1. Who we are
Glimps is registered with the Dutch Chamber of Commerce under number 94781745, at Sint Lambertusweg 18, 5953 CJ Reuver, the Netherlands. VAT identification number NL005109001B71.
We provide a platform for automated invoice processing for businesses. In this statement we call ourselves "Glimps" or "we".
For all privacy questions and for requests about your data: [email protected].
Wouter Murmans is responsible for privacy and security within Glimps. We have not appointed a Data Protection Officer. Given our size and our activities, that is not currently a legal requirement.
2. Two roles: controller and processor
This distinction tells you who to contact.
For the content our customers process in Glimps (invoices, emails, supplier data, accounting data) the customer is the controller and we are the processor. We process that data only on the instructions of that customer, under a data processing agreement. Does your name appear on an invoice that one of our customers processes? Then send your request to that company. We support that company in handling it.
For our own processing (accounts, billing, analytics, marketing, security) we are the controller ourselves. The rest of this statement is about that.
3. What data do we process, and why?
| Data | Purpose | Legal basis |
|---|---|---|
| Account data: name, business email address, encrypted password, two-factor data, role and company link | Access to and security of the platform | Performance of the contract |
| Billing data: company name, billing address, email address, VAT number, Chamber of Commerce number, payment status | Billing and administration | Performance of the contract and legal obligation (tax retention duty) |
| Payment data | Processing payments | Performance of the contract. Payments run through Mollie B.V. We do not receive full payment details |
| Platform usage data: page visits, click behaviour, device and browser information, and session replay | Security, error investigation and product improvement | Legitimate interest. See section 4 below for the details and for your right to object |
| Website visits on useglimps.com | Website statistics and improvement | Your consent. Without consent we do not load these services |
| Contact and demo forms: name, email address, company, message | Answering your enquiry | Legitimate interest in following up a business enquiry |
| Live chat conversations | Answering questions and providing support | Legitimate interest in the content of a conversation you start. The chat widget loads only after your cookie consent |
| Demo booking data: name, email address, chosen time and your answers | Scheduling and following up an appointment | Pre-contractual measures at your request |
| Email notification preferences | Notifications about invoices awaiting your approval | Performance of the contract |
| Technical logs, error logs and security logs | Security, abuse prevention and troubleshooting | Legitimate interest |
| Support correspondence | Support | Performance of the contract |
We do not deliberately process special categories of personal data. Because customers supply free text, emails and documents, such data may incidentally appear in customer data. Customers must avoid this unless they have a valid legal basis.
We do not take automated decisions producing legal effects for individuals within the meaning of Article 22 GDPR. Our AI makes proposals for a business administration. The customer decides which review and approval steps follow.
4. Product analytics and session replay in the platform
We use PostHog for product analytics and session replay in the platform. This is on by default.
What that means:
- It is enabled by default for all platform users. There is no separate banner in the platform.
- The configuration masks all input fields and all displayed text. We therefore do not capture invoice content, amounts or free text in recordings.
- We use it for security, error investigation and product improvement. Not for advertising and not for profiling individual users.
- The data is held in a European PostHog data centre. PostHog, Inc. is a US company. Standard contractual clauses apply to that relationship.
You can object to this. Send an email to [email protected] from your account email address. We will then disable analytics and session replay for your user. This does not affect your use of the platform.
Administrators who want to make a request for their whole organisation can say so in the same email.
5. AI processing
Glimps uses AI to automate invoice work. For this we engage Google and OpenAI, exclusively through business API accounts. Which data is processed where, and which safeguards apply, is set out per provider in our subprocessor list.
We do not enable, with any provider, the setting that would allow that provider to use our customer data to train or improve its models.
Corrections made by users are used only within that customer's own account, to improve the proposals for that customer. We do not learn across customers.
Where you work with AI in the Service, we make that apparent. AI output remains identifiable as a proposal.
6. Who do we share data with?
We do not sell personal data. We share data with:
- Subprocessors that make our platform work: hosting, storage, sending and receiving email, AI and product analytics. The current list, with countries and safeguards, is at useglimps.com/en/subprocessors.
- Service providers for our website and sales: Google Analytics and Microsoft Clarity for website analysis, Crisp for live chat, Cal.eu for scheduling and Mollie for payments. Per service we share only what that function needs.
- Systems the customer connects, such as Exact Online and Microsoft 365. This happens only on the customer's instruction.
- Authorities, where we are legally required to do so.
Our storage of customer data is in the European Union. However, we do not make an absolute EU promise, because that would not be true for every service. Our outgoing email runs through a US provider, one AI component is not bound to a region, and several providers have support staff outside the EEA who may have access in exceptional cases.
For transfers outside the EEA we use a valid mechanism: an adequacy decision, the EU-US Data Privacy Framework, or standard contractual clauses. Which provider processes where, and which mechanism applies, is stated per party in the subprocessor list.
7. How long do we keep data?
Full periods are in our retention policy. In short:
- Account data: for as long as the account exists, and for 90 days after that, except data we are legally required to keep longer.
- Our own invoices to customers: 7 years, under the Dutch tax retention duty.
- Customer data (invoices and similar): during the term of the contract. After termination we keep your data for a further 90 days, so you can export or reopen your account without loss. After that we delete the data from our production environment within 30 days. If you want longer retention, request it in writing.
- Backups: copies of deleted data may remain in a backup for at most 30 days. We use backups only for recovery after an incident.
The statutory 7-year retention duty for invoices remains with the customer. Glimps is the layer where you do invoice work, not your legal archive. Make sure invoices are stored in Exact Online or another auditable archive.
8. How do we secure data?
Our full overview is at useglimps.com/en/security-measures. In short: encrypted connections, encrypted storage at our hosting providers, two-factor authentication, role-based access, row-level security in the database and an audit trail per invoice.
We do not hold ISO 27001 or SOC 2 certification and we do not currently commission periodic external security audits.
9. Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection. Consent you have given, for example for cookies, can be withdrawn at any time.
Send your request to [email protected]. We respond within one month.
You can also lodge a complaint with the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl.
10. Connected mailboxes
When a customer connects a mailbox, for example [email protected], we read messages in that mailbox to recognise invoices.
In doing so we process the sender address, the subject, the message content for classification, attachment names, the attachments themselves and the classification result. In our own database we keep metadata and the recognised invoice attachments. The received message is stored temporarily in the European Union until we have processed it, and is deleted within 30 days.
The customer is responsible for informing employees whose mailbox is connected.
11. Changes
We may amend this statement. For material changes we inform users by email or in the platform.
This is version 1.0 and it is effective from 9 August 2026.
Questions about this document? [email protected]