Legal

AI & Data Use Policy

How dossierwerk uses AI, parses documents, handles email and stores data

Last updated: 6 October 2026

1. Purpose and scope

This policy explains how dossierwerk uses artificial intelligence (AI), how we process the documents you upload, how we handle email, and where your data is stored.

It applies to:

  • –Customers (importers) using the dossierwerk platform, and their team members.
  • –Suppliers who upload documents through the dossierwerk supplier portal at a customer’s request.
  • –Recipients of emails sent by dossierwerk or by our team.
  • –Visitors to the dossierwerk websites.

Dossierwerk – Gesellschaft in Gründung

A project of Daniel Kohlstaedt and Debashish Bhattacharya

Bäckerstraße 7, 38162 Cremlingen, Germany · Legal notice

The company above is the controller. For customer content inside the platform, the customer is the controller and dossierwerk acts as processor under a data processing agreement (DPA) under Article 28 GDPR.

This policy adds to our Privacy Policy, Terms and Cookie Policy. Where they overlap, the Privacy Policy governs legal bases and your rights.

In the free public demo, uploads of real documents are disabled and no customer documents are stored. Sections 3 and 5 describe the platform as used by customers and pilot partners.

2. How we use AI

We use AI for one task: reading uploaded compliance documents and proposing values for a fixed set of fields. Everything else in dossierwerk runs on documented, rule-based logic.

TaskAI used?Who decides
Reading text from a PDFNo (text extraction runs in your browser)—
Proposing field values (lab, standard, date, SKU, etc.)YesYou confirm or correct each value
Sorting files in a supplier folder by requirementYes, with a filename-based fallbackYou confirm the assignment
Grading evidence strength (A–D)No — fixed, published rulesRules, then your review
Recording decisions and due-care actionsNoThe named person who records them
Drafting emails to suppliersNo — fixed templatesYou send them

What AI never does in dossierwerk

  • –It does not decide whether a product is safe, compliant or certified. dossierwerk makes no such statement, with or without AI.
  • –It does not record decisions. Every decision is attributed to the person and organisation who made it.
  • –It does not send messages or contact suppliers on its own.

AI provider. Field extraction uses Claude, accessed directly through Anthropic’s API. Anthropic is a US company; transfers rely on Standard Contractual Clauses. Neither dossierwerk nor Anthropic trains AI models on our customers’ data.

3. How we parse documents

When you or a supplier upload a document, it goes through five steps. No step marks a document as accepted without a person confirming it.

  1. 1Text extraction in your browser. For PDFs, the text layer of the first 6 pages (up to about 6,000 characters) is read in your browser using the open-source library pdf.js. Plain-text files are read directly.
  2. 2No text, no AI. If a document has no readable text (for example a scan or photo), it is not sent to the AI. You enter the fields by hand. We do not run optical character recognition (OCR) today.
  3. 3AI field proposal. The file name and up to 9,000 characters of extracted text are sent to the AI provider. It returns proposed values for: document type, laboratory, accreditation reference, standard cited, product identifier, measured value and unit, issue date and expiry date. The full original file is not sent.
  4. 4Confidence marking. Each value is marked extracted (printed verbatim and unambiguous) or confirm (inferred, unclear or translated). Documents not in German or English are always marked confirm.
  5. 5Your confirmation. You check, correct or confirm each value. Unconfirmed values stay flagged. If extraction fails, you fill in the fields manually.

Once you accept the values, they are saved with the original file to the evidence record and to the supplier’s record in our database (Section 5). The grade shown for each document is calculated by fixed rules from the confirmed values, not by the AI.

Images (JPG, PNG) in supplier folders are matched to requirements by file name only; their content is not sent to the AI. Extraction results you do not accept are discarded and not stored.

4. Email communication and tracking

Only our newsletters are tracked. Sign-in codes, evidence requests to suppliers and emails from our team are not tracked.

Which emails

Email typeSent throughOpens and clicks tracked?
Sign-in codes and system emailsResend (Ireland, EU)No
Evidence requests to suppliers from the platformResend (Ireland, EU)No
Emails from our teamOur own mailboxesNo
Newsletters (opt-in only)MailchimpYes

How it works. Tracked emails contain a small invisible image (a tracking pixel) and links routed through our email provider. When the image loads or a link is clicked, the provider records it.

What we record: delivery status, time of opening, links clicked, and technical data such as email client, device type and an approximate location derived from the IP address. This is linked to the recipient’s email address.

Why. To see which newsletter topics readers find useful.

Providers. Resend (Ireland, EU) for sign-in codes, system emails and supplier requests; Mailchimp (Intuit) for newsletters. Transfers outside the EU rely on the EU–US Data Privacy Framework or Standard Contractual Clauses, as set out in our Privacy Policy.

Opting out. You can block tracking by turning off automatic image loading in your email program. You can withdraw consent to the newsletter at any time via the unsubscribe link or by writing to compliance@dossierwerk.com.

5. Data storage, retention and security

Your evidence files, documents, accepted extraction results, supplier records and account data are stored in a managed database run by Supabase in Ireland (EU region eu-west-1). The website and app are hosted on Vercel.

What we store

  • –Account data: name, work email, company, role and permissions.
  • –Evidence files: uploaded documents, confirmed field values, grades, decisions, due-care actions, and who did what and when.
  • –Supplier contacts and the messages sent to them, including email status (Section 4).

Some settings, such as language and layout, are stored in your browser’s local storage.

Retention

DataRetention
Evidence records (customers)10 years by default, matching the period importers must be able to produce product documentation
Demo data30 days after demo end or reset
Website logs30 days
Security and sign-in logs90 days
BackupsOverwritten within 90 days

You can export your records at any time. When your contract ends, we return your data on request and delete it within 30 days, following our internal deletion procedure, unless you ask us to keep it or the law requires us to. Backup copies are overwritten within a further 90 days.

Security. Data is encrypted in transit and at rest. Sign-in uses one-time codes sent by email. Access inside an organisation follows the roles and permissions its admin sets. We keep access controls, session controls and security logs.

Service providers (sub-processors)

ProviderPurposeLocation
SupabaseDatabase, file storage, sign-inIreland (EU), eu-west-1
AnthropicAI field extraction (API)US; Standard Contractual Clauses
VercelWebsite and app hostingGlobal network; US company
ResendSign-in codes, system emails, supplier requestsIreland (EU), eu-west-1
MailchimpNewslettersUS; DPF or SCCs
Cloudflare (cdnjs)Delivers the pdf.js library to your browserGlobal network; receives your IP address

The full list of providers for the website, analytics (Vercel Web Analytics) and meeting booking (Cal.com) is in our Privacy Policy.

The customs-tariff lookup sends only the commodity code you enter to the UK Trade Tariff service (trade-tariff.service.gov.uk).

6. Model training, confidentiality and your rights

No AI training on your documents. Neither dossierwerk nor our AI provider trains AI models on the documents or data you upload.

Confidentiality. Your evidence files are visible only to your organisation’s members and to dossierwerk staff who need access to support you. Suppliers see only the requests addressed to them and the documents they uploaded.

Aggregated data. We use anonymised data combined across all customers to build statistics about compliance evidence. Examples: which evidence types are most often missing for a product category, which standards apply, and how evidence quality varies by supplier country. We use these statistics to improve dossierwerk, and they may form part of products or services we offer in future. They do not identify any customer, person or individual document. Customers can opt out at any time by writing to compliance@dossierwerk.com; their data is then left out of future statistics.

Your rights. Under the GDPR you can request access to, correction or deletion of your personal data, restrict or object to processing, and receive your data in a portable format. You can withdraw consent (for example to newsletter tracking) at any time. You may also complain to a data-protection authority, such as the State Commissioner for Data Protection of Lower Saxony (LfD Niedersachsen).

Suppliers and other people whose data a customer holds in dossierwerk should contact that customer first; we will support them.

Changes. We will update this policy when our use of AI or our providers change, and show the date of the last change at the top.

Contact. compliance@dossierwerk.com. We will appoint a data protection officer once the company is incorporated and publish their contact details here.