Skip to content

Security & privacy

Six questions, answered plainly. If you are about to put a client's documents into a tool run by a company you have not heard of, these are the things you are entitled to know first.

You do not have to trust us to find out whether this works. Try it with redacted, dummy or already-public documents. Nothing about the extraction changes, and you learn whether it is any good before a single real client record is involved. We would rather earn the sensitive work on the second batch.

1. What happens to my document?

It is stored, read by an optical character recognition model, and then structured into the columns you agreed before uploading. You get the result as Excel, CSV or SQL. That is the whole journey.

It is not reviewed by a human, not used to improve anything, and not looked at for any purpose other than producing your output.

2. Do you retain it?

Only for a fixed period, and the clock does not move. Uploaded files are deleted automatically 30 days after the job on Free, 90 days on Starter, 180 on Pro and 365 on Max.

The one exception is deliberate and yours: if you turn a saved design into a database that accumulates across batches, the extracted values stay until you delete them, because a database that forgets its oldest rows is not a database. That is an instruction you give, recorded with its date, and you can withdraw it at any time.

3. Is it used to train AI?

No. Worth being precise about, because this is where most answers get vague.

  • We have no training pipeline. We could not train on your documents if we wanted to.
  • Our extraction provider, Mistral, offers training as an opt-out for API customers rather than excluding it by default. We have opted out, so your content is excluded.
  • Cloudflare, whose model we fall back to if Mistral is down, state in their published terms that they do not train on customer content or use it to improve their services.

If a supplier tells you "we never train on your data" without mentioning what their own sub-processors do, that is the answer to press on.

4. Where is it processed and stored?

Storage is in the EU. Files sit in an EU-only bucket and the database is EU- constrained. Neither leaves.

Processing is more nuanced, and here is the honest version. Reading your document is done by Mistral, a French company that stores in the EU by default. We call their standard endpoint, for which they do not commit to a specific inference location, so a request may be processed outside the EEA. And if Mistral is unavailable we fall back to a Cloudflare model that runs on a global network and cannot be pinned to a region.

Both are covered by standard contractual clauses and the UK transfer addendum, and both are named with their mechanism on the sub-processors page. If EU-only processing is a hard requirement for your firm, ask us before you sign up rather than after.

5. Can I delete it?

Yes, from inside the app, at any time, without asking us. Here is exactly what that does.

  • The file and any converted copy leave storage immediately.
  • The extracted values are deleted, unless you asked for that database to be kept.
  • The filename is overwritten, because documents are often named after the person they describe.
  • A record that a job ran remains, holding its date and document count and nothing from inside the document, until you delete the job or close the account.

The caveat other suppliers leave out: our database platform keeps a restorable history for up to 30 days, and our extraction provider keeps API inputs for up to 30 days for abuse monitoring. Neither is reachable by us as a document. So deletion is immediate in every sense you can observe, and complete within 30 days.

6. Who can see it?

  • You, and anyone you invite onto your account. Everyone on a team shares one account and can see everything in it, so invite deliberately.
  • The automated sub-processors needed to do the work, named individually on the sub-processors page. No human at any of them reviews your documents.
  • Us, only when genuinely necessary, which means a support request you have raised or a live security incident. It is not routine, it is not for quality checking, and there is no team of reviewers, because there is no team.

Documents are reachable only by the account that owns them. Intake email addresses are random and unguessable, which is why you should treat one like a password and revoke it if it leaks.

The technical measures

  • TLS in transit, encryption at rest for files and database.
  • Each account's data is isolated and reachable only through its own authenticated session.
  • Sign-in by emailed link, passkey or password. No shared administrative password exists to be leaked.
  • Document contents and extracted values never appear in logs. Operational logs hold job identifiers, timings and errors.
  • Card details never reach our systems. Stripe hold them and we see only the outcome.
  • Rate limiting and a bot check on card entry, so that an abusive volume of requests cannot be pointed at the service or at you.

If you need paperwork for your file

The data processing agreement is already in force and needs no signature, though we will countersign a copy if your firm's procedures require one. The privacy notice carries the full detail behind every answer above. If your checklist asks whether the supplier is registered with the Information Commissioner's Office, we are, under reference ZC053711, and you can verify that on the ICO's public register rather than taking our word for it. For a security questionnaire, send it to hello@datanem.com and you will get answers from the person who wrote the code rather than from a sales team.

Datanem is a product of DATANEM LIMITED, a company registered in England and Wales, number 16870006. Registered office: 8 Court View, Clowne, Chesterfield, England, S43 4BU. Registered with the Information Commissioner's Office, reference ZC053711.