Trust Center

Security, privacy and documentation – in one place

AIMZ handles the finances of your projects. Here's how we process your data, who gets access to it, where it's stored, and the documents your procurement and legal teams need for their assessment.

Data stored in the EU/EEA

The solution runs on Microsoft Azure within the EU/EEA. Customer data doesn't leave the region unless agreed.

No AI training on your data

AI features use your data to produce suggestions, not to train models.

GDPR compliant

A data processing agreement under GDPR Article 28 is entered into as part of the license agreement.

Open sub-processor list

Everyone who processes data on our behalf is published, with location and transfer basis.

Security

How we protect your data

Encryption

Data is encrypted in transit and at rest. Access to the production environment requires authentication and is limited to those who need it.

Roles and access

Users are assigned a role in the solution – owner, administrator or standard user. The customer controls who has access to which projects.

Hosted on Azure

The solution runs on Microsoft Azure in the EU/EEA, with backup and monitoring as part of operations.

Logs

Operations, event and access logs are retained for as long as necessary, normally a 90-day retention period.

Breach notification

In the event of a personal data breach, we notify the customer without undue delay, so the customer can report to the data protection authority within the deadline.

Planned maintenance

Notice of planned maintenance is given no later than three working days before it takes place.

AI in AIMZ

The models learn from the industry – not from your projects

AIMZ uses AI to read and classify invoices, suggest matches against cost items and change orders, and calculate indicators and insights. The suggestions are exactly that – suggestions that a person approves.

The models get better over time, and that's the whole point: when many contractors use AIMZ, the system learns the patterns that repeat across construction – how an invoice line relates to a cost item, how a change order feeds into the forecast. That insight comes back to everyone who uses the solution.

This happens in anonymised and aggregated form. Your projects, figures and customer relationships aren't recognisable, aren't made available to the public, and can't be traced back to your business by a third party. Personal data isn't used to train models.

Suggestions, not automated decisions

AI suggests matches and indicators. Approval is done by a user.

Never personal data in training

The models aren't trained on identifiable personal data. This is set out in the data processing agreement.

Anonymised and aggregated learning

Usage data in anonymised or aggregated form makes the models more accurate – for the whole customer base, not just for whoever generated it.

Not recognisable, not public

The learning shouldn't make customer data available to the public or let third parties identify the customer or business.

Region governed by agreement

AI providers must process data in accordance with the agreement, within the agreed region where relevant.

The provider is listed

The AI provider is included in the sub-processor list, with its transfer basis.

Sub-processors

Who processes data on our behalf

The full, up-to-date list of approved sub-processors is published and maintained on its own page. Changes are notified there, with a thirty-day window to raise objectively justified objections.

SupplierServiceLocation
MicrosoftHosting (Azure) and administrationEEA
FrontedIT consultancy, software developmentEEA
HubSpotCRMEEA
PostHogProduct analyticsEEA
IntercomCustomer support and chatUSA
OpenAIProduct enrichment, analysis and suggestionsUSA
See the full list with transfer basis and change log

Have a procurement or IT question we haven't answered?

Send us your security questionnaire, or ask for a meeting with our technical lead. We normally reply within one working day.

contact@aimz.no