Legal
TScopilot — MagicCompany.AI B.V.
MagicCompany.AI B.V., trading as TScopilot, is responsible for the personal data described in this policy.
MagicCompany.AI B.V.This policy covers personal data we handle as controller: visitors to tscopilot.com, people who request a demonstration or submit a PoC assessment, and contact persons at our customers, prospects, partners and suppliers.
It does not cover data inside a customer's TScopilot deployment. There, the customer decides what documents and data are processed and is the controller; we act as processor under that customer's agreement with us and the accompanying Data Processing Agreement. If you are an employee or end user of one of our customers, please direct questions to that organisation.
What you give us. Your name, business email address, company, job title, and whatever you write in an enquiry, demo request or PoC assessment. For customers and suppliers, the contact and billing details of the people named in quotations, contracts and invoices.
What we collect automatically. IP address, browser and device type, pages viewed, referring URL and approximate location derived from IP.
What we find publicly. Company websites, public professional profiles and trade registers, used only to identify organisations that may benefit from our software.
Please send business contact details only. Do not put health data or other special categories of personal data, or third-party confidential information, into our forms or free-text fields.
| Purpose | Legal basis (Article 6 GDPR) |
|---|---|
| Responding to enquiries, demo requests and PoC assessments | Legitimate interests — replying to a business enquiry addressed to us; or pre-contractual steps (Art. 6(1)(b)) |
| Preparing quotations and performing customer contracts | Legitimate interests — administering the contract with your organisation; or Art. 6(1)(b) |
| Sending you information about our products | Consent; or legitimate interests together with the existing-customer exception in Article 11.7(4) of the Dutch Telecommunications Act. You can unsubscribe at any time |
| Website analytics | Consent (Article 11.7a Dutch Telecommunications Act) |
| Security, troubleshooting and preventing misuse | Legitimate interests |
| Tax, accounting and other legal obligations | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising or defending legal claims | Legitimate interests |
We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you (Article 22 GDPR), and we do not use AI to profile website visitors.
Our business is AI applied to confidential technical documentation, so we state our position plainly.
Customer data — documents, support tickets, production lists, prompts and generated outputs — is never used to train, fine-tune or improve any foundation model made available to anyone else. We only use model providers that commit in writing not to train on customer inputs and outputs. Where we adapt a system to a customer's product data, the result is built for that customer alone and is not reused for others. Raw prompts and responses are not retained in production logs by default. For customers who require it, we deploy inside their own cloud tenant, on an EU provider, or on-premise.
TScopilot is built for technical product and service documentation. It is not intended to process patient data or other special categories of personal data, and customers should not upload such data without agreeing additional safeguards with us in advance.
AI output is probabilistic and can be wrong. Our products cite their sources and are designed to be used under human supervision.
We prefer to keep processing within the EEA. Where a provider is outside it, we rely on a European Commission adequacy decision, certification under the EU–US Data Privacy Framework, or the Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with appropriate additional safeguards. You can request a copy of the relevant safeguards from us.
| Website analytics | 14 months |
| Cookie consent records | 12 months |
| Enquiries, demo requests and PoC assessments that don't lead to a relationship | 24 months from last contact |
| Marketing contacts | Until you unsubscribe, after which we keep a suppression record only |
| Customer and supplier records, contracts and invoices | 7 years from the end of the financial year (Article 52(4) Dutch General State Taxes Act; Article 2:10(3) Dutch Civil Code) |
| Support correspondence | Contract term plus 24 months |
| Server and security logs | 12 months |
Where data is relevant to a legal claim, we keep it until the matter is resolved.
We use technical and organisational measures appropriate to the risk (Article 32 GDPR), including encryption in transit and at rest, role-based access on a least-privilege basis with multi-factor authentication for administrative access, logical separation of customer environments, audit logging, encrypted backups, and confidentiality obligations for all personnel. We carry out due diligence on our providers and have written data processing agreements with them.
If a personal data breach is likely to put your rights at risk, we notify the Dutch Data Protection Authority within 72 hours of becoming aware of it, and we inform you directly where the risk to you is high.
You have the right to access your data, correct it, have it erased, restrict or object to how we use it, receive it in a portable format, and withdraw consent at any time. You can object to direct marketing at any time, for any reason, and we will stop.
Email privacy@tscopilot.com. We reply within one month. We may ask for enough information to confirm your identity, and there is no charge unless a request is clearly unfounded or excessive.
If you are unhappy with how we have handled your data, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl, or to the authority in your own country. We would rather you came to us first.
If your data sits inside a customer's TScopilot deployment, please contact that customer — they are the controller, and we will help them respond.
United Kingdom. We process UK personal data in accordance with the UK GDPR. You may complain to the Information Commissioner's Office, ico.org.uk. Transfers out of the UK use the UK Addendum to the EU Standard Contractual Clauses.
Switzerland. We process Swiss personal data in accordance with the Federal Act on Data Protection. You may complain to the Federal Data Protection and Information Commissioner, edoeb.admin.ch.
United States. We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws. Residents of states with comprehensive privacy laws can exercise their rights using the contact details in section 11.
Our website is intended for business use by professionals and we do not knowingly collect data from anyone under 16. We are not responsible for the privacy practices of sites we link to.
We may update this policy; the version and date at the top will change and material changes will be announced on the website.