DEEPXL AS
PRIVACY POLICY
Version 1.0 | Effective from 14 September 2026
Published in the legal section of our website at deepxl.ai — prior versions archived in the same place
WHAT THIS POLICY COVERS. This policy explains how DeepXL AS handles personal data for which DeepXL itself decides the purpose: your account, the people we give access to it, your use of our website and API, our correspondence with you, our invoicing, and the fraud-prevention layer described in section 3. We are a Norwegian company; the General Data Protection Regulation (GDPR) applies to us as Norwegian law through the Personal Data Act of 2018 (personopplysningsloven), wherever you are and wherever our servers are.
WHAT IT DOES NOT COVER. It does not cover the documents, images and files our customers submit to the API for analysis. For that content the customer is the data controller and DeepXL acts only as a processor on the customer’s instructions, under the Data Processing Addendum in Schedule 2 to our API Terms. If your document was checked using DeepXL, the business that asked you for the document is responsible for that processing and is the party you should contact. Section 3 is the one exception: the fraud-prevention layer is our own processing, and you can come to us directly about it.
1. Who we are
DeepXL AS, org. no. 932 269 570, Bjørnveien 87B, 0773 Oslo, Norway, is the data controller for the processing described in this policy. You can reach us at privacy@deepxl.ai, which is our contact point for all data protection matters. We have assessed whether Article 37 of the GDPR requires us to designate a data protection officer and have not designated one at this time; we review that assessment at least annually and when the scale or nature of our processing changes, and we will name a data protection officer here if we designate one.
2. What we collect about you, why, and on what legal basis
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data: registered legal name, registered or principal business address, business e-mail address for notices, and the name, job title and business e-mail address of the person who registered and of each person given access to the account, password hash | Creating and operating your account; authentication; providing the Services | Performance of a contract (GDPR art. 6(1)(b)); legitimate interests (art. 6(1)(f)) as regards a person given access who is not the contracting party | Account lifetime, then 12 months |
| Invitation data: e-mail address of a person invited to the account, the name of the person who invited them, and the status of the invitation | Administering multi-user access to the account | Legitimate interests in operating an account securely and in knowing who has access (art. 6(1) (f)) | Account lifetime, then 12 months |
| Acceptance record: e-mail address, UTC timestamp, IP address, user agent, the version number of the API Terms displayed, the exact wording and links displayed immediately above the registration button, the label of that button, and the registration information submitted | Evidence that the API Terms, the Acceptable Use Policy and the Data Processing Addendum were accepted, and of which version | Legitimate interests in being able to establish and defend the contract (art. 6(1)(f)) | Until the limitation period for claims under the API Terms has expired: normally 3 years after the account closes under the Norwegian Limitation Act (foreldelsesloven), longer while a claim is pending or where that Act provides a longer |
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| period | |||
| Billing data: invoices, prepayment and top-up records, amounts, currency, company registration number, VAT or tax identification number, and the bank details appearing on a payment we receive | Invoicing; accounting and tax compliance | Contract (art. 6(1)(b)) and legal obligation (art. 6(1)(c), Norwegian Bookkeeping Act (bokføringsloven)) | 5 years after the end of the financial year, as the Bookkeeping Act requires |
| Usage data: Call volume and timing, endpoint, document or object type, issuing-country distribution, result category, pass and fail rates, repeated or near-identical submission patterns, error and latency data, IP address of API requests | Billing; capacity planning; security monitoring; detecting breach of our API Terms, in particular attempts to establish what our models detect | Contract (art. 6(1)(b)) for billing; legitimate interests in the security and integrity of the service and in enforcing our Terms (art. 6(1)(f)) | 12 months |
| Support and correspondence: e-mails, support tickets and their content | Answering questions; handling complaints and incidents | Contract (art. 6(1)(b)) and legitimate interests (art. 6(1)(f)) | 24 months from closure |
| Data subject requests: your identity, your request and our correspondence about it | Handling and documenting requests under section 8 and objections under section 3 | Legal obligation (art. 6(1)(c), GDPR arts. 12–22) and legitimate interests in documenting compliance (art. 6(1)(f)) | 3 years after the request is closed |
| Website data: server access logs — IP address, timestamp, page requested, referrer and user agent, collected automatically by the web server | Operating and securing the website, including detecting and responding to misuse | Legitimate interests (art. 6(1)(f)) — no consent is required because no non-essential cookie or similar technology is used to collect this; see section 4 | Kept only for as long as needed for security and troubleshooting, and in any event no longer than our hosting provider's standard log-retention period |
| Marketing data: business e-mail address, company, role, engagement with our e-mails | Sending information about our products to business contacts | Consent (art. 6(1)(a) and section 15 of the Norwegian Marketing Control Act (markedsføringsloven)); or, for an existing customer, the existing-customer exception in section 15 together with legitimate interests (art. 6(1)(f)), limited to comparable services and with an opt-out in every message | Until you object or unsubscribe; opt-out records for as long as needed to honour them |
| Fraud-prevention layer: technical signals derived from submitted files | Recognising a file, forgery template or tamper pattern seen before | Legitimate interests in preventing and detecting fraud (art. 6(1)(f), recital 47) — see section 3 | 60 months from the analysis that created the entry |
We do not sell personal data and we do not share it for advertising purposes. Where we rely on legitimate interests we have carried out and documented the balancing test, and you may ask us for a summary of it.
3. Our fraud-prevention layer
Document and object fraud is committed against many organisations using the same artefacts and the same forgery templates. So that we can recognise a document or a forgery template we have seen before, we keep a fraud-prevention layer and match new submissions against it across all our customers. For this layer, and only for this layer, DeepXL decides
the purpose and is the data controller. It is described in clause 4.4 of our API Terms and clause 13 of the Data Processing Addendum.
What the layer holds, and what it never holds
For each file submitted to us, the layer holds technical signals derived from it: cryptographic and perceptual fingerprints of the file and of regions within it, template, layout, font, structural and metadata signatures, tamper and manipulation signals, and the risk signals our analysis produces. Four limits apply and we cannot widen them without amending our API Terms:
-
(a) the layer holds only what is necessary to recognise a file, a forgery template or a tamper pattern again, and is not a store of documents or of their content;
-
(b) it does not contain the file, or a copy, reproduction or image of it, and no signal in it is designed or intended to allow the file, or the content of any field in it, to be reconstructed or reproduced;
-
(c) it holds a reference to the Call that produced an entry, and no customer identifier, account identifier or credential identifier; and
-
(d) we do not hold, extract, derive, index or match on special categories of personal data, data relating to criminal convictions and offences, genetic data or biometric data as such, and no biometric template is generated or held.
A fingerprint is not intended to identify anyone, and in most cases is not personal data in our hands. The layer does, however, hold a reference to the Call that produced each entry, and that reference can be matched, through the business’s own records, to the Call and so to you. Because of that, we treat every entry in the layer as personal data, and we do not rely on Article 11 of the GDPR. We hold no other means of identifying you — no name, no document, no contact details — and we use the reference only to investigate a suspected error in the layer, to respond to a request from you or from the business, and to investigate security incidents; we do not use it to tell you, or anyone else, which business a submission came from. Where you exercise your rights we may need information from you — for example a copy of the document concerned — so that we can locate the entries.
Why we are allowed to do this
We rely on our legitimate interests, and those of our customers and of the people harmed by document fraud, in preventing and detecting fraud — a purpose recognised in recital 47 to the General Data Protection Regulation (art. 6(1)(f)). We keep a written assessment of that balance, covering why the processing is necessary, the limits above, and the safeguards we apply, and we have carried out a data protection impact assessment for the layer. You may ask us for a summary of both.
How long we keep it
Entries are kept for 60 months from the analysis that created them and are then deleted by an automatic scheduled process. A deleted entry remains technically restorable through our database provider’s point-in-time restore for up to seven days, after which it is permanently gone. That is longer than we keep the documents themselves, because a forgery template stays in circulation for years.
How you are told about it
We hold no name or contact details for you and cannot identify you ourselves, so we cannot tell you individually that an entry exists. The business that asks you for a document is required by our API Terms to tell you, in its own privacy information, that the document may be checked by a fraud-prevention service that keeps fingerprints and derived signals, and to refer you to this section. This section is the public information that Article 14(5)(b) of the General Data Protection Regulation requires where individual notification is impossible or would involve disproportionate effort.
What we will never tell a customer
When we tell a customer that a file, template or tamper pattern has been seen before, that is all we tell them. We do not disclose the identity of any other customer, when or how often a file was submitted, or anything from which another customer, its business or the people it deals with could be identified or worked out. Our customers are contractually prohibited from trying to find out.
YOUR RIGHT TO OBJECT Because this processing is based on our legitimate interests, you have the right to object to it at any time under Article 21 of the General Data Protection Regulation. Write to privacy@deepxl.ai. You do not need to give a reason, and you do not need to go
through the business that asked you for your document. If we uphold your objection we will delete the entries concerned. You may also ask us for access to what we hold about you in the layer, and for its erasure. The layer holds no name, document or contact detail that would let us identify you directly, and we do not use the reference described above to tell you, or anyone, which business a submission came from. We may need information from you to locate the entries — for example a copy of the document concerned.
The layer is held on infrastructure operated by our providers in the United States. We are the exporter of that data, and section 6 describes the safeguards for that transfer.
4. Cookies and similar technologies
Under section 3-15 of the Norwegian Electronic Communications Act (ekomloven), in force from 1 January 2025, we may store information on your device, or read information already stored there, only with your consent, unless the storage or access is solely for transmitting a communication over a network or is strictly necessary to provide a service you have explicitly requested. We currently set only strictly necessary cookies — to operate the website and to keep you signed in — and nothing else: no analytics, no advertising and no other non-essential technology. Because we set nothing that requires consent, no consent banner is shown. If that changes we will introduce a consent mechanism meeting the standard of the General Data Protection Regulation — a genuine choice, no pre-ticked boxes, and rejecting as easy as accepting — before we set anything beyond what is strictly necessary, and we will update this section first. Nkom and the Norwegian Data Protection Authority supervise this rule.
5. Who we share your data with
We share personal data described in this policy with:
-
(a) our cloud hosting and compute providers, which store and process the data described in this policy and in the Data Processing Addendum on infrastructure in the United States, as processors on our instructions;
-
(b) Google, for our own e-mail, calendar and office tools (Google Workspace, operating on Google’s global infrastructure under Google’s Cloud Data Processing Addendum, which incorporates the Standard Contractual Clauses), and Resend, for sending transactional e-mail to you (United States, under Resend’s Data Processing Addendum, which incorporates the Standard Contractual Clauses);
-
(c) our bank, and the bank of the payer, when we invoice you and receive payment. Each acts as a controller in its own right under its own privacy policy. We do not take card payments and we do not use a payment processor, so we hold no card data;
-
(d) professional advisers, auditors and insurers, where necessary and under a duty of confidence; and
-
(e) public authorities and courts, where we are legally required to disclose, or where disclosure is necessary to establish or defend a legal claim.
A current list of the providers we use as processors, with the processing each carries out, the country in which each processes and, where we rely on it, its certification under the EU–U.S. Data Privacy Framework, is published in the legal section of our website at deepxl.ai.
6. Transfers outside Norway and the EEA
We are established in Norway. The data described in this policy, including the fraud-prevention layer in section 3, is stored and processed by our providers on infrastructure in the United States, and we are the exporter of that data under Chapter V of the General Data Protection Regulation. Microsoft Corporation is certified under the EU–U.S. Data Privacy Framework, and we rely on the European Commission’s adequacy decision for the Framework (Decision (EU) 2023/1795), incorporated into the EEA Agreement by Joint Committee Decision No 169/2024 so that it applies to transfers from Norway. If that decision or the certification ceases to cover the transfer, we will suspend the affected processing or move it to a safeguard that validly covers it within sixty days. Where we use a provider that is not certified under the Framework, the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 apply to that transfer instead. We keep a transfer impact assessment and supplementary technical and organisational measures for
these transfers and review them at least annually. You may request a copy of the relevant safeguards from privacy@deepxl.ai.
7. How we protect your data
We encrypt data in transit and at rest, restrict access to named personnel on a need-to-know basis, require multi-factor authentication for administrative access, log access, and maintain a documented incident response procedure. Our security measures are described in the legal section of our website at deepxl.ai. No system is completely secure. If a personal data breach occurs we will notify the Norwegian Data Protection Authority within 72 hours where Article 33 of the General Data Protection Regulation requires it, and we will notify you without undue delay where Article 34 requires it.
8. Your rights
You may ask us to give you access to your personal data, to correct it, to delete it, to restrict how we use it, to send it to you or another provider in a portable format, and to stop processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting processing that took place before. Write to privacy@deepxl.ai and we will respond within one month; where a request is complex or we receive many, we may extend that by up to two further months and will tell you why. We may ask you to verify your identity before we act on a request.
If you are dissatisfied, you may complain to the Norwegian Data Protection Authority (Datatilsynet, Postboks 458 Sentrum, 0105 Oslo, postkasse@datatilsynet.no) or to the supervisory authority in the country where you live or work.
If your document was analysed by DeepXL for a business, and your request is about that document, we cannot answer it, because we do not decide why it is processed and in most cases cannot identify you from it. Contact the business that asked you for the document. If you write to us, we will tell you that and pass the request on where we can identify the account. This does not apply to the fraud-prevention layer in section 3, which is our own processing and about which you should come to us directly.
9. Automated decisions and children
We do not make automated decisions about you that produce legal effects or otherwise significantly affect you in the processing described in this policy. Our analysis of documents is carried out for our customers, who are required by our API Terms never to use our output as the sole or determinative basis for a decision about a person and to apply human review that is capable of changing the outcome.
Our services are sold to businesses only and are not directed at children. We do not knowingly collect personal data from anyone under 18 in the processing described in this policy.
10. Changes to this policy
We may change this policy. Each version carries a version number and an effective date, and every version, current and superseded, remains available in the legal section of our website, as stated on the first page. Where a change materially affects how we use personal data for which we are the controller, we will tell account holders by e-mail to the notice address on the account before it takes effect, and we will say so at the top of the policy for at least 30 days after it takes effect.