Responsible AI

Your data stays yours. So does your AI policy.

The administration belongs to you or your client, and so does the responsibility. We do not take that over. We do show what Claire does with your data, and you choose how Claire works within your AI policy.

The further from the centre, the less a party sees.

The route of a question

What happens between your question and the answer.

Step by step: what happens, and who gets to see which data.

1

You ask a question

In Claire’s chat, or in your own AI assistant, such as Microsoft 365 Copilot, Claude or ChatGPT, connected to Exact Online through Claire.

If you work from your own assistant, that provider processes your question, under your own agreements with it.

2

The language model picks the steps

The model reads your question and picks the Claire functions it needs, such as fetching open invoices or starting a check.

It can only pick functions enabled for your connection. Whatever is off does not exist for Claire.

3

Claire retrieves from Exact Online

Claire requests the data through Exact Online’s official API, with the user’s Exact account. The call goes into the audit log, under your name.

Whatever that user may not see in Exact, Claire cannot retrieve either.

4

Fixed scripts do the maths

For a forecast or the month-end checks, Claire runs fixed calculation rules on the retrieved data. A general journal entry is validated before Claire creates it.

The same data gives the same result, every time.

5

The model writes the answer

The results go back to the language model, which turns them into text, a table or a chart. So the model sees your question and the data retrieved for it, not your whole administration.

In our AI infrastructure, email addresses, phone numbers and credit card numbers are redacted by then.

6

You judge

You see which data Claire retrieved and, for a check, per area what was examined and what was found. If Claire wants to change something in Exact from the chat, you see a proposal first.

Nothing changes until you approve. Through your own assistant, a change does not pass this step.

Security

What is in place today.

Safeguards for controlled use of AI.

Sign-in and access per organisation

You sign in through Auth0, with OpenID Connect and PKCE. Who can use a connection depends on membership of your organisation in Claire.

The rights from Exact Online

Claire retrieves with the connection’s Exact account and reaches no further than that account may in Exact. If every team member connects their own account, each person gets what they may see in Exact.

You decide what is on

Per connection you switch tools and categories on or off. Whatever is off cannot be invoked, not through your own AI assistant either. Categories such as HRM are off by default.

Approval before writing

In Claire’s chat, a change in Exact waits for your approval. Through your own AI assistant or an automation that step does not apply: switch off the write tools for the connection if you only want reading.

Fixed rules for calculations

Forecasts and the month-end checks calculate with fixed scripts, alongside the model’s reasoning. A general journal entry is validated before it is created.

An audit log with names

Per tool call, the audit log records who made it, in which administration, from which source and whether it succeeded. You can filter it and export it as CSV.

Encrypted at rest

We encrypt your connection credentials and the saved state of your conversations with AES-256-GCM.

Automated tests and a reporting address

Our development pipeline runs automated tests and security scans on the code, the software packages it uses and the web application. Report a vulnerability in confidence to privacy@dataflowr.nl.

Your AI policy

Which AI have you already approved? Claire connects to it.

We set Claire up to fit the AI policy you already have. If there is no policy yet, we help you think through a minimum your team will actually follow.

Staff often use AI already, with an export from Exact or a copy pasted into a chat window. A fixed route, with the rights from Exact and an audit log, is easier to control than a policy that exists only on paper.

StandardMost control of your own
  1. Our AI infrastructure

    Every plan

    It is set to send requests only to providers whose terms say they keep nothing and do not train on your data. Email addresses, phone numbers and credit card numbers are redacted there.

  2. Your own AI assistant

    Through MCP

    If your organisation already uses Microsoft 365 Copilot, Claude or ChatGPT, you work with Claire from that assistant, under your own contract. Choose a business plan: for those, the providers state they do not train on your data. Tasks Claire runs itself, such as the month-end close, also go through our AI infrastructure.

  3. Your own provider

    Enterprise

    If you have your own agreements with Microsoft Azure, Amazon Bedrock or Google Vertex AI, we connect Claire to that environment. Your contract, your region and your retention settings then apply.

  4. An open weights model you host

    By arrangement

    Claire also runs on open weights models, on your own servers or with a European cloud provider. You then decide where the model runs and whether any traffic leaves.

  5. A separate environment

    By arrangement

    For the strictest requirements we discuss a separate environment: dedicated servers for Claire, apart from other customers.

With your own provider or your own model, we agree up front which parts of Claire run through it.

Running a supplier assessment? Send us your questionnaire. We answer it with what is in place, and say plainly what is not yet.

Frequently asked questions.

Does the AI train on our data?

No. We do not train models ourselves. Not as a policy but as a contract: our model providers process prompts only to generate an answer. They do not store the data and do not train on it. If you work through your own AI assistant or your own provider, that provider’s terms apply.

What does Claire keep of our data?

Your administration stays in Exact Online and Claire builds no copy of it. What Claire retrieves for a question does become part of the conversation: messages and retrieved data are stored encrypted, while files you upload and large results sit in the conversation’s workspace. A conversation unused for 30 days is cleaned up by default. The audit log has its own retention period.

What does the model provider see?

Your question, the conversation so far and the data Claire retrieved for it. Not your full administration.

Can someone see more through Claire than in Exact?

Not if every team member connects their own Exact account. Claire retrieves data with the connection’s account, and Exact decides what that account may see. If you may not see the directors’ salaries in Exact, Claire cannot retrieve them either. We are happy to walk through how your team has set this up.

Can Claire change anything in Exact without approval?

Not in Claire’s chat: there, a change waits for your approval. Through your own AI assistant or an automation, a change does not pass that step in Claire. If you only want reading there, switch off the write tools for the connection.

Where does Claire run?

Claire runs as SaaS on Google cloud infrastructure. Sign-in goes through Auth0 in a European environment. AI traffic runs through OpenRouter to the model provider by default; that processing can take place outside the EU. If EU processing is a requirement, choose your own provider in a European region or a model you host yourself.

Can I use my own AI provider?

Yes. Claire can connect to the standard APIs of the most common AI providers, such as Microsoft Azure, Amazon Bedrock or Google Vertex AI. Your contract, your region and your retention settings then apply. Bring your own key, the mechanism for supplying such an AI provider of your own, is supported as standard in the Enterprise licence. We agree up front which parts run through your provider.

Can I use local AI models with Claire?

Yes. Claire also works on open weights models you host yourself, on your own servers or with a European cloud provider. You then decide where the model runs and whether any traffic leaves. We agree up front which parts run through that model, and we are happy to help implement local AI.

What about the GDPR?

An administration nearly always holds personal data, such as names on invoices and bank statements. The data processing agreement records what we process, what for and for how long; the sub-processor list, AI providers included, is part of it. Both are available on request. If you work for clients as a firm, discuss with your client beforehand that you use Claire. It is their administration.

Can the model run code itself?

Not in a conversation’s workspace. It is there to store and read files; running scripts is not possible there. Claire only runs fixed, prebuilt functions.