Legal

Privacy Statement

Version 1.0 · effective 9 August 2026

1. Who we are

Glimps is registered with the Dutch Chamber of Commerce under number 94781745, at Sint Lambertusweg 18, 5953 CJ Reuver, the Netherlands. VAT identification number NL005109001B71.

We provide a platform for automated invoice processing for businesses. In this statement we call ourselves "Glimps" or "we".

For all privacy questions and for requests about your data: [email protected].

Wouter Murmans is responsible for privacy and security within Glimps. We have not appointed a Data Protection Officer. Given our size and our activities, that is not currently a legal requirement.

2. Two roles: controller and processor

This distinction tells you who to contact.

For the content our customers process in Glimps (invoices, emails, supplier data, accounting data) the customer is the controller and we are the processor. We process that data only on the instructions of that customer, under a data processing agreement. Does your name appear on an invoice that one of our customers processes? Then send your request to that company. We support that company in handling it.

For our own processing (accounts, billing, analytics, marketing, security) we are the controller ourselves. The rest of this statement is about that.

3. What data do we process, and why?

DataPurposeLegal basis
Account data: name, business email address, encrypted password, two-factor data, role and company linkAccess to and security of the platformPerformance of the contract
Billing data: company name, billing address, email address, VAT number, Chamber of Commerce number, payment statusBilling and administrationPerformance of the contract and legal obligation (tax retention duty)
Payment dataProcessing paymentsPerformance of the contract. Payments run through Mollie B.V. We do not receive full payment details
Platform usage data: page visits, click behaviour, device and browser information, and session replaySecurity, error investigation and product improvementLegitimate interest. See section 4 below for the details and for your right to object
Website visits on useglimps.comWebsite statistics and improvementYour consent. Without consent we do not load these services
Contact and demo forms: name, email address, company, messageAnswering your enquiryLegitimate interest in following up a business enquiry
Live chat conversationsAnswering questions and providing supportLegitimate interest in the content of a conversation you start. The chat widget loads only after your cookie consent
Demo booking data: name, email address, chosen time and your answersScheduling and following up an appointmentPre-contractual measures at your request
Email notification preferencesNotifications about invoices awaiting your approvalPerformance of the contract
Technical logs, error logs and security logsSecurity, abuse prevention and troubleshootingLegitimate interest
Support correspondenceSupportPerformance of the contract

We do not deliberately process special categories of personal data. Because customers supply free text, emails and documents, such data may incidentally appear in customer data. Customers must avoid this unless they have a valid legal basis.

We do not take automated decisions producing legal effects for individuals within the meaning of Article 22 GDPR. Our AI makes proposals for a business administration. The customer decides which review and approval steps follow.

4. Product analytics and session replay in the platform

We use PostHog for product analytics and session replay in the platform. This is on by default.

What that means:

  • It is enabled by default for all platform users. There is no separate banner in the platform.
  • The configuration masks all input fields and all displayed text. We therefore do not capture invoice content, amounts or free text in recordings.
  • We use it for security, error investigation and product improvement. Not for advertising and not for profiling individual users.
  • The data is held in a European PostHog data centre. PostHog, Inc. is a US company. Standard contractual clauses apply to that relationship.

You can object to this. Send an email to [email protected] from your account email address. We will then disable analytics and session replay for your user. This does not affect your use of the platform.

Administrators who want to make a request for their whole organisation can say so in the same email.

5. AI processing

Glimps uses AI to automate invoice work. For this we engage Google and OpenAI, exclusively through business API accounts. Which data is processed where, and which safeguards apply, is set out per provider in our subprocessor list.

We do not enable, with any provider, the setting that would allow that provider to use our customer data to train or improve its models.

Corrections made by users are used only within that customer's own account, to improve the proposals for that customer. We do not learn across customers.

Where you work with AI in the Service, we make that apparent. AI output remains identifiable as a proposal.

6. Who do we share data with?

We do not sell personal data. We share data with:

  • Subprocessors that make our platform work: hosting, storage, sending and receiving email, AI and product analytics. The current list, with countries and safeguards, is at useglimps.com/en/subprocessors.
  • Service providers for our website and sales: Google Analytics and Microsoft Clarity for website analysis, Crisp for live chat, Cal.eu for scheduling and Mollie for payments. Per service we share only what that function needs.
  • Systems the customer connects, such as Exact Online and Microsoft 365. This happens only on the customer's instruction.
  • Authorities, where we are legally required to do so.

Our storage of customer data is in the European Union. However, we do not make an absolute EU promise, because that would not be true for every service. Our outgoing email runs through a US provider, one AI component is not bound to a region, and several providers have support staff outside the EEA who may have access in exceptional cases.

For transfers outside the EEA we use a valid mechanism: an adequacy decision, the EU-US Data Privacy Framework, or standard contractual clauses. Which provider processes where, and which mechanism applies, is stated per party in the subprocessor list.

7. How long do we keep data?

Full periods are in our retention policy. In short:

  • Account data: for as long as the account exists, and for 90 days after that, except data we are legally required to keep longer.
  • Our own invoices to customers: 7 years, under the Dutch tax retention duty.
  • Customer data (invoices and similar): during the term of the contract. After termination we keep your data for a further 90 days, so you can export or reopen your account without loss. After that we delete the data from our production environment within 30 days. If you want longer retention, request it in writing.
  • Backups: copies of deleted data may remain in a backup for at most 30 days. We use backups only for recovery after an incident.

The statutory 7-year retention duty for invoices remains with the customer. Glimps is the layer where you do invoice work, not your legal archive. Make sure invoices are stored in Exact Online or another auditable archive.

8. How do we secure data?

Our full overview is at useglimps.com/en/security-measures. In short: encrypted connections, encrypted storage at our hosting providers, two-factor authentication, role-based access, row-level security in the database and an audit trail per invoice.

We do not hold ISO 27001 or SOC 2 certification and we do not currently commission periodic external security audits.

9. Your rights

You have the right of access, rectification, erasure, restriction, data portability and objection. Consent you have given, for example for cookies, can be withdrawn at any time.

Send your request to [email protected]. We respond within one month.

You can also lodge a complaint with the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl.

10. Connected mailboxes

When a customer connects a mailbox, for example [email protected], we read messages in that mailbox to recognise invoices.

In doing so we process the sender address, the subject, the message content for classification, attachment names, the attachments themselves and the classification result. In our own database we keep metadata and the recognised invoice attachments. The received message is stored temporarily in the European Union until we have processed it, and is deleted within 30 days.

The customer is responsible for informing employees whose mailbox is connected.

11. Changes

We may amend this statement. For material changes we inform users by email or in the platform.

This is version 1.0 and it is effective from 9 August 2026.

Questions about this document? [email protected]