Sluis
ProduktPreiseEnterpriseDocsCompliance
KonsoleKey anfordern
Rechtliches

Privacy Policy

Wie 7Lab B.V. als Verantwortlicher Kontodaten für die Sluis-Plattform verarbeitet.

Version 2, gültig ab 2026-08-06. Der englische Text unten ist die verbindliche Fassung.

Privacy Policy

Version 2 — effective 6 August 2026.

This Privacy Policy explains how 7Lab B.V., Danzigerbocht 39 G, 1013 AM Amsterdam, The Netherlands (Chamber of Commerce 84815515) ("7Lab", "we") processes personal data as controller when you visit sluis.ai, create an account, or otherwise interact with us. Sluis is a product of 7Lab B.V. You can reach us at info@sevenlab.ai.

Important scope note. Content your organisation sends through the Sluis gateway or chat surfaces (prompts, documents, model responses, "Customer Content") is processed by 7Lab as processor on behalf of your organisation, under the Data Processing Agreement between 7Lab and that organisation, not under this policy. Questions about Customer Content should go to the organisation that operates your account.

1. What we collect

Account and profile data (when you sign up or are invited): email address, password hash (we never store your password itself) or Google sign-in identity, full name, phone number, job title, organisation name, country, company size, VAT number, role and organisation memberships, language preference, and, if you enable two-factor authentication, passkey public keys.

Billing data (when your organisation activates a paid plan): billing and invoice email addresses, payment method type and mandate reference from our payment provider, charge and invoice history, and VAT determination data. We never receive or store full card numbers or bank credentials; those go directly to Mollie.

Usage and security data: sign-in timestamps, IP addresses on security-relevant events (sign-up, sign-in, legal-document acceptance), operator audit events (who changed what setting, when), request metadata (model, provider, region, token counts, cost) for metering and the tamper-evident audit trail, and technical logs needed to run and secure the Service.

Contact data: what you send us through the contact and DPA-request forms or by email.

Local storage: the marketing site and Console store your language choice (sluis_lang) and session token in your browser's local storage. We use no advertising trackers and no third-party analytics cookies; fonts are self-hosted, so your visit is not disclosed to a fonts CDN.

2. Why we process it (purposes and legal bases)

PurposeLegal basis (GDPR Art. 6(1))
Providing the account, Console and Service(b) contract
Billing, invoicing, tax compliance(b) contract, (c) legal obligation
Security: abuse prevention, throttling, 2FA, audit trails(f) legitimate interest in securing the Service, (c) where required
Recording acceptance of legal documents (who, when, which version, IP)(f) legitimate interest in proving contract conclusion, (c) accountability
Service emails: verification, security notices, invoices(b) contract, (f) legitimate interest
Responding to contact requests(b)/(f) depending on context
Product improvement using aggregated, de-identified metrics(f) legitimate interest

We do not use your personal data for automated decision-making with legal effect, and we do not sell it.

3. Who receives it

  • Mollie B.V. (Amsterdam, NL): payment processing for paid plans.
  • Scaleway SAS (Paris, FR): EU cloud infrastructure hosting the Service and its databases.
  • Transactional email delivery (EU SMTP provider): verification, security and invoice emails.
  • Google (only if you choose "Sign in with Google"): Google processes the sign-in under its own terms; we receive your email address and a subject identifier.
  • Competent authorities where the law requires disclosure.

We do not transfer account data outside the EEA in the ordinary course. If a transfer becomes necessary, we use an adequacy decision or Standard Contractual Clauses. (Model Providers your organisation enables receive Customer Content, not your account data; that is governed by the DPA and, for non-EU providers, the International Transfer Terms your organisation acknowledged.)

4. How long we keep it

  • Account and profile data: for the life of the account and up to 12 months after closure, then deleted or anonymised.
  • Billing records and invoices: 7 years (Dutch fiscal retention law).
  • Legal-document acceptance records: for the life of the account plus the applicable limitation period, as evidence that the contract was concluded (Art. 17(3)(e) GDPR).
  • Operator audit events and request metadata: for the life of the account plus the applicable limitation period (append-only records needed for billing integrity and as compliance evidence); other security logs up to 12 months, longer only where needed for an ongoing investigation.
  • Contact correspondence: up to 24 months after resolution.

5. Your rights

You have the right to access, rectify, erase, and receive a copy of your personal data, to restrict or object to processing based on legitimate interest, and to withdraw consent where processing is based on consent. Write to info@sevenlab.ai; we respond within one month. You can also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or the authority of your place of residence.

6. Security

We apply the measures described in the DPA's technical-and-organisational annex to all systems, including encryption in transit and at rest for sensitive stores, envelope encryption of credentials, per-tenant isolation, tamper-evident audit chains, and role-based access with mandatory re-verification on every administrative request.

7. Changes

We may update this policy; each version carries a version number and effective date. Material changes are announced in the Console and require acknowledgment before continued use. This document is drafted in English; the English version is the binding one.

Sluis ist ein Produkt der 7Lab B.V., Amsterdam, Niederlande (KVK 84815515).

Sluis

Die Schleuse zwischen Ihren Entwicklern und allen, die sie prüfen. Eine API für jedes KI-Modell: Sie entfernt personenbezogene Daten vor dem Abgang, stellt sie in der Antwort wieder her und versiegelt jede Passage in einem Audit-Register. Konform per Default, EU-souverän, bis Sie anders entscheiden. Gebaut unter dem Meeresspiegel, in Amsterdam.

ProduktSo funktioniert esPreiseLeistungSicherheit & ComplianceEnterpriseKonsole
EntwicklerSchnellstartAPI-ReferenzKonsole öffnen
UnternehmenÜber unsTrust CentreKontaktKarriere
RechtlichesTerms of ServicePrivacy PolicyDPA
© 2026 7Lab B.V. · Amsterdam, NL · Sluis ist ein Produkt der 7Lab B.V. (KVK 84815515)Gebaut unter dem Meeresspiegel · AmsterdamISO 27001 zertifiziert