Privacy policy
Last updated: 10 August 2026
Munitor Compliance is a service of Munitor. This policy explains which personal data we process, why, and what rights you have. It is not legal advice and does not replace your own GDPR assessment.
Who is responsible
Munitor is the data controller for the data needed to run your account and workspace (name, email address, password hash, workspace and organisation data). For data you record yourself about your own customers or staff inside the service, you are the controller and Munitor is the processor — see the data processing agreement.
What data we collect
Account data at registration; workspace, organisation and measure data you enter yourself; files and links you upload as evidence; payment data that Stripe processes on our behalf (we never see your full card number); technical logs for security and troubleshooting; and, if you use the AI features, the text you submit to them.
What we use it for
To deliver the service and maintain your evidence file, to invoice you, to secure the service and prevent abuse, and to meet our own legal obligations, such as the tax retention duty for invoices.
Sub-processors
For the AI features (explanation, action plan, baseline assessment), Anthropic, PBC processes the text you submit to them, as a sub-processor and under a data processing agreement with Anthropic. We use Stripe for payments. The production environment — database, files and application servers — runs with a hosting provider inside the European Union. An up-to-date list of sub-processors is available on request via privacy@munitor.nl.
Retention periods
We keep account data for as long as your account exists, and afterwards for as long as a legal retention duty requires (for example the seven-year tax retention duty for invoices). If you ask us to close your account, we delete the remaining data within a reasonable period.
Your rights
You have the right to access, rectify, erase, restrict and object to processing, and to data portability. Email privacy@munitor.nl. If you disagree with how we handle your request, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Security
We encrypt traffic with TLS, hash passwords with a modern hashing function, and limit access to production data to what's needed to run the service. See also our page on responsibly reporting a vulnerability.
Changes
We update this policy when the service or regulation gives cause to. For a material change we inform signed-in users inside the app.