Privacy and data protection

What happens to our visitors' data?

Answer by vragen.ai

As little as possible. And you decide where it lives.

This is the question we get most often, and usually first. Below are the facts, the documents you can take with you without filling in a form, and the reasoning behind each topic. Written to be passed on to your data protection officer or your CISO.

The European Data Protection Board uses the vragen.ai API and semantic search.

See what vragen.ai does for government

The facts, in short

Looking for one specific detail for your record of processing activities? It is here. The reasoning behind each point is below. If you are actually filling in a DPIA or a processing register, go to DPIA and processing register, where the processing activities, subprocessors, periods and measures are broken out in full.

Topic Fact
Personal data From visitors, only the question they ask, plus optionally a hashed IP address. Administrators get a business account with a name, email address and IP address; a functional address works just as well, you decide what you fill in.
Purposes Answering questions, insight into what visitors ask, preventing abuse, managing the application.
Cookies None, until a visitor starts a conversation. From that moment the widget sets three functional cookies (XSRF-TOKEN and vragenai-session, both valid for two hours, and ai-toc-accepted-this-session for the duration of the visit) to keep the chat working securely. There is no personal data in them and they are not used for tracking or analytics. As strictly necessary cookies for a function the visitor requests themselves, they fall under the legal exemption, so consent is not required.
Processing location The Netherlands. Data is stored at TrueFullstaq in Amsterdam and managed from our office in Leiden. If you pick a language model through Microsoft Azure, it can run in the Netherlands as well, alongside France and Sweden; in every case inside the EEA.
Subprocessors Two by default: TrueFullstaq B.V. for hosting, storage and the embedding models, and Sentry for technical error reports from the application (EU instance, no personal data). If you choose an external language model, that provider is added: Microsoft Azure, OpenAI, Anthropic or Mistral. So who ends up in your chain depends on your model choice, and it is listed in the processing register.
Availability 99.9% for the platform vragen.ai runs on, the same figure we use in our service level agreements. With an external language model, that provider's availability is added on top.
Backups and recovery A backup every four hours, five retained, plus daily snapshots (twelve days) and weekly ones (thirteen weeks). Kept at a second location as well.
Separation between customers Every customer has their own database and their own search index. Running your environment fully isolated is possible too; get in touch about that.
Retention of conversations Twelve months by default, and you set it yourself in days, weeks, months or years.
Retention of the hashed IP address Six months at most, and only if you switch that option on.
Anonymization On by default. The system filters personal data out of the input and deletes the original after one hour.
Model training Conversations are never used to train or improve AI models.
Data breach notification As soon as possible, and where possible within 36 hours of it coming to our attention. Recorded in the data processing agreement.
Certification ISO 27001, NEN 7510 and ISO 9001, held by Swis B.V. and issued by TÜV NORD Nederland. The field of application is designing, developing and managing web applications, so it includes vragen.ai.
Access to the admin environment Role-based, with two-factor authentication you can make mandatory per environment.
Rights of data subjects We forward requests to you. We never answer them ourselves.
On termination All personal data is deleted or returned to you, whichever you prefer, including any remaining copies.
Data Protection Officer Björn Brala, SWIS.
Reporting a vulnerability Email service@vragen.ai. A human always replies.

Can I read up on this somewhere without calling first?

Answer by vragen.ai

Everything we have is on this page

Download them directly, no form required.

On request

We send these documents over as soon as you need them. Email service@vragen.ai and you will have them the same week.

  • Statement of applicability Version 2.3 of 10 September 2025, the document both the ISO 27001 and the NEN 7510 certificate refer to. On request
  • Management summary of the penetration test Findings and follow-up from the most recent external security audit. On request

A quick word from the vragen.ai team

From here on it gets long. That is deliberate.

Below is the reasoning per topic: what we process, where it is stored, how long it stays, who can see it and how you can verify it.

Read on at your own pace. But if you already have one specific question, ask it here first: you get the answer with the source included.

What exactly is vragen.ai?

Example answer by vragen.ai

vragen.ai lets visitors ask their question on your website and gives them a reliable answer straight from your own content, with the source included. You decide which sources the AI uses.

Source: How it works

This is an example. The interactive widget could not load here, for instance because of a script blocker or a slow connection.

You are asking an AI assistant from vragen.ai. Answers come from our own content, with the source included. Why we mention this (Dutch)

Which personal data do you process?

Answer by vragen.ai

Only the question someone types

From the visitor, vragen.ai processes only that question. Until someone starts a conversation there is not a single cookie. After that the widget sets three cookies that keep the chat working securely. There is no personal data in them and they do nothing for tracking. We do not ask for a name, an email address or an account, so there is no profile to attach anything to. Your administrators do have an account, with a name and an email address. Those are business account details you supply yourself; a functional address works just as well.

If a visitor does type something personal, a name or a case number, vragen.ai takes it out. After one hour vragen.ai anonymizes all input and permanently deletes the original. That is on by default; you do not have to do anything for it. In your inbox you read the question back with a marker such as [name removed].

The recognition is automated and does not catch everything with certainty. Someone writing out their whole situation can include something the recognition misses. So this is not anonymization in the sense of the GDPR: whatever the recognition misses stays personal data, and it falls under the retention period you set. What keeps the risk small: we never ask for personal data, there is no account to attach it to, and whatever the recognition does see is gone within the hour. In your DPIA this is the residual risk, with the anonymization as the mitigating measure.

The hour is there for a reason: the visitor has to be able to finish their conversation. Someone asking follow-up questions about their own situation gets a usable answer, and after that the personal information is out of the system.

One option is off by default: sending the IP address along with a search, so we can counter automated abuse and overload. We store that IP address hashed and delete it after six months at most.

Source: Anonymizing data (Dutch) Hosting and data storage Privacy statement (Dutch)

What happens to those questions, and who can see them?

Answer by vragen.ai

The four purposes and who has access

For your record of processing activities, these are the four purposes.

  • Answering the visitor's question
  • Gaining insight into frequently asked questions and gaps in your content
  • Countering abuse
  • Letting your own administrators manage the application

Training models is not on that list. If you run everything in our own environment, that is covered technically as well: the question never leaves that environment, so there is no one who could train on it or read what people ask.

With an external language model, we put it in the data processing agreement that the provider does not train on your data. On a concrete suspicion of abuse, that provider can review the content of a question. That is the standard condition at OpenAI, Anthropic, Mistral and Azure. If you want to rule that out entirely, the local option is the only route.

You can only read conversations in the admin environment, with the permissions that come with the role. On our side, only the people who need access for support or maintenance, under a confidentiality agreement and with a role of their own. We log login attempts.

Source: Users and roles Hosting and data storage

Where is our data?

Answer by vragen.ai

Wherever you want, and that can be entirely in the Netherlands

The entire chain can run in the Netherlands, in our own environment at hosting partner TrueFullstaq in Amsterdam. Those are the search index, the embedding models that capture the meaning of your content and the language model that formulates the answers. All three on the same infrastructure, so no question and no answer has to leave that environment. That is an architectural choice you can record in your processing register.

Would you rather use one of the big commercial models, because it performs better on your material? That works too: OpenAI, Anthropic, Mistral or a model through Microsoft Azure. On Azure you can now pick the Dutch region as well, alongside France and Sweden; in every case it stays inside the EEA and under a data processing agreement in line with European guidelines. Whichever provider you pick ends up in your processing register as a subprocessor.

Vragen.ai is not tied to a model. The language model is a setting you can revisit later without replacing the product, and that choice is in every plan, including the smallest one. If your organization has already approved a supplier, we can in principle connect it.

Vragen.ai is built by SWIS in Leiden, the Netherlands. If you want to rule out data going to a US provider, pick a language model that runs in the Netherlands or elsewhere in the EEA. That is a choice in the settings.

Source: Hosting and data storage Sovereign AI platform (Dutch) For government & municipalities

How long do you keep the conversations?

Answer by vragen.ai

You set the retention period

You set it in days, weeks, months or years, so in your processing register you fill in your own number. We set it together with you at delivery.

Twelve months is the default. Over that period you see in the inbox where visitors get stuck and which content is missing, and the period stays easy to defend. Shorter works too. After the period, conversations disappear automatically.

One period is fixed: we keep hashed IP addresses for six months at most. Administrator accounts exist for as long as the agreement runs.

Source: Hosting and data storage Testing and evaluating conversations

Doesn't the AI make up answers?

Answer by vragen.ai

Every answer comes from your own sources

Answers come only from your organization's own, controlled sources, always with the source included. If the search comes up empty, there is no guess: the visitor gets an honest answer with a referral. The agent has no access to the internet or to external systems.

You can verify that afterwards. We record every step in a trace: which reasoning steps the agent took, which sources it used and how it built up the answer. Every answer also gets evaluation scores for reliability, relevance and source relevance. For sensitive topics the assistant can follow extra guidelines: at the Netherlands Youth Institute (NJi) it does not engage with topics such as depression or personal cases and refers directly to appropriate help instead.

Source: How it works Testing and evaluating conversations New evaluation scores (Dutch) Customer story NJi (Dutch)

Do we get a data processing agreement and input for our DPIA?

Answer by vragen.ai

Yes, and you do not have to ask for it

We sign a data processing agreement for vragen.ai as standard. It is ready, and it can also be in your own format. It lists the subprocessors, the retention periods and the arrangements around incidents and data breaches. If the processing changes during our collaboration, we amend the agreement. We put any new subprocessor to you in advance; without your written consent it does not happen.

In case of a data breach we inform you as soon as possible, and where possible within 36 hours of it coming to our attention. That period is in the agreement, along with our obligation to cooperate on a DPIA and on requests from your supervisory authority.

That DPIA remains yours as the controller; we cannot carry it out or sign it for you. We do supply all the input you need, in your own DPIA format: a technical description in plain language, the overview of processing activities and subprocessors, and the risks and measures as we see them. SWIS has a standing method for this, in line with the guidelines of the Dutch Data Protection Authority.

If a visitor invokes their rights under Articles 15 to 22 GDPR, we pass that request on to you and help you decide within the statutory period; we never answer such a request ourselves. At the end of the collaboration we delete all personal data or return it to you, whichever you prefer, including any copies that remain.

The documents themselves are at the top of this page, collected in one list.

Source: DPIA and processing register Privacy statement (Dutch) Hosting and data storage

Which certifications can you show?

Answer by vragen.ai

ISO 27001, NEN 7510 and ISO 9001, and vragen.ai is in scope

Vragen.ai is built by SWIS, a digital agency in Leiden, the Netherlands. The certificates are held by Swis B.V. and issued by TÜV NORD Nederland. You can read whether vragen.ai falls under them in the field of application on the ISO 27001 certificate:

Design, develop and manage websites and web applications for profit and non-profit organisations in multiple sectors including the healthcare industry.

Field of application, ISO 27001 certificate CERT-000850-TN

Vragen.ai falls under that. It is a product of SWIS itself, so the same legal entity as the one named on the certificate, and exactly the kind of web application the field of application describes. There is no subsidiary or supplier in between that sits outside the audit. A product cannot hold an ISO certificate of its own, by the way: the standard certifies an organization's management system.

  • ISO 9001 CERTIFIED
  • ISO 27001 CERTIFIED
  • NEN 7510 CERTIFIED

For healthcare organizations, NEN 7510 is the relevant standard. Its field of application covers healthcare websites and healthcare applications, and it explicitly notes that hosting is outsourced. That matches practice: hosting sits with TrueFullstaq in Amsterdam. Privacy management further follows ISO 27701; no separate certificate has been issued for that, the requirements sit in the same management system.

The three certificates are at the top of this page to download, with registration number and validity date, so you can verify them with TÜV NORD. The NEN 7510 certificate is only issued in Dutch.

On the technical side: vragen.ai runs behind our Advanced Security Platform, which protects against DDoS attacks, SQL injection and cross-site scripting. All traffic runs over TLS. Before going live we run an internal security audit by a team other than the development team, plus an external vulnerability scan. Critical security patches are applied within 24 hours.

  • Separate development, test and production environments, with no customer data in the test environment
  • Four-eyes principle on all code, with a mandatory privacy check in the pull request
  • Every development team has a security manager; they meet every sprint
  • Continuous monitoring against the OWASP Top 10, plus manual code reviews

Source: About us Tested by an ethical hacker (Dutch)

Has the security been tested independently?

Answer by vragen.ai

Yes, by an ethical hacker

In September 2025, an independent ethical hacker examined vragen.ai under the Cyber Security Pen Test quality mark of the CCV, the Dutch Centre for Crime Prevention and Safety. The test focused on three questions:

User data

Could user data be accessed?

Manipulation through prompts

Could the AI be influenced with prompt injection?

Admin functions

Were the admin functions properly shielded?

The conclusion: no critical risks, and it was not possible to view other people's conversations. The test did produce two medium-level findings. The model's output could be displayed without sufficient validation, and with targeted prompts the agent's tone could be influenced temporarily. We fixed both: we tightened the system prompt and limited output to sources on a fixed list. That also produced the "Restrict reference domains" feature, which lets you control from which domains links and images are allowed in answers.

The management summary of the test is available on request. We also ran internal test rounds: more than 900 questions asked and assessed for reliability, tone and safety. Before anything goes live on your side, you do the same with your own test questions.

Source: Tested by an ethical hacker (Dutch) Restricted reference domains (Dutch)

And what if someone does find a vulnerability?

Answer by vragen.ai

Report it to us: responsible disclosure

No system is perfect. If you spot a weak spot in vragen.ai or in the widget, we want to know about it before someone else abuses it. Email your findings to service@vragen.ai. The responsible disclosure policy of SWIS, the company that builds the product, applies to vragen.ai.

What we promise

  • You will get a response within three business days, with our assessment of the report and an expected resolution date.
  • If you follow the guidelines below, we will not take any legal action against you.
  • We handle your report in strict confidence and will not pass your personal details to third parties without your permission.
  • We keep you informed of the progress until the problem is resolved.
  • If we publish anything about the problem, we will credit you as the discoverer. If you would rather stay anonymous, we leave your name out.
  • There is a reward for every report of a security problem that was not yet known to us. The amount depends on the severity of the leak and the quality of the report.

What we ask of you

  • Do not take advantage of the vulnerability. So do not download more data than you need to demonstrate the problem, and do not change or delete anyone else's data.
  • Do not share the problem with others until it has been resolved.
  • Do not use attacks on physical security, social engineering, distributed denial of service, spam, automated scans or tests, or third-party applications. Vulnerabilities that can only be found with an automated scan or test fall outside the policy.
  • Provide enough information to reproduce the problem. Usually the IP address or the URL of the affected system plus a description of the vulnerability is enough. A complex vulnerability may need more explanation.

We resolve problems as quickly as we can, and we would like to play an active role in any publication about them once they are fixed. Working with scanners or other tooling? The machine-readable details are in our security.txt per RFC 9116: contact address, languages and the PGP key you can use to encrypt your report. Requesting that file through vragen.ai gets you to the same place.

Source: Responsible disclosure SWIS security.txt

Our CISO has some technical questions. Can you answer those up front?

Answer by vragen.ai

The six questions CISOs ask us most

What about the AI Act?

Article 50 has applied since 2 August 2026: a visitor has to know they are talking to AI. You place that notice under the widget; on our own site it is already there. What the law asks of an AI search function beyond that, we have written out in a separate article.

Are we running in a shared environment with other customers?

Every customer has their own database and their own search index. Your content and your conversations therefore sit separately from those of other organizations, not in a shared index with a filter on top. Going further is possible too: we run your environment fully isolated on request. That is not a default setting, so get in touch about it; then we will look at what you need.

How is access to the admin environment secured?

With role-based access. Every user can switch on two-factor authentication in their own profile, and you can make it mandatory for everyone in your environment. Every login attempt gets a log line, successful or not.

What is traceable afterwards?

Every generated answer can be traced back to the exact sources and the prompt configuration that produced it. We also log system errors and login attempts. We keep an incident log that you can review.

What about availability and recovery?

Vragen.ai runs on the same private cloud as our other applications, at TrueFullstaq in Amsterdam. For that we work with an availability of 99.9%, with monitoring for outages and anomalous behavior 24 hours a day. Critical patches are applied within 24 hours. We put hard response and resolution times per priority level in a service level agreement.

We back up the data every four hours and keep five of those backups, so we can go back up to twenty hours. On top of that, daily snapshots are kept for twelve days and weekly ones for thirteen weeks, at a second location as well. In a normal disruption you therefore lose at most the last four hours of changes.

One dependency remains. With an external language model, that provider's availability is added to ours; locally, the whole chain is ours.

And if someone finds a vulnerability?

We have a responsible disclosure policy and receive reports on it regularly. You report through service@vragen.ai. The terms are above, under reporting a vulnerability.

Source: The AI Act and the transparency obligation (Dutch) Tested by an ethical hacker (Dutch) Users and roles Troubleshooting and support

Is the vragen.ai widget accessible to all visitors?

Answer by vragen.ai

The widget meets WCAG 2.1 level AA

The standard integration of vragen.ai is tested against it: keyboard navigation, text labels for screen readers, status updates through ARIA live regions, a logical heading structure and a clearly visible focus state. Within SWIS, every development team has at least one developer trained in WCAG. For Dutch government organizations this counts double, because there level AA is legally required.

Source: Accessibility and vragen.ai (Dutch) WCAG updates (Dutch) For government & municipalities

Our privacy officer has a few more questions.

Answer by vragen.ai

Ask the team your question

Is something missing from your own assessment framework, or would you like the whole privacy file at once? Ask here, and someone who builds the product answers.

Send us a message

We usually reply within one business day

  • An answer from the team itself
  • Technical and legal questions too

Rather have a quick call

Björn Brala, Data Protection Officer at SWIS

Björn Brala

Data Protection Officer

Is your question easier to talk through than to type? Call or email Björn directly, he will think it through with you.

+31 71 203 26 03 bjorn@swis.nl

Mon to Fri, 9:00 to 17:30

What happens next?

  1. We read your question.
  2. The colleague who knows most about it replies.
  3. Still unclear? Then we give you a call.

Form not loading? Refresh the page, or get in touch with us.

This page was last updated on .