Your data
Where we keep it, who can see it, what AI providers receive, and what we never do with it.
Last updated 4 September 2026
Where your data lives
All customer data is stored on Amazon Web Services in the EU. It is encrypted in transit and at rest. The database is on a private network with no public address.
Who can see it
- Your users, through your product. They see only the data your integration gives them access to.
- Our operators, when they support you or investigate a problem. Operator accounts need two-factor login, and every access is logged.
- Nobody else. Each customer is a separate tenant. No customer can see another customer's data.
What AI providers receive
To answer a question or check a document, we send that request to a large language model. Here is exactly what that means:
- We send only the part of the data that request needs. Not your database, not a document archive.
- The provider answers, and we store the answer with the rest of your data, in the EU.
- Every request is sent under a zero-retention policy. The provider does not keep the request, does not keep the answer, and does not use either to train its models.
- Providers never connect to our systems. There is no path from a provider back into your data.
- Answers and document processing run on AI models inside the EU.
Providers we use
Your data is stored on Amazon Web Services in the EU, encrypted. Answers and document processing run on AI models inside the EU, under zero-retention terms. We work with a small number of AI providers; the full list is part of our data processing agreement and available on request.
What we do with your data
- We use it to run the service for you.
- We use it to test and improve our answers. This work happens inside our team.
- We produce statistics across many companies, for example how a sector is trending. These statistics are published only above a minimum group size, so no company and no person can be identified in them.
What we never do
- We never sell your data.
- We never train AI models on it.
- We never move records from one customer to another.
- We never give a provider access to our systems.
How long we keep it
For as long as you use InvisiDocs. When you ask us to delete your data, we delete everything we hold for your account in a single step and confirm to you what was deleted. Records that were replicated from a partner platform are deleted by that partner, and the deletion flows through to us automatically.
Security, in plain terms
- Encrypted connections everywhere, encrypted storage in the EU.
- Private network, no public database endpoint.
- Two-factor login for operators, with every access logged.
- Automatic monitoring that alerts the team when something fails.
We do not hold a SOC 2 or ISO 27001 certificate yet. We will say so on this page when we do.
Your rights
Under data protection law, including the EU GDPR and the national laws that apply where you live, you can ask what we hold about you, have it corrected or deleted, and object to how it is used. Write to info@invisidocs.ai and we answer within 2 business days.
Questions we get asked
Who do you share the customer data with?
With nobody, apart from the AI providers that answer requests, and only the part of the data each request needs. They keep nothing. Your data is stored on Amazon Web Services in the EU and does not leave our database. AI providers never access our systems.
Do you sell or use my data with others?
We never sell it. We use it to improve our answers, inside our team, and we do not train AI models on it. The only thing that leaves your account is statistics aggregated across many companies, published only above a minimum group size, so nothing can be traced back to you.
Can InvisiDocs staff read my data?
Operators can, when they support you or investigate a problem. Their accounts need two-factor login and every access is logged. We would rather tell you this than claim otherwise.
Where do AI requests get processed?
Inside the EU. Answers and document processing run on AI models located in the EU, and every request runs under zero-retention terms.
The data controller is İnvisiDocs Teknoloji Anonim Şirketi, Bilkent CyberPark, Çankaya, Ankara, Türkiye. The early access form has its own privacy notice.