Privacy Policy

Version 1.0

This document is the English-language version of the privacy policy. In the event of any inconsistency between the English-language version and the Dutch-language version, the Dutch-language version shall prevail.

Arkintel B.V. is a company registered in the Netherlands, with the following information:

  • Company name: Arkintel B.V.
  • Address: Molengraaffsingel 12, 2629JD Delft, The Netherlands
  • Kamer van Koophandel (Chamber of Commerce) number: 99939940
  • RSIN: 869196911
  • Privacy contact: contact@arkintel.com

This privacy policy describes how personal data is collected, used, and protected in connection with the DelftGPT AI chat platform (the "Services").

Introduction

Arkintel is committed to protecting the privacy of users of the DelftGPT platform. We process personal data lawfully and carefully.

DelftGPT is an AI chat assistant for employees of Gemeente Delft. It is currently in a field trial and development phase.

Chat storage and AI processing take place on servers in the Gemeente Delft datacenter, on hardware owned by the Municipality. Some supporting services remain external, such as sign-in, secure traffic routing, frontend delivery, and privacy-friendly analytics.

This privacy policy should be read in conjunction with our Terms of Service, which govern your use of the Services.

Data Controller and Processor

For the purposes of the GDPR:

  • Gemeente Delft is the data controller. The Municipality determines the purposes and means of processing personal data in connection with the DelftGPT platform.
  • Arkintel B.V., the developer and operator of the DelftGPT platform, acts as a data processor on behalf of Gemeente Delft. Arkintel processes personal data solely in accordance with the Municipality's documented instructions and under a data processing agreement (verwerkersovereenkomst) that meets the requirements of Article 28 GDPR.

If you have questions about your data or want to exercise your rights, you can contact Arkintel at the privacy contact email address listed at the top of this document, or contact the privacy officer of Gemeente Delft.

Data Protection Officer

Gemeente Delft has a Functionaris Gegevensbescherming (FG) as required under the GDPR. For questions about how the Municipality processes your data through DelftGPT, you may contact the FG of Gemeente Delft.

Arkintel B.V. has not appointed a separate Data Protection Officer.

Data Protection Impact Assessment

DelftGPT does process normal account and usage data needed to run the service, such as your sign-in details, chat history, feedback, and technical logs. However, the platform is not intended for uploading personal case data, sensitive data, or other protected information into chat prompts or uploaded files.

If actual usage patterns show that DelftGPT is being used to process personal or sensitive content in practice, the DPIA determination will be revisited.

What Information Do We Process?

Information from Your Entra ID Account

When you log in to DelftGPT, the following information is received from the Municipality's Microsoft Entra ID system:

Data fieldPurpose
Display namePersonalisation of the interface
Email addressUser identification and account linking
Entra ID user identifierUnique account identification

This information is provided by the Municipality's identity system. Arkintel does not independently collect or verify this data.

Information Generated Through Use

Data fieldPurpose
Chat messages (your input and AI responses)Core chat functionality and chat history
Uploaded files (content processed by the AI)Document analysis and chat context
Chat historyAllowing you to review and continue previous conversations
Feedback (upvotes, downvotes, suggestions)Quality measurement and system improvement
Model selection preferencesUser experience personalisation

Information Collected Automatically

When you access the Services, the following technical information may be collected:

  • Browser type and version
  • Device type and operating system
  • Date and time of access
  • Error logs and technical diagnostic data
  • Request and security metadata needed for secure delivery of the service

This information is collected for the purposes of platform security, error detection, and performance monitoring.

Legal Basis for Processing

Personal data is processed on the following legal bases (Article 6 GDPR):

Processing activityLegal basisGDPR Article
User authentication via Entra IDLegitimate interest6(1)(f)
AI chat functionality and chat historyLegitimate interest6(1)(f)
Feedback and benchmark evaluation during Phase 2Legitimate interest6(1)(f)
Privacy-friendly web analyticsLegitimate interest6(1)(f)
Platform security and error loggingLegitimate interest6(1)(f)

The main legitimate interest is the Municipality's interest in providing employees with a secure AI productivity tool and improving it during the current field trial.

In assessing this interest, the following points are relevant:

  • The professional context of the processing (employer-provided work tool).
  • The strong security measures in place.
  • The fact that the system is not intended for special category data or sensitive case data.
  • The transparency provided through this privacy policy and the platform's FAQ.

How Do We Use Your Information?

We use the information we process for the following purposes:

  • Service delivery: to provide and operate DelftGPT, including chat functionality, file analysis, and chat history.
  • Authentication: to verify your identity through the Municipality's Microsoft Entra ID system.
  • Quality measurement: to measure and improve the quality of the AI output using chats, feedback, and usage metrics during Phase 2.
  • Security and integrity: to detect, prevent, and respond to security incidents and technical issues.
  • Legal compliance: to comply with applicable legal obligations.

We do not use your data for:

  • Marketing or advertising purposes.
  • Selling or sharing with third parties outside the data processing relationship.
  • Training or fine-tuning AI model weights. Your chats and uploaded files are not used to train the AI models behind DelftGPT.
  • Automated decision-making or profiling.

Chat History and Audit

Chat history is stored so you can review and continue earlier conversations.

Each user can only access their own chats in the platform.

In specific audit cases or when the Gemeente is required to do so, the Gemeente may request export of a user's chat data.

How Do We Store Your Data?

Storage Location

Chat content, uploaded files, chat history, and AI processing are handled on servers in the Gemeente Delft datacenter, on hardware owned by the Municipality.

Some supporting services remain external. For example:

  • Microsoft Entra ID handles sign-in and identity tokens.
  • Cloudflare handles secure traffic routing and related request metadata.
  • Vercel delivers the frontend and privacy-friendly web analytics.

Data Protection Strategy

Arkintel and the Municipality apply appropriate technical and organisational measures to protect data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Hardware redundancy: data is stored across 3 servers. Loss of 1 server has zero impact; loss of 2 servers still preserves data integrity.
  • Snapshots: rolling snapshots allow instant rollback from corruption or ransomware.
  • Backups: server exports to the Municipality's Petabyte storage cluster protect against total cluster failure.
  • Offsite replication: backup replication to a secondary location ensures survival even if the primary datacenter is lost.
  • Encryption in transit: all traffic is encrypted using TLS with modern cipher suites.
  • Network isolation: the AI cluster is isolated inside the municipal network.
  • Zero Trust access: access uses secure outbound-only tunnels.
  • Access control: user access is controlled through the Municipality's Microsoft Entra ID, restricted to authorized employees only.

While we take strong measures to protect your data, no system can promise zero risk.

Backup Storage

Backups are stored on the Municipality's Petabyte storage cluster and replicated to a secondary location managed by the Municipality.

Sub-processors

The following sub-processors are involved in the delivery of the Services:

Sub-processorPurposeData processedLocation
Cloudflare Inc.Secure traffic routing and securityUser IP address and request metadata needed to deliver traffic securelyGlobal edge network
Vercel Inc.Frontend delivery and privacy-friendly web analyticsStatic frontend assets, request metadata in transit, and anonymous aggregated page view dataGlobal edge network
Microsoft (Entra ID)Authentication and access control (SSO)User identity tokensMicrosoft cloud (configured by the Municipality)

No AI processing is performed by external sub-processors. All AI models run on-premises on the Municipality's servers. No chat content, uploaded files, or user data is sent to external AI providers.

Arkintel reserves the right to engage additional sub-processors in the future. Where a new sub-processor is engaged that materially affects the processing of personal data, this privacy policy will be updated accordingly.

Data Sharing

The platform uses third parties only where needed to deliver sign-in, secure traffic routing, frontend delivery, and analytics as described in this policy.

Gemeente Delft, as data controller, may have access through authorized administrators for compliance, audit, or operational reasons.

Aggregated or sufficiently anonymised usage information may be used for quality measurement and reporting.

Cookies and Tracking Technologies

The DelftGPT platform uses strictly necessary cookies required for the technical operation of the service:

  • Session cookies: to keep you signed in while using the platform.
  • Security cookies: to support the sign-in flow and platform security.

We do not use:

  • Advertising cookies
  • Profiling cookies
  • Behavioural tracking cookies

Because the platform uses only strictly necessary cookies, no cookie consent banner is required for those cookies.

Web Analytics

DelftGPT uses Vercel Web Analytics, a privacy-friendly, cookieless analytics service. It provides aggregated usage information, such as page views and visitor counts, to help improve the service.

Vercel Web Analytics does not place cookies on your device.

Data Retention

Data categoryRetention period
Chat history and user dataRetained according to the retention rules agreed between Arkintel and Gemeente Delft.
Uploaded filesProcessed as part of the chat session and chat context.
Technical and security logsRecorded in anonymised form
Feedback dataRetained according to the retention rules agreed for quality measurement and service evaluation

When a user's access is revoked by the Municipality, the user can no longer access the platform. Retention and deletion after that point follow the agreed municipal retention setup.

International Data Transfers

Primary chat storage and AI processing take place on-premises in the Gemeente Delft datacenter in the Netherlands.

Some supporting services may involve international processing of limited technical or authentication data, depending on how those services deliver their network and cloud infrastructure.

  • Cloudflare may process request metadata through its global edge network.
  • Vercel may process frontend delivery and analytics data through its global edge network.
  • Microsoft Entra ID may process authentication data through Microsoft's cloud services as configured by the Municipality.

No chat content, uploaded files, or AI processing data is sent to external AI providers.

Your Rights Under the GDPR

Under the GDPR, you have the following rights:

  • Right of access (Article 15): the right to request confirmation of whether personal data concerning you is being processed, and if so, to request a copy of that data.
  • Right to rectification (Article 16): the right to request correction of inaccurate personal data or completion of incomplete personal data.
  • Right to erasure (Article 17): the right to request deletion of your personal data where certain conditions apply.
  • Right to restriction of processing (Article 18): the right to request that processing be restricted in certain circumstances.
  • Right to data portability (Article 20): the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON).
  • Right to object (Article 21): the right to object to processing based on legitimate interest.
  • Right related to automated decision-making (Article 22): the right not to be subject to a decision based solely on automated processing. DelftGPT does not make automated decisions about you.

How to Exercise Your Rights

To exercise any of these rights, please contact Arkintel at the privacy contact email address listed at the top of this document, or contact the privacy officer of Gemeente Delft.

We will respond to your request within one (1) month of receipt. This period may be extended by a further two (2) months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month, together with the reasons for the delay.

Verification of your identity may be required before a request is processed.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR. The competent supervisory authority in the Netherlands is:

Autoriteit Persoonsgegevens Postbus 93374, 2509 AJ Den Haag Website: https://autoriteitpersoonsgegevens.nl

We encourage you to contact us first so that we can try to resolve your concern directly.

Data Breach Notification

In the event of a personal data breach, Arkintel will notify Gemeente Delft without undue delay. Gemeente Delft, as data controller, will handle any required notifications to the Autoriteit Persoonsgegevens and to affected users.

Changes to This Privacy Policy

Arkintel keeps this privacy policy under review and will place updates on this page. The "Version" and "date" fields at the top of this document show the current version and effective date.

Material changes will be communicated through the platform or through the Municipality's internal channels.

Third-Party Links

The Services may contain links to other websites or services. Arkintel is not responsible for the privacy practices or content of those external services.

Applicable Law

This privacy policy is governed by the laws of the Netherlands and the GDPR.