Legal

Privacy Policy

TScopilot — MagicCompany.AI B.V.

Version 1.0Effective

1. Who we are

MagicCompany.AI B.V., trading as TScopilot, is responsible for the personal data described in this policy.

MagicCompany.AI B.V.
Gedempte Raamgracht 39, 2011 WG Haarlem, The Netherlands
KvK 91269199 · VAT NL865600077B01
privacy@tscopilot.com

2. What this policy covers — and what it doesn't

This policy covers personal data we handle as controller: visitors to tscopilot.com, people who request a demonstration or submit a PoC assessment, and contact persons at our customers, prospects, partners and suppliers.

It does not cover data inside a customer's TScopilot deployment. There, the customer decides what documents and data are processed and is the controller; we act as processor under that customer's agreement with us and the accompanying Data Processing Agreement. If you are an employee or end user of one of our customers, please direct questions to that organisation.

3. What we collect

What you give us. Your name, business email address, company, job title, and whatever you write in an enquiry, demo request or PoC assessment. For customers and suppliers, the contact and billing details of the people named in quotations, contracts and invoices.

What we collect automatically. IP address, browser and device type, pages viewed, referring URL and approximate location derived from IP.

What we find publicly. Company websites, public professional profiles and trade registers, used only to identify organisations that may benefit from our software.

Please send business contact details only. Do not put health data or other special categories of personal data, or third-party confidential information, into our forms or free-text fields.

5. Cookies

We place cookies that are strictly necessary to deliver the website without asking you. Everything else — analytics, and the third-party scheduling widget and forms embedded on our contact pages — requires your prior consent, which we ask for through the banner on your first visit. The banner lists the specific cookies in use and lets you refuse as easily as accept. You can change your choice at any time via Cookie settings in the footer, and refusing has no effect on your ability to use the site.

We do not use advertising or retargeting cookies and we do not build advertising profiles.

6. Who we share it with

We do not sell personal data. We share it with:

  • Service providers acting on our instructions, each under a written data processing agreement: website hosting and platform, analytics, CRM and marketing, meeting scheduling, email and collaboration, accounting and invoicing, AI model providers and inference platforms, and IT security and monitoring. We can tell you which specific providers we use on request.
  • Professional advisers — lawyers and accountants, bound by professional secrecy.
  • Authorities, where we are legally required to disclose or need to defend a legal claim.
  • A successor entity, in a merger or sale of the business, subject to this policy continuing to apply.

7. AI and customer data

Our business is AI applied to confidential technical documentation, so we state our position plainly.

Customer data — documents, support tickets, production lists, prompts and generated outputs — is never used to train, fine-tune or improve any foundation model made available to anyone else. We only use model providers that commit in writing not to train on customer inputs and outputs. Where we adapt a system to a customer's product data, the result is built for that customer alone and is not reused for others. Raw prompts and responses are not retained in production logs by default. For customers who require it, we deploy inside their own cloud tenant, on an EU provider, or on-premise.

TScopilot is built for technical product and service documentation. It is not intended to process patient data or other special categories of personal data, and customers should not upload such data without agreeing additional safeguards with us in advance.

AI output is probabilistic and can be wrong. Our products cite their sources and are designed to be used under human supervision.

8. International transfers

We prefer to keep processing within the EEA. Where a provider is outside it, we rely on a European Commission adequacy decision, certification under the EU–US Data Privacy Framework, or the Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with appropriate additional safeguards. You can request a copy of the relevant safeguards from us.

9. How long we keep it

Website analytics14 months
Cookie consent records12 months
Enquiries, demo requests and PoC assessments that don't lead to a relationship24 months from last contact
Marketing contactsUntil you unsubscribe, after which we keep a suppression record only
Customer and supplier records, contracts and invoices7 years from the end of the financial year (Article 52(4) Dutch General State Taxes Act; Article 2:10(3) Dutch Civil Code)
Support correspondenceContract term plus 24 months
Server and security logs12 months

Where data is relevant to a legal claim, we keep it until the matter is resolved.

10. Security

We use technical and organisational measures appropriate to the risk (Article 32 GDPR), including encryption in transit and at rest, role-based access on a least-privilege basis with multi-factor authentication for administrative access, logical separation of customer environments, audit logging, encrypted backups, and confidentiality obligations for all personnel. We carry out due diligence on our providers and have written data processing agreements with them.

If a personal data breach is likely to put your rights at risk, we notify the Dutch Data Protection Authority within 72 hours of becoming aware of it, and we inform you directly where the risk to you is high.

11. Your rights

You have the right to access your data, correct it, have it erased, restrict or object to how we use it, receive it in a portable format, and withdraw consent at any time. You can object to direct marketing at any time, for any reason, and we will stop.

Email privacy@tscopilot.com. We reply within one month. We may ask for enough information to confirm your identity, and there is no charge unless a request is clearly unfounded or excessive.

If you are unhappy with how we have handled your data, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl, or to the authority in your own country. We would rather you came to us first.

If your data sits inside a customer's TScopilot deployment, please contact that customer — they are the controller, and we will help them respond.

12. Visitors outside the EU

United Kingdom. We process UK personal data in accordance with the UK GDPR. You may complain to the Information Commissioner's Office, ico.org.uk. Transfers out of the UK use the UK Addendum to the EU Standard Contractual Clauses.

Switzerland. We process Swiss personal data in accordance with the Federal Act on Data Protection. You may complain to the Federal Data Protection and Information Commissioner, edoeb.admin.ch.

United States. We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws. Residents of states with comprehensive privacy laws can exercise their rights using the contact details in section 11.

13. Other

Our website is intended for business use by professionals and we do not knowingly collect data from anyone under 16. We are not responsible for the privacy practices of sites we link to.

We may update this policy; the version and date at the top will change and material changes will be announced on the website.

MagicCompany.AI B.V. · Gedempte Raamgracht 39, 2011 WG Haarlem, The Netherlands · KvK 91269199 · VAT NL865600077B01 · privacy@tscopilot.com