laadt de add-in programmabestanden van
smartsuite.agtt.nl(Microsoft Azure), van Microsoft (Office.js) en van twee openbare CDN's:cdnjs.cloudflare.com(pdf-viewer PDF.js) encdn.jsdelivr.net(tekstherkenning Tesseract). Zoals bij elke webpagina zien deze partijen uw IP-adres en browsergegevens. Er gaat geen documentinhoud of werkmapgegeven naar toe.
4Doeleinden en rechtsgronden#
| Verwerking | Doel | Grondslag (AVG) |
|---|---|---|
| Gegevens in uw werkmap (3.1) | De functies van de add-in | Niet van toepassing: AGTT verwerkt deze gegevens niet |
| OneDrive- of SharePoint-koppeling (3.2) | Documenten openen en opslaan in de gekoppelde map | AGTT is verwerker voor uw kantoor (art. 28); uw kantoor bepaalt de grondslag |
| Documenten uitlezen (3.3) | Tekst, bedragen en tabellen uit documenten halen | AGTT is verwerker voor uw kantoor (art. 28); uw kantoor bepaalt de grondslag |
| AI-beoordeling (3.4) | Een voorstel doen voor een controlestap | AGTT is verwerker voor uw kantoor (art. 28); uw kantoor bepaalt de grondslag |
| Aanmelding en licentie (3.5) | Toegang tot Snap en Sense; beveiliging van de API | Uitvoering van de overeenkomst (art. 6 lid 1 sub b) |
| Gebruik tellen (3.6) | Kosten beheersen, limieten per licentie toepassen, misbruik voorkomen | Gerechtvaardigd belang (art. 6 lid 1 sub f) |
| Technische logboeken (3.7) | Storingen oplossen en de dienst beveiligen | Gerechtvaardigd belang (art. 6 lid 1 sub f) |
| Licentie- en factuuradministratie | Administratie en fiscale bewaarplicht | Wettelijke verplichting (art. 6 lid 1 sub c) |
| Contact en ondersteuning | Uw vragen beantwoorden | Uitvoering van de overeenkomst of gerechtvaardigd belang (art. 6 lid 1 sub b of f) |
| Voorkeuren in de add-in (3.8) | Uw instellingen onthouden | Gerechtvaardigd belang (art. 6 lid 1 sub f); alleen functionele opslag |
5Ontvangers en subverwerkers#
Onze enige subverwerker is Microsoft Ireland Operations Ltd. (Microsoft Azure). Microsoft verwerkt de gegevens volgens de Microsoft Products and Services Data Protection Addendum.
| Azure-dienst | Waarvoor | Regio |
|---|---|---|
| Azure AI Document Intelligence | Facturen, bonnen en tabellen uitlezen (3.3) | West-Europa |
| Azure AI Content Understanding | Tabellen van een jaarrekening uitlezen (3.3) | Zweden Centraal |
| Azure OpenAI (gpt-5-mini) | AI-beoordeling in Test of Details (3.4) | Zweden Centraal |
| Azure Functions | De SmartSuite-API | Duitsland West-Centraal |
| Azure Table Storage | Licenties en gebruikstellers (3.5, 3.6) | West-Europa |
| Azure Application Insights | Technische logboeken (3.7) | Duitsland West-Centraal |
| Azure Storage en Azure Front Door | Programmabestanden van de add-in (smartsuite.agtt.nl) | West-Europa; Front Door levert via het wereldwijde netwerk van Microsoft |
Aanmelding (Microsoft Entra ID) en uw bestanden op OneDrive en SharePoint (Microsoft Graph) lopen via de Microsoft 365-omgeving van uw eigen organisatie. Daarvoor is Microsoft de leverancier van uw organisatie, niet van AGTT.
Cloudflare (cdnjs) en jsDelivr leveren alleen programmabestanden (artikel 3.8). Zij ontvangen geen documentinhoud of werkmapgegevens.
Wij delen geen gegevens met andere partijen, tenzij de wet ons daartoe verplicht.
6Doorgifte buiten de EER#
- AGTT geeft geen persoonsgegevens door naar landen buiten de Europese Economische Ruimte (EER).
- Alle Azure-resources van SmartSuite staan in EU-regio's: West-Europa, Zweden Centraal en Duitsland West-Centraal.
- Microsoft bewaart deze gegevens in de Azure-regio's in de EU uit de tabel hierboven en verwerkt ze binnen de EU Data Boundary. Azure Front Door levert alleen de programmabestanden van de add-in, via het wereldwijde netwerk van Microsoft; daarbij gaat alleen uw IP-adres mee, geen inhoud.
- De CDN's uit artikel 3.8 kunnen programmabestanden leveren vanaf servers buiten de EER. Daarbij gaat alleen uw IP-adres mee, geen inhoud.
7Beveiliging#
- Alle verbindingen zijn versleuteld (HTTPS/TLS).
- U meldt zich aan via het Microsoft-identiteitsplatform. De API controleert bij elke aanroep of het token echt van Microsoft komt, voor SmartSuite bedoeld is en niet verlopen is.
- De sleutels voor de Azure-diensten staan alleen op de server. Ze zitten niet in de add-in.
- AGTT bewaart geen documenten en geen uitkomsten van analyses. Het toegangstoken voor Microsoft Graph blijft op de server en wordt niet bewaard.
- Microsoft Azure is onder meer gecertificeerd volgens ISO 27001 en SOC 2.
- Uw werkmap wordt beschermd door uw eigen omgeving: Excel, OneDrive of SharePoint en de maatregelen van uw organisatie.
- Bij een datalek handelen wij volgens de AVG en informeren wij uw kantoor zonder onredelijke vertraging.
8Bewaartermijnen#
| Gegevens | Bewaartermijn |
|---|---|
| Gegevens in uw werkmap, ook uitgelezen resultaten | Zolang u de werkmap bewaart. AGTT heeft geen kopie. |
| Documenten in een gekoppelde OneDrive- of SharePoint-map | Zoals uw organisatie bepaalt. AGTT heeft geen kopie. |
| Documenten die u laat uitlezen | AGTT: niet bewaard. Microsoft: document en analyseresultaat automatisch verwijderd na 24 uur. |
| Gegevens voor een AI-beoordeling | AGTT: niet bewaard. Microsoft: tot 30 dagen voor misbruikbewaking. |
| Licentiegegevens | Zolang de licentie loopt, daarna 7 jaar (fiscale bewaarplicht). |
| Gebruikstellers | 24 maanden; daarna verwijderd. |
| Technische logboeken | 90 dagen; daarna automatisch verwijderd. |
| Voorkeuren in de add-in | Tot u ze wist of de add-in verwijdert. |
9Wat wij niet doen#
- Wij verkopen geen gegevens.
- Wij plaatsen geen advertenties, trackers of analysecookies in de add-in.
- Wij laten geen AI-modellen trainen op uw documenten of gegevens.
- Wij lezen niet mee in uw werkmappen.
- Wij nemen geen besluiten over personen die alleen op automatische verwerking berusten. De AI doet voorstellen; de auditor beslist.
10Uw rechten#
U hebt het recht op:
- inzage in de gegevens die wij van u verwerken;
- correctie van onjuiste gegevens;
- verwijdering van uw gegevens;
- beperking van de verwerking;
- overdraagbaarheid van uw gegevens;
- bezwaar tegen verwerking op grond van gerechtvaardigd belang.
Stuur uw verzoek naar info@agtt.nl. Wij reageren binnen een maand. Wij kunnen u vragen om uw identiteit te bevestigen.
Gaat uw verzoek over documenten of gegevens die wij als verwerker voor uw kantoor verwerken (artikel 2)? Richt het dan aan uw kantoor. Wij helpen uw kantoor daarbij.
11Autoriteit Persoonsgegevens#
Bent u het niet eens met hoe wij met uw gegevens omgaan? Neem dan eerst contact met ons op. U kunt ook een klacht indienen bij de Autoriteit Persoonsgegevens.
- Website
- www.autoriteitpersoonsgegevens.nl
- Telefoon
- 088 - 1805 250
- Postadres
- Postbus 93374
2509 AJ Den Haag
12Wijzigingen#
Wij kunnen deze verklaring aanpassen, bijvoorbeeld als SmartSuite verandert. De datum bovenaan laat zien welke versie geldt. Belangrijke wijzigingen melden wij in de add-in of per e-mail aan licentiehouders.
Vorige versie: november 2024.
13Contact#
Vragen over deze verklaring of over uw gegevens? Neem contact op:
- Bedrijfsnaam
- AGTT B.V. (KvK 82713111)
- info@agtt.nl
- Website
- www.agtt.nl
- Adres
- Lange Kleiweg 14, Unit 1.15
2288 GK Rijswijk
Privacy policy AGTT SmartSuite
How the AGTT SmartSuite add-in for Excel handles data: what stays in your workbook, what goes to Microsoft Azure and what AGTT itself keeps.
1Introduction#
AGTT SmartSuite ("SmartSuite") is an add-in for Microsoft Excel made by AGTT. SmartSuite is a professional tool for accounting and audit firms. This policy describes which data SmartSuite processes, why, where and for how long.
SmartSuite consists of these parts:
- Documentation and Questions
- Document audit programmes and keep track of client questions.
- Data Integrity
- Checks on the completeness and accuracy of data in the workbook.
- Test of Details
- Test a selection against invoices, with invoice reading and AI proposals per step.
- Sampling
- Set up, draw and evaluate samples (monetary unit, non-statistical and SRA sampling model).
- SmartTie
- Check the arithmetic and the consistency between statements in annual reports.
- DocSense Snap and Sense
- View documents, link values to cells (Snap) and have documents read (Sense).
- Shortcuts
- Ribbon buttons, among others to open the client folder on OneDrive or SharePoint.
Technically, SmartSuite consists of the add-in, which runs in Excel, and the SmartSuite API. The API is an AGTT server in Microsoft Azure. The add-in uses the API only for sign-in and licensing, for reading documents, for AI assessments and for the link with OneDrive or SharePoint.
2Who is responsible?#
- AGTT is the controller for account and licence data, usage data (counters), technical logs and contact with you (for example questions or invoices).
- AGTT is a processor for the documents and data that you, on behalf of your firm, have read or assessed (sections 3.2 to 3.4). Your firm is the controller for those. AGTT processes them only to perform the function you ask for. AGTT's data processing agreement is an annex to the General Licence Terms and also applies to this use; on request we sign a separate copy.
- Data in your workbook is not processed by AGTT. Your firm manages it.
- Company name
- AGTT B.V. (Chamber of Commerce no. 82713111)
- Address
- Lange Kleiweg 14, Unit 1.15
2288 GK Rijswijk
The Netherlands - info@agtt.nl
- Website
- www.agtt.nl
3What data and why#
3.1In your workbook#
- What you record in SmartSuite is stored in tables and sheets in the workbook itself: documentation, answers, client questions, samples, reviews, links between documents and cells, and the results of documents that were read. The add-in language is stored in a document property.
- This data is wherever your workbook is: on your computer, on OneDrive or on SharePoint. AGTT has no access to it.
- Documents (PDF or image) that you add can be kept in the workbook itself, or in a folder that you link (section 3.2).
- Snap displays documents and recognises text (OCR) on your own computer. Nothing is sent to AGTT or Microsoft Azure for this.
3.2Link with OneDrive or SharePoint#
- You can link a OneDrive or SharePoint folder to a workbook to keep documents there. A ribbon button opens the client folder.
- For this, SmartSuite requests these permissions through your Microsoft sign-in:
openid,profileandUser.Read(sign-in),Files.Read.AllandSites.Read.All(read folders and documents), andFiles.ReadWrite.AllandSites.ReadWrite.All(save documents in the linked folder). - SmartSuite uses these permissions only to show the folders you browse, to open the client folder, and to read, save or move back the documents you choose. It does not open or change any other files.
- The requests go on your behalf through the SmartSuite API to Microsoft Graph. The Microsoft Graph access token stays on the server and is not stored. Documents pass through the API, but the API does not keep them.
3.3Having documents read#
- When you choose to read, recognise or analyse in Sense, Test of Details or SmartTie, SmartSuite sends the document through the SmartSuite API to Microsoft Azure:
- Azure AI Document Intelligence (West Europe region) for invoices, receipts and tables;
- Azure AI Content Understanding (Sweden Central region) for the tables of an annual report (SmartTie). If that fails, SmartTie uses Document Intelligence.
- The result (text, amounts, positions on the page) comes back and is stored in your workbook.
- Documents may contain personal data, such as names, addresses and bank account numbers on invoices.
- AGTT does not keep the documents or the results on its own servers. Microsoft processes them under the Azure terms and does not use them to train models. Microsoft keeps the document and the analysis result temporarily in the same region so that the API can retrieve them, and deletes both automatically after 24 hours.
3.4AI assessment (Test of Details)#
- For the AI steps in Test of Details (addressee, creditor, general ledger account and allocation to the financial year), SmartSuite sends data through the SmartSuite API to Azure OpenAI (model gpt-5-mini, Sweden Central region).
- Only the fields a step needs are sent: the description and the addressee of the invoice, the creditor on the invoice, the invoice date, and from the selection the general ledger account, the booked counterparty, the name of the audited entity and the financial year. The document itself is not sent.
- The assessment comes back to the pane as a proposal. The AI never approves on its own. In case of doubt, missing data or an error, the step becomes "to be checked". The auditor decides.
- Microsoft does not use this data to train models. For abuse monitoring, Microsoft may keep prompts and responses for up to 30 days in the service region (EU); only when abuse is suspected may a Microsoft employee in the EEA review them.
3.5Sign-in and licence#
- SmartSuite uses your Microsoft 365 sign-in (single sign-on). You do not need to sign in separately.
- From the Microsoft sign-in token, the API reads your e-mail address, your user ID and your organisation's ID (tenant). The token also contains your name; we do not store it. The add-in keeps the token in memory only.
- With this data the API checks whether you have a licence for Snap and Sense. The other parts need no licence.
- AGTT keeps the licence data in Azure Table Storage (West Europe region): e-mail address, whether Snap and Sense are enabled, end dates, status, date of assignment, who assigned it, and an optional note (for example the firm's name or an invoice number).
3.6Usage metering and limits#
- Reading documents and AI assessments cost AGTT money per page or call. The API therefore counts usage per user and per organisation, per day and per month.
- We store: your user ID, your e-mail address, your organisation's ID, your usage tier, and per service the number of calls, pages, documents and AI text units (tokens), the number of refused calls, and first and last use.
- We do not store document content or file names.
- Above the limit of your licence, you get a message and the function is temporarily unavailable.
3.7Technical logs#
- The API keeps technical logs in Azure Application Insights: time, function called, duration, error code, a user ID and the usage counters from section 3.6.
- The logs contain no document content and no sign-in or access tokens.
- We use the logs to resolve errors and to detect misuse.
3.8Preferences in the add-in#
- The add-in remembers a few preferences in Excel's local storage (localStorage) on your device, such as the language and the last view you chose. This data does not leave your device.
- The add-in itself sets no cookies and uses no analytics or tracking services.
- When it opens, the add-in loads program files from
smartsuite.agtt.nl(Microsoft Azure), from Microsoft (Office.js) and from two public CDNs:cdnjs.cloudflare.com(PDF viewer PDF.js) andcdn.jsdelivr.net(text recognition Tesseract). As with any web page, these parties see your IP address and browser details. No document content or workbook data is sent to them.
4Purposes and legal bases#
| Processing | Purpose | Legal basis (GDPR) |
|---|---|---|
| Data in your workbook (3.1) | The functions of the add-in | Not applicable: AGTT does not process this data |
| OneDrive or SharePoint link (3.2) | Open and save documents in the linked folder | AGTT is a processor for your firm (Art. 28); your firm determines the legal basis |
| Reading documents (3.3) | Extract text, amounts and tables from documents | AGTT is a processor for your firm (Art. 28); your firm determines the legal basis |
| AI assessment (3.4) | Propose an outcome for an audit step | AGTT is a processor for your firm (Art. 28); your firm determines the legal basis |
| Sign-in and licence (3.5) | Access to Snap and Sense; security of the API | Performance of the contract (Art. 6(1)(b)) |
| Usage metering (3.6) | Control costs, apply limits per licence, prevent misuse | Legitimate interest (Art. 6(1)(f)) |
| Technical logs (3.7) | Resolve errors and secure the service | Legitimate interest (Art. 6(1)(f)) |
| Licence and invoice records | Bookkeeping and statutory tax retention | Legal obligation (Art. 6(1)(c)) |
| Contact and support | Answer your questions | Performance of the contract or legitimate interest (Art. 6(1)(b) or (f)) |
| Preferences in the add-in (3.8) | Remember your settings | Legitimate interest (Art. 6(1)(f)); functional storage only |
5Recipients and sub-processors#
Our only sub-processor is Microsoft Ireland Operations Ltd. (Microsoft Azure). Microsoft processes the data under the Microsoft Products and Services Data Protection Addendum.
| Azure service | Used for | Region |
|---|---|---|
| Azure AI Document Intelligence | Reading invoices, receipts and tables (3.3) | West Europe |
| Azure AI Content Understanding | Reading the tables of annual reports (3.3) | Sweden Central |
| Azure OpenAI (gpt-5-mini) | AI assessment in Test of Details (3.4) | Sweden Central |
| Azure Functions | The SmartSuite API | Germany West Central |
| Azure Table Storage | Licences and usage counters (3.5, 3.6) | West Europe |
| Azure Application Insights | Technical logs (3.7) | Germany West Central |
| Azure Storage and Azure Front Door | Program files of the add-in (smartsuite.agtt.nl) | West Europe; Front Door delivers through Microsoft's global network |
Sign-in (Microsoft Entra ID) and your files on OneDrive and SharePoint (Microsoft Graph) run through your own organisation's Microsoft 365 environment. For these, Microsoft is your organisation's provider, not AGTT's.
Cloudflare (cdnjs) and jsDelivr only deliver program files (section 3.8). They receive no document content or workbook data.
We do not share data with other parties, unless the law requires us to.
6Transfers outside the EEA#
- AGTT does not transfer personal data to countries outside the European Economic Area (EEA).
- All SmartSuite Azure resources are in EU regions: West Europe, Sweden Central and Germany West Central.
- Microsoft stores this data in the EU Azure regions listed in the table above and processes it within the EU Data Boundary. Azure Front Door only delivers the add-in's program files, through Microsoft's global network; only your IP address is involved, no content.
- The CDNs in section 3.8 may deliver program files from servers outside the EEA. Only your IP address is involved, no content.
7Security#
- All connections are encrypted (HTTPS/TLS).
- You sign in through the Microsoft identity platform. On every call, the API checks that the token comes from Microsoft, is meant for SmartSuite and has not expired.
- The keys for the Azure services are kept on the server only. They are not in the add-in.
- AGTT does not keep documents or analysis results. The Microsoft Graph access token stays on the server and is not stored.
- Microsoft Azure is certified under, among others, ISO 27001 and SOC 2.
- Your workbook is protected by your own environment: Excel, OneDrive or SharePoint, and your organisation's measures.
- In the event of a data breach, we act in accordance with the GDPR and inform your firm without undue delay.
8Retention periods#
| Data | Retention |
|---|---|
| Data in your workbook, including results of reading | As long as you keep the workbook. AGTT has no copy. |
| Documents in a linked OneDrive or SharePoint folder | As your organisation decides. AGTT has no copy. |
| Documents you have read | AGTT: not kept. Microsoft: document and analysis result deleted automatically after 24 hours. |
| Data for an AI assessment | AGTT: not kept. Microsoft: up to 30 days for abuse monitoring. |
| Licence data | For the term of the licence, then 7 years (statutory tax retention). |
| Usage counters | 24 months; then deleted. |
| Technical logs | 90 days; then deleted automatically. |
| Preferences in the add-in | Until you clear them or remove the add-in. |
9What we do not do#
- We do not sell data.
- We place no ads, trackers or analytics cookies in the add-in.
- We do not have AI models trained on your documents or data.
- We do not read your workbooks.
- We take no decisions about individuals based solely on automated processing. The AI makes proposals; the auditor decides.
10Your rights#
You have the right to:
- access the data we process about you;
- have incorrect data corrected;
- have your data erased;
- restriction of processing;
- data portability;
- object to processing based on legitimate interest.
Send your request to info@agtt.nl. We respond within one month. We may ask you to confirm your identity.
Does your request concern documents or data that we process as a processor for your firm (section 2)? Then address it to your firm. We will assist your firm.
11Dutch Data Protection Authority#
If you disagree with how we handle your data, please contact us first. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
- Website
- www.autoriteitpersoonsgegevens.nl
- Telephone
- +31 88 1805 250
- Postal address
- Postbus 93374
2509 AJ Den Haag
The Netherlands
12Changes#
We may change this policy, for example when SmartSuite changes. The date at the top shows which version applies. We announce important changes in the add-in or by e-mail to licence holders.
Previous version: November 2024.
13Contact#
Questions about this policy or about your data? Please contact us:
- Company name
- AGTT B.V. (Chamber of Commerce no. 82713111)
- info@agtt.nl
- Website
- www.agtt.nl
- Address
- Lange Kleiweg 14, Unit 1.15
2288 GK Rijswijk
The Netherlands