Docs Trust & support

DPIA and processing register

A DPIA and a record of processing activities ask for the same facts: what is processed, for what purpose, by whom, where and for how long. Those are below, in a form you can copy into your own documents. The shorter version, for anyone who just wants an answer, is on the security and data protection page.

This page is the current source. Where you can, refer to it from your own documents rather than copying the tables: if a subprocessor or a retention period changes, it is correct here straight away and your own documents do not go stale.

A DPIA remains your responsibility as the controller. SWIS cannot carry it out or sign it for you. What we do: supply all the input, in your own DPIA format. Request it through service@vragen.ai.

What vragen.ai does

A visitor asks a question in natural language. vragen.ai searches an index built from the sources you have designated, and has a language model formulate an answer based on the passages it finds, referring to the sources used. The system consults only your sources; it does not draw on general knowledge of the internet.

Administrators on your side work in an admin environment where they manage sources, set configuration and review the questions that were asked. Access runs through an account with two-factor authentication, which you can make mandatory per environment.

The processor is SWIS B.V., 3e Binnenvestgracht 23 T1, 2312 NR Leiden, the Netherlands, Chamber of Commerce number 28083445. You determine the legal basis for the processing yourself. For public sector organizations that is usually the performance of a public task: a public authority cannot rely on legitimate interests for its own tasks (Article 6(1) GDPR). Private organizations usually do rely on a legitimate interest.

The processing activities

Processing Purpose Data subjects Data Location
Answering questions Giving visitors an answer and pointing them to the right next step Visitors to the website The question that was asked; optionally a hashed IP address Amsterdam. With an external language model, that model runs inside the EU
Statistics and improvement Insight into frequently asked questions and gaps in the content, so the agent and the sources can be improved Visitors to the website The question asked and the answer given Amsterdam
Countering abuse Preventing automated abuse and overload Visitors to the website Hashed IP address, only if you enable that option Amsterdam
Managing the application Enabling administrators to manage sources, settings and answers Administrators of the controller Name, email address, IP address Leiden and Amsterdam

vragen.ai sets no cookies until a visitor starts a conversation; from that moment the widget sets three functional cookies (XSRF-TOKEN and vragenai-session, both valid for two hours, and ai-toc-accepted-this-session for the duration of the visit) to keep the chat working securely. They contain no personal data and are not used for tracking or analytics; as strictly necessary cookies for a function the visitor requested themselves, they fall under the legal exemption, so no consent is required for them. Vragen.ai asks visitors for no account and builds no profiles. Questions generally contain no personal data, but they can if a visitor enters it of their own accord.

Subprocessors

Subprocessor Chamber of Commerce Outsourced processing Location
TrueFullstaq B.V., Keienbergweg 100, Amsterdam 34131108 Hosting, infrastructure management, storage of the index and the questions asked, running the embedding models Amsterdam, the Netherlands
Sentry (Functional Software, Inc.) not applicable Technical error logging and monitoring of the application. Only technical error reports are sent; personal data is stripped out before sending EU instance, inside the EEA
Microsoft B.V., Evert van de Beekstraat 354, Schiphol 34061536 Running the language model when formulating answers, through Microsoft Azure. Microsoft can review questions on a concrete suspicion of abuse The Netherlands, France or Sweden, depending on the region chosen

With TrueFullstaq and with the provider of the language model you choose, SWIS has a data processing agreement in line with European guidelines. No transfer takes place to countries outside the European Economic Area; any transfer beyond it happens only with your prior written consent.

The first two rows always apply. The third applies only if you use an external language model, and Microsoft Azure is listed as the example because it is the most common route. If you choose a model that SWIS runs on its own infrastructure in the Netherlands, Microsoft drops away as a subprocessor. If you choose another large lab, such as OpenAI, Anthropic or Mistral, that provider takes Microsoft's place in this table. We can in principle also connect a provider your organization has already approved; ask about it through service@vragen.ai. More about that choice is in Hosting and data storage.

We report a new subprocessor in advance. Under the data processing agreement, SWIS may only outsource work with your prior written consent, and SWIS remains responsible for the acts of every subprocessor.

Retention periods

Data Period Notes
Questions asked and answers given 12 months by default Configurable in days, weeks, months or years. After that, conversations are deleted automatically
Personal data inside a question One hour at most Automatic anonymization, on by default. That hour keeps an ongoing conversation possible and is not a retention period
Hashed IP address Six months at most Only if the option is enabled. This period cannot be changed
Administrator accounts Duration of the agreement On termination deleted or returned to you, whichever you prefer, including any remaining copies

Risks and measures

Risk Assessment Control measure
A visitor enters personal data of their own accord Realistic, limited impact Automatic anonymization within one hour, on by default. Expectation management towards the visitor through the text next to the input field
Incorrect or misleading answer Realistic, impact depends on the domain Answers are source-bound and carry source references, so the visitor can verify them. Every answer is traceable to the sources used and the prompt configuration. Administrators can steer through settings and source management
Unauthorized access to the admin environment Small Role-based access, two-factor authentication that can be made mandatory per environment, encrypted storage of credentials, logging of login attempts
Attack on the service or the platform Small Advanced Security Platform protecting against DDoS, SQL injection and cross-site scripting. TLS on all traffic. Internal security audit by a team other than the development team and an external vulnerability scan before going live
Unwanted transfer outside the EEA Very small All processing inside the EEA, recorded in the data processing agreement
Reuse of data for model training Very small Conversations are not used to train or improve models, neither by SWIS nor by the model provider
Data breach Small Notification to you as soon as possible, and where possible within 36 hours of it coming to our attention, including cause, categories of data subjects and the measures taken. Incident log, available for you to review

The security of vragen.ai was examined in September 2025 by an independent ethical hacker under the Cyber Security Pen Test quality mark of the CCV, the Dutch Centre for Crime Prevention and Safety. The conclusion: no critical risks. The two medium-level findings have been fixed. See Tested by an ethical hacker (Dutch).

Organizational measures at SWIS

SWIS works with a certified information security management system based on ISO 27001 and NEN 7510. Privacy management follows ISO 27701. No separate certificate has been issued for that; the requirements are part of the same management system. The certificates can be downloaded from the security page.

  • Every development team has a security manager; all security managers meet every sprint in a central security review.
  • Privacy by design and privacy by default: separate development, test and production environments, role-based access management, no customer data in test environments.
  • Four-eyes principle on all code. The pull request template includes a mandatory check on changes to the processing of personal data.
  • Continuous monitoring for vulnerabilities against the OWASP Top 10, plus manual code reviews.
  • Critical security patches within 24 hours; 24/7 monitoring of availability and anomalous behavior.
  • Periodic external vulnerability scans by an independent party; the report is available on request.
  • A standing DPIA method, in line with the guidelines of the Dutch Data Protection Authority.

Rights of data subjects

Because vragen.ai has no accounts, cookies or profiles, questions are generally not traceable to an individual visitor.

If a data subject does invoke their rights under Articles 15 to 22 GDPR, SWIS cooperates fully so that you can decide within the statutory period. Requests that reach SWIS are passed on to you; we never answer them ourselves.

When a DPIA is mandatory

The GDPR requires a DPIA in three cases regardless: a systematic and extensive evaluation of personal aspects, large-scale processing of special categories or criminal-offence data, and systematic monitoring of a publicly accessible area. None of those three arises when using vragen.ai as described above.

Whether a DPIA is nonetheless necessary or advisable in your situation depends on your audience, the sensitivity of your content and your own organization's policy. That judgment is yours as the controller. We supply the input and are glad to think along.

What you get from us

The security page collects the documents. The ISO 27001, NEN 7510 and ISO 9001 certificates can be downloaded there directly.

If you want the facts on this page delivered in your own DPIA format, we do that on request. The same goes for the model data processing agreement, the statement of applicability and the management summary of the penetration test. Email service@vragen.ai and you will have them the same week.

Didn't find what you were looking for?

Ask your question directly to vragen.ai.

What exactly is vragen.ai?

Example answer by vragen.ai

vragen.ai lets visitors ask their question on your website and gives them a reliable answer straight from your own content, with the source included. You decide which sources the AI uses.

Source: How it works

This is an example. The interactive widget could not load here, for instance because of a script blocker or a slow connection.

You are asking an AI assistant from vragen.ai. Answers come from our own content, with the source included. Why we mention this (Dutch)