Je data blijft aantoonbaar veilig. Your data stays demonstrably safe.
Alles wat je uploadt staat voor 100% in Nederland, op onze eigen servers in Arnhem. Elke schakel is beveiligd, gelogd en toetsbaar: van datacenter en toegangsbeheer tot de AI-aanroep binnen de EER.Everything you upload is stored 100% in the Netherlands, on our own servers in Arnhem. Every link in the chain is secured, logged and verifiable: from data centre and access control to the AI call within the EEA.
Vijf oplossingen, één fundamentFive solutions, one foundation
Dit document geldt voor alle software-oplossingen van WIDE Solutions. Ze draaien op dezelfde infrastructuur, met dezelfde beveiliging en dezelfde afspraken over data en AI.This document applies to all WIDE Solutions software. It runs on the same infrastructure, with the same security and the same agreements on data and AI.
Data-analyse voor audit en (interne) controle. Leest de administratie door en toetst die op rechtmatigheid, WKR, factuurvereisten, dubbele betalingen en meer. Het platform waar 25+ gemeenten dagelijks mee werken. Meer over ROIBOT →Data analysis for audit and (internal) control. Reads through the accounting records and tests them for lawfulness, work-related expense rules, invoice requirements, duplicate payments and more. The platform 25+ municipalities work with every day. More about ROIBOT →
Analyse ondersteund door AI. Meer over Aviseo →Analysis supported by AI. More about Aviseo →
Teamcommunicatie in eigen huis. Meer over SleQ →Team communication in-house. More about SleQ →
Van lead tot verlenging. Meer over ContraQ →From lead to renewal. More about ContraQ →
Gebruikelijk loon, controleerbaar onderbouwd. Meer over dgaproof.nl →Customary salary, verifiably substantiated. More about dgaproof.nl →
Wie is WIDE Solutions?Who is WIDE Solutions?
Een kernteam van vier. Per 1 augustus 2026 zet WIDE Solutions de software voort die eerder binnen de Juyst Groep werd ontwikkeld. Team, servers en werkwijze blijven dezelfde.A core team of four. As of 1 August 2026, WIDE Solutions continues the software previously developed within the Juyst Group. Team, servers and way of working remain the same.
- Wil Peters RA RE, medeoprichter, vakkennis en engineering. Registeraccountant én register-IT-auditor, softwareontwikkelaar en AI-engineer. Bijna veertig jaar audit en fiscaliteit, zestien eigen oplossingen sinds 2000., co-founder, professional expertise and engineering. Chartered accountant and registered IT auditor, software developer and AI engineer. Nearly forty years in audit and tax, sixteen solutions of his own since 2000.
- Dennis Verhaert, medeoprichter, product en commercie. Product owner van ROIBOT en eerste aanspreekpunt voor nieuwe opdrachten., co-founder, product and commerce. Product owner of ROIBOT and first point of contact for new engagements.
- Vais Logovinsky, infrastructuur en security. Verantwoordelijk voor de multi-tenant platforms met strikte scheiding en beveiliging., infrastructure and security. Responsible for the multi-tenant platforms with strict separation and security.
- Gus Dassen, junior, analyse en applicatie-inrichting. Student Economie aan de Universiteit Maastricht. Richt applicaties in en ondersteunt audits en klantadministratie., junior, analysis and application setup. Economics student at Maastricht University. Sets up applications and supports audits and client administration.
Het digitale teamThe digital team
Vier AI-collega's werken mee aan de software zelf. De eindverantwoordelijkheid ligt altijd bij een mens.Four AI colleagues contribute to the software itself. Final responsibility always rests with a human.
- Cas, orchestrator. Coördineert het werk en bewaakt de kwaliteit, schrijft zelf geen code., orchestrator. Coordinates the work and guards quality, writes no code himself.
- Paul, developer. Schrijft code, draait tests en levert werkende oplossingen op., developer. Writes code, runs tests and delivers working solutions.
- Anton, reviewer. Spoort zwakke plekken op en handhaaft de normen., reviewer. Tracks down weak spots and upholds the standards.
- Cody, externe reviewer. Geeft een onafhankelijke second opinion vanaf een ander AI-model., external reviewer. Provides an independent second opinion from a different AI model.
Ons advies: ruim data op na afrondingOur advice: clean up data once you finish
We bewaren geüploade gegevens en resultaten, maar adviseren je data te verwijderen zodra een analyse of dossier is afgerond. In de analyse-oplossingen is elke analyse te herhalen: upload dezelfde data opnieuw en speel de stappen af via de geschiedenisfunctie. We verwijderen nooit data zonder overleg vooraf.We retain uploaded data and results, but advise deleting your data as soon as an analysis or file is completed. In the analysis solutions every analysis can be repeated: upload the same data again and replay the steps through the history function. We never delete data without consulting you first.
AI: minimaal, optioneel en zonder contextAI: minimal, optional and without context
Bij elke uitvraag aan een AI sturen we alleen mee wat strikt nodig is om die ene vraag te beantwoorden. Niets meer. Het model weet nooit voor welke organisatie het werkt en alle AI-functies zijn optioneel.With every request to an AI we send along only what is strictly needed to answer that one question. Nothing more. The model never knows which organisation it is working for and all AI features are optional.
1 · Data blijft in Nederland1 · Data stays in the Netherlands
Data in ruste staat voor 100% op onze eigen servers in Arnhem en verlaat die servers niet. De verwerking gebeurt daar lokaal.Data at rest is stored 100% on our own servers in Arnhem and never leaves those servers. Processing happens there, locally.
2 · De conversatie blijft in de EER2 · The conversation stays in the EEA
Roep je een AI-functie aan, dan is die aanroep region-locked op AWS Bedrock: uitsluitend EU-regio's toegestaan, operationeel Ierland (eu-west-1).When you invoke an AI feature, the call is region-locked on AWS Bedrock: only EU regions allowed, operationally Ireland (eu-west-1).
3 · Minimale data, geen context3 · Minimal data, no context
Nooit meegestuurd: organisatienaam, datums, locaties, financiële totalen, leveranciers-, gebruikers- of werknemersgegevens.Never sent along: organisation name, dates, locations, financial totals, supplier, user or employee data.
Een paar voorbeeldenA few examples
De AI-inzet is het intensiefst in onze analyse-oplossingen ROIBOT en Aviseo. Vier toepassingen daaruit en precies wat er per stuk wordt gedeeld; voor elke andere oplossing geldt dezelfde systematiek.AI use is most intensive in our analysis solutions ROIBOT and Aviseo. Four applications from those, with exactly what is shared for each; the same approach applies to every other solution.
01Een vraag stellen in gewone taalAsking a question in plain language
Je stelt je vraag in het Nederlands. Het model vertaalt die naar een statement dat je zelf bekijkt, aanpast en uitvoert.You ask your question in plain language. The model translates it into a statement that you review, adjust and run yourself.
Meegestuurd: alleen je vraag en de kolomnamen van de tabel. Nooit de inhoud van de tabel.Sent along: only your question and the column names of the table. Never the contents of the table.
02Boekingen classificeren voor de WKRClassifying entries for expense rules
De assistent bepaalt of een boeking WKR-gerelateerd is en doet een voorstel dat je accordeert of verwerpt.The assistant determines whether an entry falls under the Dutch work-related expense scheme (WKR) and makes a suggestion that you approve or reject.
Meegestuurd: alleen de tekst van de boekingsomschrijving. Geen bedragen, leveranciers of datums.Sent along: only the text of the entry description. No amounts, suppliers or dates.
03Dezelfde classificatie, volledig lokaalThe same classification, fully local
Naast de assistent draait een door WIDE Solutions zelf getraind machine learning-model in Arnhem, met een accuraatheid van ongeveer 95%. Beide technieken vullen elkaar aan.Alongside the assistant runs a machine learning model trained by WIDE Solutions itself in Arnhem, with an accuracy of around 95%. The two techniques complement each other.
Meegestuurd: niets. Er verlaat geen enkele data het datacenter.Sent along: nothing. No data whatsoever leaves the data centre.
04Een controle laten afwerkenHaving a test carried out
Je laat een controle, bijvoorbeeld op factuurvereisten, door het model uitvoeren in plaats van volledig handmatig. Je valideert de uitkomst zelf.You have a test, for instance on invoice requirements, carried out by the model instead of entirely by hand. You validate the outcome yourself.
Meegestuurd: alleen de gegevens van die ene factuur die nodig zijn om de toets uit te voeren, plus de instructie van het werkprogramma.Sent along: only the data of that single invoice needed to perform the test, plus the instruction from the work programme.
Human-in-the-loop, altijdHuman-in-the-loop, always
- Geen enkel statement wordt automatisch uitgevoerd. Jij beoordeelt het eerst.No statement is ever executed automatically. You review it first.
- Classificaties zijn suggesties die je accordeert, wijzigt of verwerpt.Classifications are suggestions that you approve, change or reject.
- AI-bevindingen in werkprogramma's valideer je altijd zelf.AI findings in work programmes are always validated by you.
- Elke AI-aanroep wordt gelogd met tijdstempel, gebruiker en model.Every AI call is logged with timestamp, user and model.
Welk model en geen trainingWhich model, and no training
We gebruiken Claude van Anthropic, via AWS Bedrock binnen de EER. De prompts stelt de applicatie zelf samen, niet de gebruiker, zodat vertrouwelijkheid bewaakt blijft.We use Claude by Anthropic, through AWS Bedrock within the EEA. The prompts are composed by the application itself, not by the user, so confidentiality remains guarded.
Noch Anthropic, noch AWS gebruikt de uitgewisselde gegevens om modellen te trainen of te verbeteren. Dat is contractueel vastgelegd. Ook ons eigen model wordt niet getraind op data van individuele klanten.Neither Anthropic nor AWS uses the exchanged data to train or improve models. That is contractually guaranteed. Our own model is not trained on data from individual clients either.
Opslag in Arnhem, AI binnen de EERStorage in Arnhem, AI within the EEA
De vraag wáár verwerking plaatsvindt is net zo belangrijk als wat zij oplevert. Bij ons is dat een architectuurkeuze, geen instelling.The question of where processing takes place matters as much as what it delivers. With us that is an architectural choice, not a setting.
Rust. Alle gegevens staan in Arnhem.At rest. All data is in Arnhem.
Al je gegevens blijven in Nederland. De primaire opslag staat op onze eigen servers in Arnhem. Wordt er AI aangeroepen, dan gebeurt dat uitsluitend binnen de Europese Economische Ruimte, in de praktijk Ierland. Nooit in de Verenigde Staten.All your data stays in the Netherlands. Primary storage sits on our own servers in Arnhem. When AI is invoked, that happens exclusively within the European Economic Area, in practice Ireland. Never in the United States.
Op dit moment zetten we AI op een aantal onderdelen in, het meest in de analyse-oplossingen. Dat worden er waarschijnlijk meer. De systematiek blijft dezelfde: per onderdeel gaat alleen mee wat strikt nodig is om die ene vraag te beantwoorden.At the moment we use AI in a number of features, most of all in the analysis solutions. That number will probably grow. The approach stays the same: per feature, only what is strictly needed to answer that one question is sent along.
- Vraag in gewone taal: alleen de vraag en de kolomnamen, geen inhoud uit de administratie.Question in plain language: only the question and the column names, no content from the records.
- WKR-assistent: alleen de boekingsomschrijvingen.Expense-scheme assistant: only the entry descriptions.
- Factuurcontrole: alleen de gegevens van één factuur per controle.Invoice check: only the data of one invoice per check.
Komt er een onderdeel bij, dan geldt dezelfde regel: de verwerking blijft binnen de EER en er gaat niet meer mee dan de vraag zelf.Whenever a feature is added, the same rule applies: processing stays within the EEA and nothing more than the question itself is sent along.
Er gaan geen organisatienamen, leveranciersnamen of financiële totalen mee en geen persoonsgegevens, met één eerlijke kanttekening: in de analyse-oplossingen kan een boekingsomschrijving er incidenteel een bevatten. We werken aan een aanvullende anonimiseringslaag vóór verzending.No organisation names, supplier names or financial totals are sent along, and no personal data, with one honest caveat: in the analysis solutions an entry description may occasionally contain some. We are working on an additional anonymisation layer before transmission.
Het juridisch kaderThe legal framework
AVG, EU AI Act, BIO en de CLOUD Act: wat geldt er, wat is geborgd en waar zit het rest-risico.GDPR, EU AI Act, the Dutch government security baseline (BIO) and the CLOUD Act: what applies, what is guaranteed and where the residual risk sits.
De rolverdeling in één beeldThe division of roles at a glance
Jij bent verwerkingsverantwoordelijke, wij zijn verwerker, AWS is sub-verwerker. Alle drie de partijen zitten binnen de EER, dus er is geen doorgifte naar een derde land.You are the controller, we are the processor, AWS is the sub-processor. All three parties sit within the EEA, so there is no transfer to a third country.
01AVG: rolverdeling en doorgifteGDPR: roles and transfers
Jij bent verwerkingsverantwoordelijke (art. 4 lid 7 AVG), WIDE Solutions is verwerker (art. 4 lid 8 AVG). Met elke klant sluiten we een verwerkersovereenkomst conform artikel 28 AVG; voor gemeentelijke klanten op basis van de GIBIT 2023-voorwaarden. Per 1 augustus 2026 is WIDE Solutions de contractpartij; bestaande overeenkomsten zetten we in overleg over.You are the controller (art. 4(7) GDPR), WIDE Solutions is the processor (art. 4(8) GDPR). With every client we conclude a data processing agreement in accordance with article 28 GDPR; for municipal clients based on the Dutch GIBIT 2023 terms. As of 1 August 2026 WIDE Solutions is the contracting party; existing agreements are transferred in consultation.
Omdat alle verwerking binnen de EER plaatsvindt, inclusief de aanroepen naar het taalmodel, is er geen doorgifte naar een derde land. De artikelen 44 tot en met 46 AVG zijn niet activerend en een Transfer Impact Assessment is niet nodig. Het AWS Data Processing Addendum met standaard contractuele clausules borgt de keten aanvullend.Because all processing takes place within the EEA, including the calls to the language model, there is no transfer to a third country. Articles 44 to 46 GDPR are not triggered and a Transfer Impact Assessment is not needed. The AWS Data Processing Addendum with standard contractual clauses provides additional assurance along the chain.
Daarmee zijn we ook niet afhankelijk van het EU-VS Data Privacy Framework, het adequaatheidsbesluit dat juridisch onder druk staat. Zou dat sneuvelen, dan heeft dat geen gevolgen voor onze software.That also means we do not depend on the EU-US Data Privacy Framework, the adequacy decision that is under legal pressure. Should it fall, that has no consequences for our software.
02EU AI Act: laag-risico, rollen helderEU AI Act: low-risk, clear roles
De EU AI Act treedt voor het grootste deel in werking op 2 augustus 2026. Onze AI-toepassingen zijn laag-risico: geen geautomatiseerde besluitvorming met rechtsgevolgen, geen biometrie, geen hoogrisico-toepassing uit Annex III.The EU AI Act largely enters into force on 2 August 2026. Our AI applications are low-risk: no automated decision-making with legal effect, no biometrics, no high-risk application from Annex III.
WIDE Solutions is provider: transparantie, technische documentatie conform art. 11, prestatiemonitoring, incidentmelding en EER-borging. Jij bent deployer: correct gebruik, human-in-the-loop-toezicht, registratie en transparantie. Dit document ondersteunt je rechtstreeks bij die verplichtingen.WIDE Solutions is the provider: transparency, technical documentation in accordance with art. 11, performance monitoring, incident reporting and EEA assurance. You are the deployer: correct use, human-in-the-loop oversight, registration and transparency. This document supports you directly in those obligations.
03De Amerikaanse CLOUD ActThe American CLOUD Act
AWS is van Amerikaanse oorsprong en valt formeel onder de CLOUD Act (2018), ook bij verwerking in Ierland. VNG, de IBD en de Autoriteit Persoonsgegevens wijzen daar terecht op. We beweren dus niet dat er nul Amerikaanse betrokkenheid is. Wat we wél kunnen aantonen:AWS is of American origin and formally falls under the CLOUD Act (2018), even when processing in Ireland. The Dutch association of municipalities (VNG), the IBD and the Dutch Data Protection Authority rightly point this out. So we do not claim there is zero American involvement. What we can demonstrate:
- Data wordt fysiek in de EU verwerkt en opgeslagen, region-locked.Data is physically processed and stored in the EU, region-locked.
- Het contract loopt via een EU-entiteit: AWS EMEA SARL in Luxemburg.The contract runs through an EU entity: AWS EMEA SARL in Luxembourg.
- Er is geen operationele dataflow naar de Verenigde Staten.There is no operational data flow to the United States.
- AWS heeft publiek toegezegd elk overheidsverzoek juridisch te toetsen en te bestrijden als het in strijd is met EU-recht.AWS has publicly committed to legally reviewing every government request and challenging it if it conflicts with EU law.
Het rest-risico is materieel beperkt en vergelijkbaar met Microsoft 365, Google Workspace en Azure, diensten die vrijwel elke organisatie al breed inzet. Volledige uitsluiting vereist Europese modellen zoals Mistral, die voor financiële analyses nog onvoldoende kwaliteit leveren. We volgen die ontwikkeling actief.The residual risk is materially limited and comparable to Microsoft 365, Google Workspace and Azure, services nearly every organisation already uses widely. Full exclusion would require European models such as Mistral, which do not yet deliver sufficient quality for financial analysis. We follow that development actively.
04BIO en BIO2BIO and BIO2
Voor gemeenten en andere overheidsorganisaties geldt de Baseline Informatiebeveiliging Overheid. Die schrijft geen geografische verwerkingseis voor, maar verplicht wel tot een risicogebaseerde leveranciersselectie. EER-verwerking wordt in gemeentelijk cloudbeleid en in de implementatierichtlijn van het GGI-Cloud Expertisecentrum (VNG) positief gewaardeerd.Municipalities and other government organisations are bound by the Baseline Informatiebeveiliging Overheid, the Dutch government information security baseline. It prescribes no geographical processing requirement, but does require risk-based supplier selection. EEA processing is valued positively in municipal cloud policy and in the implementation guideline of the GGI-Cloud Expertise Centre (VNG).
Standaard vindt alle verwerking plaats op onze eigen, ISO 27001-gecertificeerde servers in Arnhem, met AI-aanroepen uitsluitend binnen de EER.By default all processing takes place on our own ISO 27001-certified servers in Arnhem, with AI calls exclusively within the EEA.
Beveiliging: toetsbaar in de hele ketenSecurity: verifiable along the entire chain
Van datacenter tot de laptop van de ontwikkelaar. Elke schakel is ingericht conform ISO 27001 en aantoonbaar voor je leveranciersbeoordeling.From data centre to the developer's laptop. Every link is set up in accordance with ISO 27001 and demonstrable for your supplier assessment.
Hosting en infrastructuurHosting and infrastructure
- Eigen fysieke servers van WIDE Solutions in het Tier III-datacenter Eurofiber Arnhem (Dataplace).WIDE Solutions' own physical servers in the Tier III data centre Eurofiber Arnhem (Dataplace).
- Strikte scheiding tussen ontwikkel- en productieomgeving.Strict separation between development and production environments.
- HTTPS/TLS voor alle dataoverdracht, versleuteling van data in rust.HTTPS/TLS for all data transfer, encryption of data at rest.
- 24/7 beschikbaarheidsmonitoring, per SLA minimaal 99,5% beschikbaarheid per maand.24/7 availability monitoring, at least 99.5% availability per month under the SLA.
ToegangsbeheerAccess control
- 2-factor authenticatie verplicht voor álle gebruikers, niet optioneel.Two-factor authentication mandatory for all users, not optional.
- Rolgebaseerd toegangsbeheer, van alleen-lezen tot beheer; de rolnamen verschillen per oplossing (in de analyse-oplossingen bijvoorbeeld Uitvoerder, Manager en Reviewer).Role-based access control, from read-only to administration; role names differ per solution (in the analysis solutions for instance Executor, Manager and Reviewer).
- Toegang tot een project of werkruimte vereist de juiste rol én expliciete toevoeging.Access to a project or workspace requires the right role and explicit addition.
- Je richt rechten per omgeving en per gebruiker zelf in.You configure permissions per environment and per user yourself.
- Wachtwoorden met veilige hashfunctie en salt.Passwords with a secure hash function and salt.
Interne maatregelenInternal measures
- Toegang tot de ontwikkel- en productieservers is beperkt.Access to the development and production servers is restricted.
- Verbinding loopt via een beveiligd, afgesloten netwerk met verplichte 2FA, off-site uitsluitend via VPN.Connections run through a secured, closed network with mandatory 2FA, off-site exclusively via VPN.
- Beveiligde laptops beheerd via Intune: BitLocker, afgeschermde USB-poorten, actuele antivirussoftware.Secured laptops managed through Intune: BitLocker, shielded USB ports, up-to-date antivirus software.
Back-ups en continuïteitBackups and continuity
- Frequente off-site back-ups, zodat een storing op één locatie nooit het einde van je gegevens betekent.Frequent off-site backups, so an outage at one location never means the end of your data.
- Een vastgelegde restoreprocedure: we weten niet alleen dát er een back-up is, maar ook hoe die terugkomt.A documented restore procedure: we not only know a backup exists, we know how it comes back.
- Periodieke monitoring van de off-site opslag, zodat een stille fout niet pas bij een herstelpoging opvalt.Periodic monitoring of the off-site storage, so a silent fault does not surface only during a restore attempt.
Logging en herleidbaarheidLogging and traceability
- Registratie van gebruikershandelingen, beheeractiviteiten, AI-aanroepen en beveiligingsgebeurtenissen.Recording of user actions, administrative activities, AI calls and security events.
- Per logregel: gebeurtenis, data-object, gebruiker, resultaat en tijdstempel.Per log entry: event, data object, user, result and timestamp.
- Per analyse of dossier aantoonbaar wat er is gedaan, door wie en wanneer.Per analysis or file it is demonstrable what was done, by whom and when.
Incidenten en bewaartermijnenIncidents and retention periods
- Datalekken handelen we af conform ISO 27001 en de AVG-meldplicht (art. 33 en 34): melding aan jou binnen 24 uur na ontdekking.Data breaches are handled in accordance with ISO 27001 and the GDPR notification duty (art. 33 and 34): notification to you within 24 hours of discovery.
- Ondersteuning bij je melding aan de Autoriteit Persoonsgegevens.Support with your notification to the Dutch Data Protection Authority.
- Bewaartermijn maximaal 7 jaar. Bij einde contract eerst export, daarna verwijdering in overleg.Retention period of at most 7 years. At the end of the contract first an export, then deletion in consultation.
DPIA-samenvattingDPIA summary
Deze tabel kun je rechtstreeks gebruiken als input voor je DPIA of leveranciersbeoordeling. Een volledige DPIA is niet per definitie verplicht, maar wel aan te raden vanwege het gebruik van AI. Door de EER-verwerking vervalt de doorgifteparagraaf vrijwel volledig.You can use this table directly as input for your DPIA or supplier assessment. A full DPIA is not mandatory by definition, but advisable given the use of AI. Because of the EEA processing, the transfer section all but disappears.
| VraagQuestion | AntwoordAnswer |
|---|---|
| Waar staat de data in ruste?Where is the data at rest? | Voor 100% op onze eigen servers in Arnhem (Tier III, ISO 27001). Data verlaat deze servers niet.100% on our own servers in Arnhem (Tier III, ISO 27001). Data does not leave these servers. |
| Waar wordt AI verwerkt?Where is AI processed? | AWS Bedrock, region-locked binnen de EU (operationeel eu-west-1, Ierland). Het onderliggende model is Claude van Anthropic. De EU-lock is aantoonbaar via de IAM-permissiepolicy, die uitsluitend eu-regio's toestaat.AWS Bedrock, region-locked within the EU (operationally eu-west-1, Ireland). The underlying model is Claude by Anthropic. The EU lock is demonstrable through the IAM permission policy, which allows eu regions only. |
| Verlaat data de EER?Does data leave the EEA? | Nee. Alle verwerking, inclusief de aanroepen naar het taalmodel, vindt plaats binnen de EER.No. All processing, including the calls to the language model, takes place within the EEA. |
| AVG art. 44 t/m 46 activerend?GDPR art. 44 to 46 triggered? | Nee, geen doorgifte naar een derde land. Een Transfer Impact Assessment is niet nodig.No, no transfer to a third country. A Transfer Impact Assessment is not needed. |
| Welke overeenkomsten gelden?Which agreements apply? | Verwerkersovereenkomst tussen jou en WIDE Solutions (art. 28 AVG; voor gemeenten conform GIBIT 2023). AWS Data Processing Addendum inclusief SCC's tussen WIDE Solutions en AWS EMEA SARL.Data processing agreement between you and WIDE Solutions (art. 28 GDPR; for municipalities in accordance with GIBIT 2023). AWS Data Processing Addendum including SCCs between WIDE Solutions and AWS EMEA SARL. |
| Modeltraining op klantdata?Model training on client data? | Nee. Contractueel geborgd.No. Contractually guaranteed. |
| Geautomatiseerde besluitvorming of profilering?Automated decision-making or profiling? | Nee. Human-in-the-loop bij alle AI-functies, alle suggesties valideer je zelf.No. Human-in-the-loop for all AI features, you validate every suggestion yourself. |
| Audit trail?Audit trail? | Ja. Alle AI-aanroepen worden gelogd met tijdstempel, gebruiker en model.Yes. All AI calls are logged with timestamp, user and model. |
| EU AI Act-classificatie?EU AI Act classification? | Laag-risico AI. WIDE Solutions is provider, jij bent deployer.Low-risk AI. WIDE Solutions is the provider, you are the deployer. |
| Certificeringen?Certifications? | ISO 27001. |
| Bewaartermijn?Retention period? | Maximaal 7 jaar, met het advies data te verwijderen zodra een analyse of dossier is afgerond. Bij einde contract: export, daarna verwijdering in overleg.At most 7 years, with the advice to delete data as soon as an analysis or file is completed. At the end of the contract: export, then deletion in consultation. |
De tien vragen die we het vaakst krijgenThe ten questions we get most often
Van FG's, CISO's en gebruikers. Met het volledige antwoord, zonder kleine lettertjes.From DPOs, CISOs and users. With the full answer, no small print.
01Welke AI gebruiken jullie precies?Which AI do you use, exactly?
We gebruiken Claude, een taalmodel van Anthropic, via AWS Bedrock, region-locked binnen de EU en operationeel in Ierland. Dat gebeurt voor duidelijk begrensde toepassingen: in de analyse-oplossingen bijvoorbeeld een vraag stellen in gewone taal, de WKR-assistent en werkprogramma's bij het afwerken van een controle; in dgaproof.nl alleen de leesbare toelichting bij het conceptrapport.We use Claude, a language model by Anthropic, through AWS Bedrock, region-locked within the EU and operationally in Ireland. That happens for clearly bounded applications: in the analysis solutions for instance asking a question in plain language, the expense-scheme assistant and work programmes when completing a test; in dgaproof.nl only the readable explanation accompanying the draft report.
Daarnaast draait er een eigen, door WIDE Solutions getraind machine learning-model volledig lokaal in Arnhem. Dat wisselt geen data uit met externe partijen.In addition, a machine learning model trained by WIDE Solutions itself runs fully locally in Arnhem. It exchanges no data with external parties.
02Verlaat onze data de Europese Unie?Does our data leave the European Union?
Nee. Alle data in ruste staat voor 100% op onze eigen servers in Arnhem en verlaat die servers niet. Gebruik je een AI-functie, dan gaat er een minimale, contextloze aanroep naar AWS Bedrock, region-locked binnen de EU en operationeel in Ierland. Volledig binnen de EER dus. De IAM-permissiepolicy staat aantoonbaar alleen EU-regio's toe, waardoor de AVG-doorgifteregels (art. 44 t/m 46) niet worden geactiveerd.No. All data at rest is stored 100% on our own servers in Arnhem and never leaves those servers. When you use an AI feature, a minimal, context-free call goes to AWS Bedrock, region-locked within the EU and operationally in Ireland. Entirely within the EEA, that is. The IAM permission policy demonstrably allows EU regions only, so the GDPR transfer rules (art. 44 to 46) are not triggered.
03Wordt onze data gebruikt om AI-modellen te trainen?Is our data used to train AI models?
Nee, nooit. Noch Anthropic, noch AWS gebruikt prompts of output voor het trainen van modellen. Dat is vastgelegd in de geldende Data Processing Agreements. Ook ons eigen model wordt niet getraind op data van individuele klanten.No, never. Neither Anthropic nor AWS uses prompts or output for training models. That is laid down in the applicable Data Processing Agreements. Our own model is not trained on data from individual clients either.
04Neemt de software geautomatiseerde beslissingen?Does the software make automated decisions?
Nee. Human-in-the-loop is leidend bij alle AI-functies: statements worden getoond vóór uitvoering, classificaties krijg je ter beoordeling en AI-bevindingen valideer je altijd zelf. Er worden geen automatische correcties of besluiten doorgevoerd en er vindt geen profilering plaats.No. Human-in-the-loop leads in all AI features: statements are shown before execution, classifications are presented for your review and AI findings are always validated by you. No automatic corrections or decisions are applied and no profiling takes place.
05Welke persoonsgegevens kunnen bij het taalmodel terechtkomen?Which personal data could reach the language model?
Zeer beperkt. Het model ontvangt nooit contextuele informatie: geen organisatienaam, leveranciersnamen, gebruikersnamen, financiële totalen of datums. Het enige rest-risico zit in de analyse-oplossingen, waar een boekingsomschrijving incidenteel een naam kan bevatten, bijvoorbeeld bij onkostendeclaraties. Meer dan de omschrijving wordt in geen geval verstuurd. We werken aan een aanvullende anonimiseringslaag.Very little. The model never receives contextual information: no organisation name, supplier names, user names, financial totals or dates. The only residual risk sits in the analysis solutions, where an entry description may occasionally contain a name, for instance with expense claims. In no case is anything beyond the description sent. We are working on an additional anonymisation layer.
06Is het gebruik van AI verplicht?Is the use of AI mandatory?
Nee. AI-functies zijn optioneel. Wil je in de analyse-oplossingen geen taalmodel inzetten, dan gebruik je de overige modules onverkort: steekproeven, een controle afwerken zonder AI-werkprogramma, queries zonder natuurlijke taal en het lokale ML-model. Dat laatste draait volledig in Arnhem en wisselt geen gegevens uit met externe partijen. En in dgaproof.nl rekent AI nooit: elke euro in het rapport komt uit de deterministische berekeningsengine.No. AI features are optional. If you prefer not to use a language model in the analysis solutions, the remaining modules work in full: sampling, completing a test without an AI work programme, queries without natural language and the local ML model. The latter runs entirely in Arnhem and exchanges no data with external parties. And in dgaproof.nl AI never does the maths: every euro in the report comes from the deterministic calculation engine.
07Hoe zit het met de Amerikaanse CLOUD Act?What about the American CLOUD Act?
Daar zijn we transparant over. AWS is van Amerikaanse oorsprong en valt formeel onder de CLOUD Act, ook bij verwerking in Ierland. Wat we kunnen aantonen: data wordt fysiek in de EU verwerkt en is region-locked, het contract loopt via AWS EMEA SARL in Luxemburg en er is geen operationele dataflow naar de VS. AWS heeft bovendien publiek toegezegd elk overheidsverzoek juridisch te toetsen en te bestrijden als het in strijd is met EU-recht.We are transparent about that. AWS is of American origin and formally falls under the CLOUD Act, even when processing in Ireland. What we can demonstrate: data is physically processed in the EU and region-locked, the contract runs through AWS EMEA SARL in Luxembourg and there is no operational data flow to the US. AWS has moreover publicly committed to legally reviewing every government request and challenging it if it conflicts with EU law.
Het rest-risico is vergelijkbaar met Microsoft 365 en Google Workspace, die vrijwel elke gemeente al gebruikt. Volledige uitsluiting vereist Europese modellen zoals Mistral, die voor financiële analyses nog onvoldoende kwaliteit leveren. We volgen die ontwikkeling actief.The residual risk is comparable to Microsoft 365 and Google Workspace, which nearly every municipality already uses. Full exclusion would require European models such as Mistral, which do not yet deliver sufficient quality for financial analysis. We follow that development actively.
08Moeten wij een DPIA uitvoeren?Do we need to carry out a DPIA?
Een volledige DPIA is niet per definitie verplicht, maar wel aan te raden vanwege het gebruik van AI. De onderbouwing is een stuk eenvoudiger dan bij systemen die buiten de EER verwerken: de doorgifteparagraaf vervalt, een Transfer Impact Assessment is niet nodig en er is geen profilering, geautomatiseerde besluitvorming of verwerking van bijzondere categorieën persoonsgegevens. Hoofdstuk 06 van dit document is direct bruikbaar als input en we ondersteunen je FG op verzoek.A full DPIA is not mandatory by definition, but advisable given the use of AI. The substantiation is considerably simpler than for systems that process outside the EEA: the transfer section disappears, a Transfer Impact Assessment is not needed and there is no profiling, automated decision-making or processing of special categories of personal data. Chapter 06 of this document can be used directly as input and we support your DPO on request.
09Hoe lang worden gegevens bewaard en wat gebeurt er bij een datalek?How long is data retained and what happens in case of a breach?
Gegevens worden maximaal 7 jaar bewaard. We adviseren je data te verwijderen zodra een analyse of dossier is afgerond; in de analyse-oplossingen zijn analyses altijd te herhalen via de geschiedenisfunctie. Bij einde contract krijg je eerst de beschikking over je gegevens, daarna volgt verwijdering in overleg. We verwijderen nooit data zonder overleg vooraf.Data is retained for at most 7 years. We advise deleting your data as soon as an analysis or file is completed; in the analysis solutions analyses can always be repeated through the history function. At the end of the contract you first receive your data, after which deletion follows in consultation. We never delete data without consulting you first.
Bij een beveiligingsincident handelen we conform ISO 27001 en de AVG-meldplicht (art. 33 en 34): detectie en indamming, interne registratie, melding aan jou binnen 24 uur na ontdekking en ondersteuning bij je melding aan de Autoriteit Persoonsgegevens.In case of a security incident we act in accordance with ISO 27001 and the GDPR notification duty (art. 33 and 34): detection and containment, internal recording, notification to you within 24 hours of discovery and support with your notification to the Dutch Data Protection Authority.
10Welke documenten kunnen we opvragen voor onze DPIA of leveranciersbeoordeling?Which documents can we request for our DPIA or supplier assessment?
Op verzoek sturen we toe: de verwerkersovereenkomst (conform art. 28 AVG; voor gemeenten GIBIT 2023), het AWS Data Processing Addendum inclusief SCC's, het ISO 27001-certificaat met scopebeschrijving, compliancedocumentatie van het datacenter (Eurofiber/Dataplace) en de technische architectuurbeschrijving. We lichten dit document ook graag persoonlijk toe.On request we send: the data processing agreement (in accordance with art. 28 GDPR; for municipalities GIBIT 2023), the AWS Data Processing Addendum including SCCs, the ISO 27001 certificate with scope description, compliance documentation of the data centre (Eurofiber/Dataplace) and the technical architecture description. We are also happy to walk you through this document in person.
Neem het door met je FG of CISOGo through it with your DPO or CISO
Dit is het complete verhaal over beveiliging en gegevensverwerking bij de software-oplossingen van WIDE Solutions. Deel het gerust met je FG, CISO of accountant: er staat niets in dat we niet kunnen onderbouwen.This is the complete story on security and data processing in the WIDE Solutions software. Feel free to share it with your DPO, CISO or accountant: there is nothing in it we cannot substantiate.
De drempel om verantwoord met AI te beginnen is een stuk lager geworden. Geen derde-landanalyse, geen Transfer Impact Assessment, wel een keten die je in één gesprek kunt uitleggen. Loopt er een DPIA of wil je een toelichting op maat? Laat het weten.The threshold for starting with AI responsibly has become considerably lower. No third-country analysis, no Transfer Impact Assessment, but a chain you can explain in a single conversation. Is a DPIA under way, or would you like a tailored walkthrough? Let us know.
dennis.verhaert [at] widesolutions.eu · 06‑57587987
wil.peters [at] widesolutions.eu
Op verzoek beschikbaarAvailable on request
- Verwerkersovereenkomst conform artikel 28 AVG (voor gemeenten: GIBIT 2023)Data processing agreement in accordance with article 28 GDPR (for municipalities: GIBIT 2023)
- AWS Data Processing Addendum inclusief Standard Contractual ClausesAWS Data Processing Addendum including Standard Contractual Clauses
- ISO 27001-certificaat met scopebeschrijvingISO 27001 certificate with scope description
- Compliancedocumentatie Eurofiber Datacenter Arnhem (Dataplace)Compliance documentation Eurofiber Data Centre Arnhem (Dataplace)
- Technische architectuurbeschrijvingTechnical architecture description
BronnenSources
- AVG, Verordening (EU) 2016/679, art. 28, 33 en 34, 44 t/m 46GDPR, Regulation (EU) 2016/679, art. 28, 33 and 34, 44 to 46
- EU AI Act, Verordening (EU) 2024/1689, gefaseerde inwerkingtreding tot augustus 2027EU AI Act, Regulation (EU) 2024/1689, phased entry into force until August 2027
- BIO en BIO2, Baseline Informatiebeveiliging Overheid (BZK / VNG)BIO and BIO2, Dutch government information security baseline (BZK / VNG)
- GGI-Cloud Expertisecentrum (VNG), implementatierichtlijn BIO-compliant cloudinrichtingGGI-Cloud Expertise Centre (VNG), implementation guideline for BIO-compliant cloud setup
- Informatiebeveiligingsdienst voor gemeenten (IBD), VNG RealisatieInformation Security Service for municipalities (IBD), VNG Realisatie
- Anthropic Trust Center, trust.anthropic.com