This schedule is incorporated by clause 9.1 of the terms of use. It sets out TIF Synergy Ireland Limited’s obligations as processor under Article 28 GDPR. Annex 2, the sub-processor list, is published separately at /legal/sub-processors/ under its own version identifier.
2026-08-31.Downloadable copy. This schedule must be provided in a form you can store and reproduce. A link to this page is not that; the PDF below is.
Download PDFTIF Synergy Ireland Limited, named above, is the processor under this schedule for every Suite customer from 28 August 2026, wherever the customer is established, including in the Netherlands. Blauw Belastingen B.V., a private limited company incorporated in the Netherlands, KvK 58905375, registered office Oudezijds Achterburgwal 173, 1012 DJ Amsterdam, the Netherlands, operates the tools for it and is its sub-processor, listed at row 11 of annex 2.
For a customer established in the Netherlands the processor changes with the contracting entity, on the same condition as the terms of use: only once separate terms published by Blauw Belastingen B.V. are in force and the customer has accepted them. Until then this schedule continues to apply in full.
Version: 2026-08-31-IE. Applies from: 31 August 2026. Sub-processor list: annex 2, which carries its own version identifier and changes under clause DP6.
Which of our companies you are contracting with. These terms apply where your contracting entity is TIF Synergy Ireland Limited. From 28 August 2026 to 13 September 2026 that is every user of a TIF Suite tool, wherever your organisation is established, including in the Netherlands. From 14 September 2026 a second set of terms becomes available for organisations established in the Netherlands, under which the contracting entity is Blauw Belastingen B.V., published at https://www.tifsynergy.com/legal/nl/terms-of-use/; if your organisation is established in the Netherlands your contracting entity changes only when those terms are in force and you have accepted them, and until then these terms continue to apply to you. How we decide whether your organisation is established in the Netherlands is at clause DP1.5.
This schedule forms part of the TIF Suite terms of use. Words defined in those terms have the same meaning here. Where this schedule and the rest of the terms conflict on the handling of personal data, this schedule governs.
DP1.1 This schedule applies where we process personal data on your behalf in connection with a tool. For that processing you are the controller and we are the processor. In this schedule "personal data", "controller", "processor", "sub-processor", "processing", "personal data breach" and "supervisory authority" have the meanings given in the General Data Protection Regulation (Regulation (EU) 2016/679).
DP1.2 Who we are. We are TIF SYNERGY IRELAND LIMITED, a private company limited by shares incorporated in Ireland, registered number 821025, registered office 77 Camden Street Lower, Dublin, D02 XE80, Ireland, VAT identification number IE4760769WH.
The tools are developed and provided by Blauw Belastingen B.V., trading as TIF Synergy, a private limited company incorporated in the Netherlands, KvK 58905375 and are supplied to you under these terms by us. Blauw operates the tools for us and is our sub-processor. It is listed in annex 2 and clause DP6.2 explains what that means for you.
Supervisory authorities, stated for each thing we do rather than in the abstract. For the personal data we process on your behalf under this schedule, you are the controller and your own supervisory authority is the competent one; we do not displace it. For the data we hold as controller, described at clause DP1.3, our supervisory authority is the Data Protection Commission in Ireland. Blauw is established in the Netherlands and its supervisory authority is the Autoriteit Persoonsgegevens. You may in any case complain to the supervisory authority of the place where you live or work.
DP1.3 What this schedule does not cover. We are the controller, not your processor, for the data we hold about the individual people who use a tool: their account, their sign-in, their preferences and the record of what they did in the tool. That is described in our privacy notice and it is not governed by this schedule. You are not asked to authorise anything in relation to it and you are not responsible for it. Annex 2 tells you which of our providers touch which of the two.
DP1.4 Nothing in this schedule makes either of us a joint controller with the other.
DP1.5 How we decided which of our companies you contract with. Between 28 August 2026 and 13 September 2026 there is nothing for this clause to decide: your contracting entity is TIF Synergy Ireland Limited whatever you tell us. For the change described in the header of this schedule, which begins on 14 September 2026, we work out whether your organisation is established in the Netherlands from two things your organisation gives us: the VAT identification number, a number beginning NL meaning the Netherlands and any other prefix meaning somewhere else, and the registered office address. Where we hold both, we read both. Where we hold only one, that one decides. Where the two point in different directions, the Netherlands answer applies. Where we hold neither, your contracting entity does not change and these terms continue to apply to you. That answer does not change unless we agree it with you in writing, so a later change in where your organisation is established does not by itself move your contract to the other company.
DP1.6 When we say "we do" something, we may do it through a sub-processor. Where this schedule says we do, hold, operate or provide something, we may do it ourselves or through a sub-processor listed in annex 2. We remain fully liable to you for it under clause DP6.3.
DP2.1 The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subject are set out per tool in annex 1.
DP2.2 Duration. We process for as long as the terms of use are in force between us, plus the period in clause DP10.
DP2.3 Your obligations as controller: lawfulness. You warrant that you have a lawful basis under Article 6 of the General Data Protection Regulation and where relevant a condition under Article 9 or Article 10, for the content you put into a tool and for our processing of it on your behalf and that the instructions you give us are lawful.
DP2.4 Your obligations as controller: telling your own data subjects. You are responsible for giving the individuals whose personal data appears in your content the information they are owed under Articles 13 and 14. That includes the people described in annex 1 who are not your own staff, in particular the people you invite to complete a questionnaire in TaxTrack, who are not party to our terms with you and may not know we hold anything about them.
DP2.5 Your obligations as controller: the categories at annex 1. You undertake not to put into a tool the categories of data annex 1 asks you not to put in and you accept that we do not detect them and do not claim to.
DP2.6 Your obligations as controller: keeping your administrator contact current. You keep the administrator contact on your account accurate, because that is the address the notice mechanism at clause DP6.4 uses and it is how your right to object under DP6.5 reaches you.
DP2.7 Your rights under this schedule, in one place. You instruct us and we act only on those instructions (DP3). You authorise our sub-processors, you are told before the list changes and you may object (DP6). You are told about a personal data breach (DP9.1) and we help you with your own assessments (DP9.2). You choose whether we delete or return your content (DP10.1). You may ask us for the information that demonstrates our compliance and you may audit us (DP11).
DP3.1 We process personal data on your behalf only on your documented instructions, including in relation to transfers of personal data to a country outside the European Economic Area, unless we are required to process by Union or Irish law that applies to us or a sub-processor we engage is required to process by Union law or by the law of the member state that applies to it. Where that happens we will tell you before we process, unless that law forbids us to tell you on important grounds of public interest.
DP3.2 What counts as your instructions. Your instructions are: the terms of use including this schedule, your configuration and use of the tool and any further written instruction you give us. We have no other instructions and we act on no others.
DP3.3 We do not use your content for our own purposes. We do not process the content you put into a tool for any purpose of our own. In particular we do not use it to train, fine-tune, evaluate or improve any artificial-intelligence model, ours or anyone else's, we do not use it to develop or improve our products and we do not use it to produce statistics or insights beyond operating the tool for you. This applies to Blauw Belastingen B.V. as it applies to us. What the other providers listed in annex 2 may do with your content is at DP3.3.2, which states the one exception rather than leaving it to be found.
DP3.3.1 We do not make your content available to another customer, except where one of your own users chooses to publish an item into a shared area of a tool. Annex 3 says which tools have such an area and what separation applies to each tool and a tool that has one tells the user at the point of publishing.
DP3.3.2 What our providers may do with your content, stated with the one exception rather than without it. The providers listed in annex 2 are engaged under written terms restricting them to processing on documented instructions and none of them is instructed to use your content for training, fine-tuning or model improvement. One of those providers also carries out security and abuse screening as part of providing the service, which is not something we instruct and which we cannot switch off. That is described at clause DP7.7. We would rather state the exception than state a rule that has one.
DP3.4 If we think an instruction is unlawful. If in our opinion an instruction you give us infringes the General Data Protection Regulation or another data-protection provision of Union or member state law, we will tell you immediately.
DP4.1 We make sure that every person we authorise to process personal data on your behalf is bound by a written confidentiality undertaking that survives the end of their engagement with us or is under an appropriate statutory or professional obligation of confidentiality.
DP4.2 We limit access to your content to the people who need it to provide, secure or support the tool. We record who has that access and when it was granted.
DP5.1 We implement and maintain the technical and organisational measures set out in annex 3, which are appropriate to the risk under Article 32 of the General Data Protection Regulation.
DP5.2 We may change those measures as technology and threats change. We will not reduce the overall level of security below what annex 3 describes and a change that lowers it is a change to these terms under clause 7.3 rather than an operational adjustment.
DP5.3 Annex 3 describes what we actually operate. It does not describe controls we intend to build. The same applies to every statement of fact in this schedule about how a tool behaves or what we are able to do and where a capability exists in some tools and not others we say so per tool rather than for the estate.
DP6.1 General authorisation. You give us a general authorisation to engage sub-processors to process personal data on your behalf, on the conditions in this clause DP6.
DP6.2 The current list and how the chain is put together. We engage one sub-processor directly: Blauw Belastingen B.V., which develops the tools and operates them for us. Blauw in turn engages the providers that host, index, read, screen and support the tools. All of them, ours and Blauw's, are listed in annex 2, which is published at a permanent address, is kept current and marks for each entry who engaged it.
Your authorisation under DP6.1 covers every entry in annex 2 marked as processing content you put into a tool, at both levels of the chain. The other entries are listed for transparency: they process data for which we are the controller, so they are not your sub-processors and you are not asked to authorise them.
DP6.3 Back-to-back terms and our liability, down every link. We engage Blauw under a written contract imposing data-protection obligations that are in substance the same as those in this schedule, in particular the obligation to provide sufficient guarantees of appropriate technical and organisational measures and that contract requires Blauw to impose the same obligations on every provider it engages. Where any of them fails to fulfil its data-protection obligations, we remain fully liable to you for its performance. That is so whether the failure is Blauw's or that of a provider Blauw engaged.
DP6.4 Notice of a change. Before we or Blauw add or replace a sub-processor that will process your content, at either level of the chain, we will give you at least 30 days' notice. Notice is given by updating annex 2 with the date the change takes effect and by emailing the administrator contact for your organisation, which you give us when your organisation is set up or when you first accept these terms.
DP6.5 Your right to object. You may object to an addition or replacement, at either level of the chain, on reasonable data-protection grounds, within those 30 days. If you object we will work with you to find a solution. If we cannot, you may stop using the affected tool and we will delete or return your content under clause DP10, at no cost to you and neither of us owes the other anything further in respect of that tool.
DP6.6 Urgent replacement. We may engage, or allow Blauw to engage, a replacement sub-processor immediately, without the 30 days, where it is necessary to keep the tool secure or available. We will tell you as soon as we reasonably can and your right to object under DP6.5 then runs from that notice.
DP6.7 A change to a sub-processor entry in annex 2 is us performing this clause. It does not change these terms and it does not need your agreement beyond the authorisation you have already given.
DP7.1 Where the tools run. All four tools are hosted in the European Economic Area, in Microsoft Azure regions inside it and are operated for us by Blauw Belastingen B.V. from the Netherlands. Annex 2 says which region each service runs in.
DP7.1.1 Where a tool sends a request to an AI service is a different question from where the tool is hosted, so we answer it separately rather than letting the answer to the first stand for both. TaxMap does not send anything to an AI service today. A mapping-proposal feature that does is being built. It is not available, and this schedule will state what it sends and where those requests are processed before it is made available. TaxTrack sends uploaded documents only to Microsoft's document-reading service in West Europe. TaxTag's AI processing runs on a deployment confined to Microsoft's EU data zone. TaxLex composes its answers on a deployment inside Microsoft's EU data zone by default and two of the models you can choose in TaxLex, gpt-5.4-nano and gpt-5.4-pro, are published by Microsoft only as globally routed deployments. Microsoft may process a request sent to either of those two in any region in which the model is deployed, including outside the European Economic Area. What that means for what you send is at DP7.2.
DP7.2 What leaves the European Economic Area and we would rather tell you than have you find it.
gpt-5.4-nano and gpt-5.4-pro, exist only as globally routed deployments, so when a user selects one of them Microsoft may process that request in any region in which the model is deployed, including outside the European Economic Area. What is sent is the text of the question and the material assembled to answer it. Content from documents in your library is not sent to either of those two models: where library content is in the material assembled to answer a question, TaxLex uses a deployment inside Microsoft's EU data zone instead. Where a TaxLex request is served from is not fixed in advance.DP7.2.1 One step happens on every TaxLex question whichever model is chosen, so we state it separately rather than inside a bullet about one of them. Before any model sees your question, TaxLex turns that question into a search vector using a Microsoft AI service. Everything said in DP7.3 about the safeguards applies to that step as well and annex 2 says where that step runs.
DP7.3 The transfer mechanism, described as it actually is rather than in the shorter version a reader might expect.
We make no transfer of your personal data outside the European Economic Area ourselves. We are established in Ireland and Blauw is established in the Netherlands. Your content moving from us to Blauw stays inside the European Economic Area, so it is not a transfer within Chapter V of the General Data Protection Regulation and it needs no transfer mechanism. We say that expressly rather than leaving you to work it out.
The transfers described in DP7.2 are made by Blauw, which holds the accounts with the providers concerned. We remain fully liable to you for them under clause DP6.3 and they are assessed under DP7.4.
For SendGrid the transfer is made directly by Blauw. Twilio's data protection addendum does not put a single mechanism behind it. It ranks two and applies whichever ranks highest and is available at the time, so we describe the ranking rather than naming the half of it a reader might expect.
Ranked first is the EU-US Data Privacy Framework. The addendum records that Twilio Inc. is self-certified under it, which brings the transfer within the European Commission's adequacy decision for that framework, Implementing Decision (EU) 2023/1795. Ranked behind it and designated by the addendum to apply automatically if that self-certification is withdrawn, terminated, revoked or otherwise invalidated are the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914: module three, processor to sub-processor, both for content you put into a tool and for the data we hold as controller about the people who use a tool, because in each case Blauw transfers as our processor rather than in its own right. Twilio must tell us in writing if the self-certification falls away. Twilio Inc. is the organisation self-certified under the framework and the named data importer under the clauses, whichever Twilio company holds the account, so this is the position either way.
We are telling you how the addendum is arranged. We are not offering the certification to you as a safeguard of ours and we do not ask you to rely on it. A self-certification can be withdrawn. The adequacy decision standing behind it is under challenge before the Court of Justice. That is exactly why the second mechanism is worth stating: if the first one goes, this transfer moves to signed clauses by the operation of the addendum itself rather than by a new negotiation with the provider.
Microsoft is different in structure and the difference matters to you. Blauw's contract is with Microsoft B.V., a company established in the Netherlands, so that transfer does not leave the European Economic Area at all. The transfers described in the third and fourth bullets of DP7.2 are made by Microsoft rather than by us or by Blauw and Microsoft is obliged to put its own safeguards on them. It does: the Microsoft Products and Services Data Protection Addendum annexes the 2021 standard contractual clauses between two Microsoft companies for transfers out of the European Economic Area and commits that all such transfers are subject to those clauses. Neither of our companies is a party to those clauses and neither describes itself as the exporter under them. What we hold instead is Microsoft's contractual commitment: that it will engage no other processor without the safeguards that addendum requires, that it remains fully liable for that processor's performance, that it will challenge and narrow any government demand for your data and never give unfettered access and that transfers may be suspended or the agreement terminated if the law changes to your material disadvantage. Microsoft's EU Data Boundary commitments sit alongside all of that. They are a commitment about where processing is performed. They are not a transfer mechanism. We do not rely on an adequacy decision for the Microsoft transfers described in DP7.2. The one route where an adequacy decision does operate is SendGrid. We set that out where we describe SendGrid rather than denying it here, because Twilio's addendum ranks the framework ahead of the clauses and a blanket denial would be untrue of one route in four.
DP7.4 Our assessment of those transfers. A transfer impact assessment covering every transfer of personal data outside the European Economic Area in connection with the tools has been carried out, using the six-step method in the European Data Protection Board's Recommendations 01/2020 read with the Court of Justice's judgment in *Schrems II* (C-311/18). We make it available to you on request.
DP7.5 Not used. This clause described what a provider of AI-assisted engineering and support tooling did with content that reached it. That provider is no longer engaged and its entry has been removed from annex 2 under clause DP6.2. The number is kept so that the numbering of this schedule does not move between versions.
DP7.6 What may enter an AI-assisted engineering or support session. The tools are built, maintained and supported for us by Blauw Belastingen B.V., using AI-assisted engineering and support software. Where a problem is investigated, data is migrated or a request you have raised with us is worked on, content held in a tool can enter that software. This is not a feature of any tool and it does not happen during your ordinary use of one. It happens when the service is worked on. The providers that may process your content on this route are the ones listed in annex 2, and no other. We restrict what may enter such a session. This clause is where that restriction binds us and clause DP6.3 makes us answerable to you for Blauw's observance of it. Synthetic or redacted data must be used first. Your content may enter such a session only where the task genuinely requires it and an extract cannot answer the question. Whole documents, national identification numbers, special category data and bulk exports must not enter such a session at all. A record is kept of the occasions when your content does enter one. We tell you on request how we give effect to these restrictions. Where a tool sends your content to a Microsoft AI service, clause DP7.7 applies to that as it applies to the tools.
DP7.7 What Microsoft does with content sent to its AI services. Where a tool sends your content to Microsoft's Azure OpenAI Service, Microsoft does not use it to train or improve its own models or OpenAI's. Microsoft's licence terms commit it not to use customer data to train any generative AI foundation model except on the customer's own documented instructions, and we give no such instruction. That is Microsoft's default position and not something we had to buy. Microsoft also runs abuse monitoring, which is a separate mechanism from training and is on by default.
What that involves, stated from Microsoft's licence terms rather than from the shorthand. Microsoft's terms say that, as part of providing the service, it temporarily stores what a tool sends to it and what the service sends back, in order to monitor for and prevent abusive or harmful use. Where its automated systems flag something, authorised Microsoft employees may review that content to investigate and verify potential abuse. For a customer whose deployment sits inside Microsoft's EU data boundary, Microsoft's terms commit that those authorised employees are located in the European Economic Area. We do not tell you that every deployment we use sits inside that boundary, because which of them do is not established. What we are able to say, tool by tool, is at DP7.1.1, and it records that two of the models selectable in TaxLex are published by Microsoft only as globally routed deployments. Microsoft's published documentation describes a narrower ordinary practice, under which content that is flagged and then reviewed by automated means is not additionally stored by the abuse-monitoring system and under which review by a person is the exception introduced where automated review does not meet Microsoft's confidence thresholds or is unavailable. Where Microsoft's licence terms and its documentation differ we tell you what the licence terms say. Where content is stored for abuse monitoring, Microsoft's published position is that the store sits in the geography your resource is in and that this is so whether the deployment is a globally routed one or a data-zone one, because a globally routed deployment changes where processing happens and not where data is kept at rest. Microsoft publishes no retention period for this store and we will not state one.
Switching it off requires Microsoft's approval for modified abuse monitoring, which we do not hold and for which, on Microsoft's published eligibility criteria, we do not expect to qualify. This is processing Microsoft carries out in order to provide the service rather than for a purpose of its own and Microsoft's own agreement limits the purposes it may pursue as an independent controller to billing, compensation, internal reporting and financial reporting, in each case without accessing or analysing the content you put into a tool.
DP8.1 Taking into account the nature of the processing, we help you by appropriate technical and organisational measures, so far as it is possible, to answer requests from individuals exercising their rights under Chapter III of the General Data Protection Regulation.
DP8.2 If an individual contacts us directly about content you put into a tool, we will not answer the substance of the request ourselves. We will tell them to contact you and we will pass the request on to you without undue delay.
DP8.3 How we help, in practice. We handle these requests by hand rather than through a feature in the tool. Ask us and a person deals with it. We aim to respond to you within five working days.
DP8.4 Two things we do not delete when we act on an erasure instruction. You should factor both into your own answer to the individual. The first is records we are required by law to keep. The second is the audit trail of who did what in the tool and what can be done to that trail differs by tool, so we say it per tool rather than for all four:
Where you need an audit record removed rather than retained, ask us and we will tell you what is possible in that tool before you answer the individual.
DP8.5 We cannot reach content Microsoft holds in the store it keeps for the abuse monitoring described at clause DP7.7. That store is not exposed to us, Microsoft publishes no retention period for it and switching the monitoring off requires an approval we do not hold.
DP9.1 Breaches. We notify you of a personal data breach affecting personal data we process on your behalf without undue delay and in any event within 72 hours of becoming aware of it. We become aware of it when we become aware of it or when any sub-processor we engage becomes aware of it, whichever is earlier. Our notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as we know them, the likely consequences and the measures we have taken or propose to take.
DP9.2 We help you meet your own obligations under Articles 32 to 36 of the General Data Protection Regulation, taking into account the nature of the processing and the information available to us. That includes helping you with a data protection impact assessment and with any prior consultation with a supervisory authority that you are required to carry out.
DP9.3 We tell you if we become aware that a feature of a tool, as you have configured it, is likely to affect your own assessment of the risk of the processing.
DP10.1 When the tool stops being provided to you, you choose whether we delete your content or return it. Tell us which. If you tell us nothing, we will give you at least 30 days from the day the tool stops being provided to get your content out and we will then delete it.
DP10.2 Where the tool has a self-service export you can use it yourself. Where it does not, ask us and we will get your content out to you within that period, in a structured, commonly used and machine-readable format wherever the tool allows one. We do this by hand rather than through a feature in the tool. If the format you need is not one the tool can produce, we will tell you what it can produce before the period runs out rather than at the end of it.
DP10.3 After that we delete the content and existing copies of it, unless Union or Irish law requires us to keep it or Union law or the law of the member state that applies to a sub-processor requires it to keep it, in which case we will tell you what is being kept and why.
DP10.4 Two exceptions you should know about. Backups are deleted on the ordinary backup rotation rather than immediately and remain protected by this schedule until they are. Audit records are treated as described in clause DP8.4.
DP11.1 We make available to you the information necessary to demonstrate compliance with Article 28 of the General Data Protection Regulation. We may do that through a standard response pack rather than a bespoke answer each time.
DP11.2 We allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. An audit is at your cost, on at least 30 days' written notice, during business hours, no more than once in any twelve-month period and conducted so as not to disrupt the tool or the confidentiality of our other customers' data.
DP11.3 The once-a-year limit does not apply where a supervisory authority requires an audit or where one follows a personal data breach affecting your content.
DP11.4 Your auditor must not be a competitor of ours and must sign a confidentiality undertaking before the audit begins.
DP11.5 Where the information you need or the audit you wish to carry out, concerns a sub-processor we engage, we will obtain it from that sub-processor or procure its cooperation. You do not have to deal with anyone but us.
DP12.1 This schedule carries the same version identifier as the terms of use it forms part of, and it is published in the same document, at the same address, in a form you can save and reproduce. Every superseded version stays available at a permanent address. The version identifier ends in -IE, which records that this is the version of the terms under which TIF Synergy Ireland Limited is your contracting entity.
DP12.2 If we change this schedule we will publish the changed version, say what changed and say the date it applies from and we will tell you before it applies. Clause 7.3 of the terms of use governs how we make that change.
DP12.3 Annex 2 is different and changes under clause DP6. It carries its own version identifier and its own dated record of changes. Updating annex 2 is us performing clause DP6. It is not a change to this schedule or to the terms.
DP12.4 When a change to annex 2 is also a change to this schedule. We treat a change to annex 2 as a change to this schedule under DP12.2 as well and give you notice accordingly, where it:
Anything else that is not simply a change of a provider's name, its role, the service it performs or its region within the European Economic Area and anything we are unsure about, we treat the same way. Each of these is something you rely on for your own record of processing and your own transfer assessment, so where there is doubt we would rather tell you twice than not at all.
This annex forms part of schedule DP and carries the same version identifier.
Subject matter and duration. The provision of the TIF Suite tool you use, for as long as the terms of use are in force between us, plus the period in clause DP10.
Nature and purpose. Hosting, storing, indexing, retrieving, transforming and displaying the content you put into the tool, so that the tool does what you use it for, together with securing it, backing it up, keeping an audit record of what was done in it and supporting you when you ask us to.
Types of personal data. Whatever personal data appears in the content you choose to put into a tool. You decide what that is and it is unbounded from our side. In practice it includes names, work contact details, job roles, ledger and payroll entries, entity and engagement details and the free text of documents, questions and responses. See the note below on data you should not put in at all.
Categories of data subject.
Per tool. The table below states, for each tool, what is stored about the user, what content is held, whether the tool is AI-assisted and what is sent, where it is hosted and how long each category is kept.
| Tool | What it stores about you as a user | What content it holds | AI, and what is sent | Where it is hosted | How long |
|---|---|---|---|---|---|
| TaxLex | Email, name, organisation, role, your saved preferences. Sign-in and session records. A log of your actions | The text of your questions, which TaxLex keeps. Your questions and the answers, saved as chat history. A separate short record of each question asked, shortened to the first 1000 characters. Feedback you give us. Prompts you save. Engagement details you enter. Files you upload to your library and the text extracted from them | Yes. Your question and the source passages found for it are sent to Microsoft's Azure OpenAI Service to compose the answer. Uploaded image-only PDFs are read by Microsoft's document-reading service. You choose which model answers. Two of the models offered, gpt-5.4-nano and gpt-5.4-pro, exist only as globally routed deployments, so Microsoft may process a request sent to either outside the EEA. Content from documents in your library is never sent to those two: where library content is in the material assembled to answer a question, TaxLex uses a deployment inside Microsoft's EU data zone instead | Azure West Europe. Answer composition runs on an account in Azure Sweden Central, which is in the EEA, on a deployment inside Microsoft's EU data zone by default. What leaves the EEA: account emails through SendGrid in the United States; the text of a question where Microsoft processes it on a globally routed deployment, which is the case whenever a user picks one of the two models named alongside; and Microsoft's own access to the services from outside the EEA, by the four routes set out at section 4.3 | Chat history up to 24 months from the last message, and you can delete a chat yourself at any time. The question record 90 days. Feedback 90 days. Session records 7 days. Uploaded files 24 months from last use. Audit records 7 years. Saved prompts and engagement details are kept until you delete them |
| TaxTag | No profile is stored. Your email, role and organisation are read from your sign-in for each request and held in your session. Your actions are recorded in an audit log against your sign-in identifier | Word templates, spreadsheets and mapping files you upload. Documents the tool generates. Templates you save to your library, whether private to you or shared with your organisation | Yes, in one place. When you ask for tag suggestions, the text of that document, including its headers and footers, is sent to Microsoft's Azure OpenAI Service. It is not sent at all unless you first declare the document contains no real client data. No structured data file is ever sent, and your name, email and the file name are not sent | Azure West Europe. The AI call runs on a deployment confined to Microsoft's EU data zone | Uploads and generated documents are deleted 24 hours after you finish with them. Library templates are kept until you delete them. Audit records 24 months, with your identity removed if you ask us to erase your data |
| TaxMap | Email, display name, your sign-in identifier, the date your account was created. Nothing else. We do not even store which organisation you belong to | Account listings, general ledger and trial-balance extracts you upload, held as you uploaded them. The working copy of that data. The mappings, transformations and cleaning steps you configure. A record of every material action | Not today. TaxMap's column-matching suggestions compare column names against a fixed dictionary and by ordinary text matching, and nothing you put into TaxMap is sent to any AI provider. A mapping-proposal feature that does use AI is being built and will be made available. When it is, the names of your columns and the mapping structure you have configured are sent to Microsoft's Azure OpenAI Service. The figures, ledger lines and account balances in your file are not sent | Azure West Europe. Where the mapping-proposal requests will be processed is not established and clause DP7.1.1 will state it before that feature is made available. Microsoft's own access to the services from outside the EEA applies, by the four routes at clause DP7.2 | Kept until you delete the workflow, which deletes what belongs to it. There is no automatic deletion timer. Audit records are kept long-term |
| TaxTrack | Email, your role, your sign-in identifier, the date you were added. A record of your sign-ins and sign-outs, which includes your IP address and browser. Your acknowledgement of our disclaimer, with the version and the date | Your workflows, tasks, deadlines, sign-offs and rejections and who is responsible for each one. Assessment notices and other documents you upload and the fields read out of them. Questionnaire responses, including from people outside your organisation you invite | No chat or text generation. Uploaded assessment notices are read by Microsoft's document-reading service, which pulls out fields such as amounts, dates and names using a standard pre-trained model. A person confirms what it read before it enters the record. Dutch social-security numbers are removed at two points: when a document you upload is read and again when a person confirms what was read. They are not removed from every record the tool keeps | Azure West Europe, including the email service, which is set to hold data in Europe. Nothing leaves the EEA | Workflows are kept while they exist. Uploaded documents move to cheaper storage at 7 years and are deleted at 10 years, matching the longest record-keeping rule we cover. In-app notifications 90 days. The audit trail is kept indefinitely and is not deleted on an erasure request, because it is the evidence trail of a tax record |
Do not put a Dutch burgerservicenummer, an Irish personal public service number or any equivalent statutory identification number of another country, into any tool. We have no statutory basis to hold one.
Do not rely on any tool to take one out for you. No tool in the Suite is a filter, none of them is designed to detect a statutory identification number and we do not claim that any of them does. Where a tool carries out any removal of its own, it is a convenience inside that tool and it is not something you should build a process on.
Please also think carefully before uploading documents containing special category data within Article 9 or criminal-offence data within Article 10. The tools have no capability to detect either and we do not claim one.
Annex 2 is published as a separate document at https://www.tifsynergy.com/legal/sub-processors/. It carries its own version identifier, SUBPROCESSOR_LIST_VERSION, its own dated record of changes, and every superseded version stays available at that address followed by that version's identifier.
It is published separately on purpose. Under clause DP6 we can change a sub-processor entry without changing these terms, so the list has to be able to change while this schedule does not. We record the version of annex 2 that was in force when you accepted, together with its address, so that what you were shown can be identified later.
This annex forms part of schedule DP and carries the same version identifier. It describes measures operated today, not measures we intend to build. Clause DP1.6 applies: these measures are operated for us by Blauw Belastingen B.V. and we remain fully liable to you for them under clause DP6.3.
Common to all four tools. Each of these applies to every tool without qualification.
What separates your data from another customer's, stated per tool because the mechanism genuinely differs.
The record of what happened in a tool, stated per tool for the same reason.
Measures in individual tools that go beyond that baseline.
What we do not have, stated so you do not have to ask.