Version 2026-08-28, applies from this date

Privacy Policy

Which personal data Instant Process processes, for what purpose, who it is shared with, how long it is kept and what rights data subjects have.

1. Who is responsible for the processing?

Instant Process, with its registered office at Doelenstraat 118, 2611 NW, Delft, registered in the Commercial Register under Chamber of Commerce number 42140557, is the data controller for the personal data it processes for its own business operations and the provision of its services. Instant Process operates a platform for modelling, visualising, analysing and managing business processes (hereinafter: ‘the platform’).

If you have any questions regarding privacy or the processing of personal data, please contact us at info@instantprocess.nl.

Instant Process processes personal data with due care and in accordance with the General Data Protection Regulation (GDPR).

2. What personal data does Instant Process process, and where does it come from?

The personal data that Instant Process processes depends on how a person comes into contact with Instant Process and on the features used. This may include, amongst other things, name, email address, account, login and identification details, organisation and team details, details of the chosen subscription, contact and communication details, quotation, contract and customer details, invoice, payment and administrative details, and technical details such as IP addresses, browser, device, session and log data.

Instant Process may also process data relating to the use of its website and platform. Within the platform, process models, comments, project data and other user content may be processed. Where such data contains personal data, that personal data will also be processed. When using AI functionalities, prompts, texts, process information and other data provided by the user may be processed, amongst other things.

Personal data may be obtained directly from the data subject, for example when creating an account, taking out a subscription, making a payment or getting in touch.

Instant Process may also receive personal data indirectly. This may occur, for example, when a business customer, employer or other organisation designates an individual as a user of the platform or provides that person’s details in connection with the performance of an agreement. In addition, Instant Process may receive personal data when a user on the platform includes data relating to other individuals in user content.

Instant Process processes personal data for the purposes of creating and managing accounts, granting access to the platform, entering into and performing agreements, invoicing and payments, financial administration, customer and relationship management, communication, support, security, access control, fraud prevention, error detection and technical management. In addition, Instant Process processes personal data to the extent necessary to comply with legal and administrative obligations.

Depending on the purpose, the processing is based on the performance of an agreement or on taking steps prior to entering into an agreement, a legal obligation, a legitimate interest of Instant Process, or the consent of the data subject.

Where Instant Process invokes a legitimate interest, this relates, for example, to its interest in providing secure and properly functioning digital services, sound business operations, the prevention of misuse and fraud, or the maintenance of business relationships.

Where consent forms the legal basis, such consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of any processing carried out prior to the withdrawal.

The provision of personal data may be necessary for the creation or use of an account, the conclusion or performance of an agreement, the making of a payment, or compliance with a legal obligation. If the personal data required for these purposes is not provided, Instant Process may not be able to conclude or perform the relevant agreement.

4. Personal data in user content and AI functionalities

The platform is primarily intended for modelling, visualising, analysing and managing business processes, and is not specifically designed for the processing of personal data. However, users may themselves include personal data in, for example, process models, process descriptions, comments, imported files, chat messages or other user content.

Instant Process uses an external AI provider for its AI functionalities. Data that a user deliberately submits to this functionality, such as prompts, process information, text or data from imported files, may be processed via that AI provider’s infrastructure.

Where a business customer determines which personal data is processed within the platform and for what purpose, and Instant Process processes this personal data exclusively on behalf of that customer, Instant Process acts as the data processor in respect of that personal data and the customer as the data controller. The relevant arrangements are set out in the data processing agreement within Instant Process’s general terms and conditions.

This privacy policy essentially describes the processing operations for which Instant Process itself is the data controller.

5. With whom is personal data shared?

Instant Process may engage external parties in the course of its business operations and service provision. Personal data may, where necessary, be shared with hosting, cloud and infrastructure providers, AI providers, payment service providers, CRM suppliers, suppliers of accounting and administration software, backup and IT service providers, external technical suppliers, bookkeepers, accountants, administrative service providers, legal advisers and other professional service providers.

Among other things, Instant Process uses a CRM system for customer and commercial processes. The platform is primarily hosted via an external hosting environment in the Netherlands.

That hosting environment is Scaleway, in the Amsterdam region (nl-ams). Instant Process uses Mistral AI for its AI functionalities.

Where a third party processes personal data on behalf of Instant Process, arrangements will be made where necessary regarding, amongst other things, confidentiality, security and processing solely on behalf of Instant Process.

6. Transfer outside the European Economic Area

Depending on the suppliers, technical infrastructure and sub-processors used, personal data may be processed outside the Netherlands and possibly outside the European Economic Area. This may be particularly relevant in the case of certain AI, cloud or other technical service providers.

Where personal data is transferred outside the European Economic Area, Instant Process ensures that there is a valid legal basis for such a transfer, for example an adequacy decision by the European Commission, approved standard contractual clauses or another legally permissible safeguard.

Insofar as Instant Process is the data controller for the processing in question, a data subject may request further information via info@instantprocess.nl regarding the applicable legal basis for the transfer and, where available and required by law, regarding the appropriate safeguards used in that context.

7. How long is personal data retained?

Instant Process does not retain personal data for longer than is necessary for the purpose for which it was collected, unless a legal obligation or a legitimate interest justifies longer retention.

Account data is, in principle, retained for as long as the account remains active and, thereafter, for as long as it is necessary for administrative, security, evidential or dispute resolution purposes. Invoice and administrative data is retained for the duration of the applicable statutory retention periods. Customer communications and CRM data are retained for as long as is reasonably necessary for customer and relationship management, the provision of evidence, and the resolution of enquiries or disputes. Technical and security data are retained for as long as is necessary for security, monitoring, fault-finding and incident management.

User content may be deleted by the user and will be deleted following the termination of the account or the agreement in accordance with the applicable contractual and technical retention periods. Data may remain temporarily in backups after deletion until it is overwritten or deleted in accordance with the regular backup cycle.

8. Security

Instant Process takes appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration, destruction or any other unlawful processing.

The nature of the security measures is determined, amongst other things, by the nature and scope of the processing, the technology used and the potential risks to data subjects.

9. Automated decision-making

Instant Process’s AI functionalities can automatically analyse data and, based on this, generate suggestions, analyses or other output.

Instant Process does not, for its own purposes, make any decisions based solely on automated processing which produce legal effects concerning data subjects or which otherwise significantly affect them.

Where a business customer has personal data analysed within the platform and makes decisions on that basis, that customer is responsible for assessing whether automated decision-making or profiling within the meaning of the GDPR is taking place, and which obligations apply in that regard.

10. Rights of data subjects

Insofar as Instant Process acts as the data controller, a data subject may, depending on the circumstances, request access to their personal data, the rectification of inaccurate personal data, the erasure of personal data, the restriction of processing or the transfer of personal data. In eligible cases, a data subject may also object to processing or withdraw consent previously given.

A request may be submitted via info@instantprocess.nl. Instant Process may request additional information where necessary to verify the identity of the applicant and will, in principle, respond within one month of receiving the request. In cases where the GDPR permits, this period may be extended by up to two months, in which case the data subject will be notified of this within one month of receipt of the request.

Where a request relates to personal data that Instant Process processes solely as a data processor on behalf of a business customer, that customer is, in principle, responsible for dealing with the substance of the request.

11. Cookies

The Instant Process website and platform may use cookies and similar technologies that are necessary for the functioning, security and management of the online environment. Where non-essential cookies or similar technologies are used that require consent, consent will be sought in advance.

The Instant Process cookie notice explains which cookies are set, what they are used for, how long they are stored, and how a visitor can change their preferences.

12. Complaints and changes

Any data subject who believes that Instant Process is not processing personal data in accordance with the GDPR may contact us at info@instantprocess.nl. In addition, the data subject has the right to lodge a complaint with the Dutch Data Protection Authority.

Instant Process may amend this privacy policy should there be changes to its business operations, the platform, the suppliers it uses, AI functionalities, data processing or applicable laws and regulations. The most up-to-date version will be made available via the website or the platform.