What we do with your data
We do not train AI models on customer data. We did not do so over the past year and do not do so today. Chainfill learns only through company-specific context and memory: corrections, examples and rules that belong to your company and never generalise to another customer.
Our agreement does reserve the right to use input and output to improve the service, including training our own models. That is deliberately retained so we can do so for your organisation the moment you ask, for example for a model tuned to your document flow. We do not act on it without you, and never for the benefit of another customer. Input and output are never used to develop third-party AI models without your written consent.
Which models we use and where they run
Chainfill runs on Google-hosted AI models through Google Cloud Vertex AI. Processing takes place in the Eemshaven data centre in the Netherlands, with provisioned throughput. No document content goes to a model provider outside this setup.
Model selection
Models can be selected per company, document type and configuration. There is therefore no single fixed model for all customers and all document types.
Processing location
Google Cloud Vertex AI, Netherlands region (Eemshaven). Google Cloud is on our subprocessor list with its location.
Roles under the Regulation
The model provider is the provider of the general-purpose AI model. Chainfill builds a document processing AI system on top of it. You deploy that system inside your own process and remain responsible for the decisions you take on the basis of its output.
Human oversight
Chainfill proposes, people decide. By default every extraction is a proposal that is visible, correctable and traceable back to its source field in the original document in the inspect view, and is exported only after approval. Validation rules, reference tables and business rules block what is wrong.
You can narrow that pause yourself: for suppliers and document flows you mark as trusted, you can switch on automatic export so a document passes through without intervention as long as it meets your conditions. That is a deliberate choice you make per supplier and document type, with validation and duplicate checks still active, and you can reverse it at any time. The system is not designed for automated decision-making with legal effects, and our terms expressly prohibit that use without appropriate human intervention.
What output is and is not
AI functionality is probabilistic. Output can be incorrect, incomplete or out of date. You verify output yourself before acting on it and remain responsible for its use in your business process and towards third parties. Output is not professional advice.
AI literacy
The Regulation expects staff working with AI to be sufficiently AI-literate. We support that with onboarding and training for your planners and key users, in-interface explanations of where a value came from, and documentation on what the system does and does not do. Ask for it during onboarding.
Transparency
Chainfill users know they are working with an AI system: extraction fields show their origin and confidence, and AI-generated drafts are recognisable as such before anyone sends them. The AI addendum to our agreement records the arrangements on model updates, input, output and rights, and is available on request.
The application dates
1 August 2024
The AI Act enters into force
2 February 2025
Prohibited practices and the AI literacy duty start to apply
2 August 2025
Obligations for general-purpose AI models, governance and penalties
2 August 2026
The bulk of the Regulation becomes applicable, including the transparency obligations
2 August 2027
Article 6(1) on high-risk AI in regulated products becomes applicable