legal
processing
Your data, our commitments.
What we process on your behalf, how we secure it and who else has access. In plain language, with the facts taken from the system itself.
- 01 Who is responsible for what
- For the data you put into Fikst you are the controller and we are the processor. We process that data solely to deliver the service, following your instructions. This agreement forms part of the main agreement and takes precedence where personal data is concerned.
- 02 What we do not do
- We do not use your data for our own purposes, for profiling, or to train models. We do not sell anything on.
- 03 Which data this covers
- Names, addresses and contact details of your customers and contacts; the history of quotes, work orders, installations and service; signatures given on approval; sent messages; invoice data and, where bank feeds are used, the counterparty account number; and for your employees their name, e-mail, phone and role. No special categories of personal data are processed and no national identification number is stored.
- 04 How we secure it
- Data belonging to different organisations is separated at row level in the database. Rights follow from the role of the signed-in user, where an unknown role receives the minimum rather than the maximum. Traffic is encrypted. Signatures live in protected storage and can only be viewed through short-lived links, never a public address. Keys for the programming interface are stored hashed and cannot be read back after creation. Every change is recorded together with the user who made it.
- 05 What we deliberately do not record
- We do not store the IP address of anyone viewing an online quote. Of the browser we keep only the family, so "Chrome" rather than the full identifying string. There is no cross-site tracking of visitors.
- 06 Sub-processors
- We engage other parties for hosting, database, e-mail delivery, payments, accounting, calendar synchronisation and the AI features. The current list is on this page under "Who else has access". If we start using a new party we announce it in advance and you may object.
- 07 Who else has access
- Supabase (database, sign-in, storage), Resend (e-mail delivery, European region), Anthropic (the AI features), Vercel (hosting), Hetzner and Cloudflare (the connector server), Mollie (payment links), Moneybird (accounting), monday.com (source system for customers who use it) and Microsoft (calendar synchronisation, only if you enable it). We hold a processing agreement with each of them.
- 08 AI features and transfers
- Fikst includes AI features. If you use them, the content those features need is processed by our AI provider outside the European Economic Area, under the applicable safeguards. If you do not want that, the AI features can be switched off for your environment.
- 09 Data breaches
- If we discover a breach affecting your data we notify you without undue delay and with the information you need, so that you can report to the supervisory authority within the statutory 72 hours.
- 10 Requests from data subjects
- If you receive a request for access, correction or deletion, we help you carry it out. If such a request reaches us while it concerns your data, we refer the requester to you and let you know.
- 11 End of the agreement
- On termination you get your data back in a common format. We then delete our copies, except what we are legally required to keep, such as invoices covered by the statutory retention period.
this text is also available in Dutch, which is the version a Dutch customer signs. questions, or need a countersigned copy? ask via the contact page.
Last updated: 5 August 2026