Data Processing
How the AccuraSee platform processes customer data — roles, location, sub-processors, and how to get our Data Processing Agreement.
This is a plain-language summary for evaluation; the binding terms are in the signed Data Processing Agreement.
1. Who this is for
This page is for prospective and current customers assessing how AccuraSee handles your organisation’s data. For how we handle data collected through this website, see the Privacy Policy.
2. Roles
When you use the AccuraSee platform, your organisation is the data controller and iSolve AB acts as a data processor, processing data only on your documented instructions under a signed Data Processing Agreement (DPA). We operate under a signed DPA with our customers; the same terms are offered for evaluation (see below).
3. Where your data is processed
The platform is designed to keep your data in your own EU environment. The data store and bulk data remain in your tenant, pinned to an EU region (Azure, Sweden Central). We say this precisely: per-query results transit an approved EU-region, zero-retention model endpoint under contract — we never claim that “nothing ever leaves” your tenant.
4. Sub-processors
The providers that may process customer data on our behalf. The current list is confirmed per deployment in your DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting / compute (in your tenant or a builder-managed tenant) | EU — Sweden Central |
| AI model provider — selected by you | Per-query inference at a zero-retention endpoint | EU region where the chosen provider offers one |
On the AI model: you choose the AI model your organisation uses — we do not impose one as a default sub-processor, and the model provider becomes a sub-processor only because of that choice. During setup, and only with your agreement, we may evaluate different models against your data to ensure AccuraSee's answer quality before you settle on one. Because the Gateway is protocol-agnostic (MCP), you can change the model later without re-plumbing your data layer; any change to sub-processors is handled under the DPA's change process.
5. Security measures
Processing is protected by identity on every call (OAuth 2.1 / Entra ID), row-level security in governed views, read-only access, full per-user audit logging, and encryption in transit and at rest. The technical detail is on our Architecture page.
6. International transfers
The platform is built to keep processing in the EU. If you choose an AI model whose endpoint is outside the EU/EEA, that transfer is covered by an adequacy mechanism (such as the EU–US Data Privacy Framework) and/or Standard Contractual Clauses, and is set out in your DPA.
7. Data-subject requests & breach notification
We assist controllers in responding to data-subject requests and commit to notifying you without undue delay on becoming aware of a personal-data breach affecting your data, consistent with the DPA and the GDPR.
8. Get the DPA
Our Data Processing Agreement is available to customers and prospects under evaluation. Request it at email us.
9. Contact
Questions about data processing: email us.
Ask your business data anything. Get an answer in seconds.
Start with a discovery call — we'll scope a low-risk pre-study and show you what's answerable on your data.
What to expect: a 30-minute call · we map your data sources · a live answer on your data — no pressure.