Privacy & transparency
REPS / TRUST

Trust Center

Version 0.1Draft updated September 30, 2026EDITORIAL DRAFT · NOT PUBLISHED
ON THIS PAGE

Draft status. This page is grounded in the two supplied policies, each dated September 23, 2026. Policy-stated means documented there, not independently verified. [VERIFY] marks an operational claim requiring evidence. [TO COMPLETE] marks missing information. [PROPOSED] marks new wording or an approach requiring adoption. The training-policy discrepancy described below must be resolved before publication. Editorial labels should only be removed once their questions have been answered.

REPS is the AI-powered service operated by DeltaBase CommV in Belgium. This Trust Center brings together the information customers need to understand how their data is handled, what AI outputs mean, and which questions still require confirmation.

This page complements the Terms of Use and Privacy & Cookie Policy. It does not amend those documents or resolve inconsistencies between them. The Terms set out contractual use, ownership and responsibilities. The Privacy & Cookie Policy describes personal-data processing, retention, rights and cookies. Both refer to a Data Processing Addendum (DPA); [TO COMPLETE: supply the applicable DPA and its customer access route].

01 / Data and responsibilities

Policy-stated. REPS acts as controller for account management, billing, marketing and website/platform usage analytics. For Customer Data uploaded for AI processing, the Privacy Policy describes the customer as controller and REPS as processor, with processing governed by the DPA. See Privacy, Part 1 §1.

The policy identifies four data categories:

Category Examples identified in the policy
Account & Identity Data Name, business email, company, telephone number and login credentials
Billing & Financial Data Invoicing address, VAT number and payment details
Technical & Usage Data IP address, browser, device identifiers, time zone and interaction logs
AI Input & Prompt Data Personal data included in submitted prompts, text, files or media

[TO COMPLETE] Map REPS-specific transcripts, recordings, assessment scores, coaching reports and progress history to the policy and DPA. Their collection, access rules and retention are not established by these files. Do not assume psychometrics, embeddings, CRM integrations or voice recording are enabled.

Policy-stated ownership. Users retain ownership and intellectual property rights in Input. Rights to Output are assigned to the user to the extent the Company has them, subject to compliance with the Terms and payment of applicable fees. Output may not be unique. See Terms §3.

02 / AI processing and where data goes

Policy-stated architecture. The Privacy Policy describes the platform, database and open-source AI models as physically hosted with Combell in Belgium. It also names OpenAI and Anthropic as third-party API providers for specific capabilities. The policy states that their data-protection agreements prohibit use of the submitted data to train their models. These are existing policy commitments, not verified vendor guarantees in this draft.

[VERIFY] Confirm the production services, contracted entities, account settings, model endpoints, data categories, storage regions, processing locations, support access and backups. Belgian primary hosting does not by itself establish that all processing stays in Belgium or the EEA.

For transfers outside the EEA, the policy describes an adequacy decision or Standard Contractual Clauses combined with Transfer Impact Assessments. [VERIFY] Identify the mechanism and assessment actually applicable to each recipient and service. See Privacy, Part 1 §§4–6.

REPS practice and coaching flow — template to complete

[PROPOSED; implementation unverified] Use the following register to make each enabled capability understandable. It is not a representation of the deployed architecture.

Stage Information to identify Required completion
Practice Scenario, participant Input and permitted context [Enabled modes, collected data and recipients]
Speech, if enabled Audio, transcription and generated speech [Providers, recording behavior, locations and retention]
Simulation Input and context used to generate the counterpart response [Model, provider, exact payload and storage]
Assessment, if enabled Evidence and rubric used to generate observations or scores [Criteria, model, recipients and storage]
Coaching, if enabled Evidence, results and history used to produce feedback [Model, permitted history and retention]
Progress, if enabled Individual or team results visible over time [Visibility, aggregation rules, access and deletion]

03 / Does customer data train AI?

Publication blocker: the source policies need reconciliation. The clauses below are preserved because their scopes and consent mechanisms differ. This draft does not infer which clause prevails.

Privacy Policy, Part 1 §4 — personal data in Input and Output:

No Training on Customer Prompts: We do not use personal data contained within your Inputs or Outputs to train, fine-tune, or optimize our proprietary or open-source machine learning models without your explicit, separate opt-in consent.

Terms §3 — Standard Account Tier:

Standard Account Tier: Unless explicitly agreed otherwise or opted-out via your dashboard settings, you grant the Company a limited, anonymized, royalty-free license to use Input and Output strictly to evaluate, improve, and optimize our infrastructure and AI models.

Terms §3 — Enterprise/Paid Tiers:

Enterprise/Paid Tiers: The Company guarantees that Inputs and Outputs processed within paid commercial tiers are hosted securely, treated as confidential, and never utilized to train, fine-tune, or improve any foundational or public artificial intelligence models without your prior, explicit written consent.

[TO COMPLETE] Clarify what Standard means, whether tiers overlap, what qualifies as anonymized data, and whether evaluation, prompt optimization, benchmarking, proprietary-model improvement or customer-specific adaptation is permitted. Verify that actual controls match the resulting wording. An opt-out license is not evidence of separate opt-in consent.

Separately, the Privacy Policy states that OpenAI and Anthropic are contractually prohibited from training on API data. [VERIFY] Check this against the actual agreements and configurations. A no-training restriction does not establish zero retention: provider logging, abuse monitoring and deletion periods remain [TO COMPLETE].

04 / Providers and subprocessors

The following is a policy-derived starting inventory, not a complete verified subprocessor register. Legal entity names, roles and service scope require confirmation.

Name in source Policy-stated purpose or commitment Verification required
Combell Belgium hosting for platform, database and open-source AI models; local hosting of primary account data and metadata Contracting entity; precise services; data categories; backups; remote access; DPA; locations
OpenAI API capabilities; agreement prohibiting model training on submitted data Entity; model/service; Input categories; processing and storage regions; retention; account settings; DPA; transfer mechanism
Anthropic API capabilities; agreement prohibiting model training on submitted data Entity; model/service; Input categories; processing and storage regions; retention; account settings; DPA; transfer mechanism
[Unnamed payment provider] Payment details handled by a third-party provider described as PCI-DSS compliant Name; controller/processor role; PCI scope/evidence; data received; location; retention

[TO COMPLETE] Inventory any additional hosting, authentication, email, speech, analytics, monitoring, storage and support suppliers actually used. Do not add vendors from the earlier competitor template merely because they are common in the market.

Changes to this register: [TO COMPLETE: applicable DPA provisions, notification method, notice period, objection process and remedies]. The supplied policies do not establish a subprocessor-change notice period. The Terms' 30-day notice for price indexation is unrelated.

Customer-connected services: [TO COMPLETE if applicable: available integrations, permissions, data exchanged, roles and revocation/deletion behavior]. Customer authorization alone does not determine a provider's legal role.

05 / Retention and deletion

The following wording comes directly from Privacy, Part 1 §5:

Category Existing policy wording
Account Data “Retained for the duration of your active subscription and deleted 30 days post-termination.”
Billing Data “Retained for seven (7) years to comply with Belgian fiscal and accounting regulations.”
AI Cache/Logs “Transient Input logs used for system error detection are automatically deleted or thoroughly anonymized within thirty (30) days.”

[VERIFY] Confirm implemented deletion jobs, anonymization methods and applicable billing-record requirements. These statements are preserved, not independently validated.

[TO COMPLETE] Specify retention and deletion for stored Inputs and Outputs, transcripts, recordings, scores, coaching reports, uploads, security logs, backups and provider-held copies. The 30-day error-log period must not be presented as a universal limit for all AI data. Document exceptions, termination/export handling and deletion propagation.

The policy discourages submission of sensitive personal data and states that, if submitted, it is processed automatically and transiently. [VERIFY] Check that storage, logs and provider handling support this statement. It is not evidence that all audio or all Inputs are never stored.

06 / Security and reliability

Policy-stated. Paid-tier Inputs and Outputs are described as securely hosted and confidential. The Terms require users to protect account credentials and report unauthorized access to support@reps.be. See Terms §§2–3.

The supplied policies do not specify the controls below. Complete them from implementation evidence before making affirmative public claims.

Area Evidence and wording to complete
Encryption [Transport and storage coverage; protocols; key management; exceptions]
Access [MFA coverage; production access; role boundaries; support access; review and revocation]
Customer separation [Tenant isolation design and tests; administrator and manager visibility]
Development and vulnerabilities [Review process; scanning; patching; penetration-test date and scope, if any]
Incidents [Detection; response owner; reporting route; contractual notification terms]
Backups and recovery [Backup locations and retention; restore testing; evidenced recovery objectives]
Availability [Monitoring; status route; measured availability; applicable SLA, if any]

No uptime percentage, response deadline, recovery target, security certification or penetration-test result is asserted here. The Terms describe the service as provided “as is” and “as available”; this draft adds no SLA.

07 / AI judging, coaching and human review

Policy-stated. The Terms acknowledge that AI outputs can be inaccurate, incomplete or biased and require users to review, verify and validate outputs before relying on them. The Privacy Policy states:

Automated Decision-Making: Our Service acts as a productivity tool. We do not use your personal data to perform automated individual decision-making that produces legal or significantly similar effects (Article 22 GDPR).

See Terms §5 and Privacy, Part 1 §4.

[PROPOSED — REPS-specific positioning, subject to product and policy approval]

REPS practice feedback is intended to support learning. A simulation result should be considered in its context and reviewed by a person before it informs a consequential decision. Scores should not be used as the sole basis for employment, promotion, compensation or disciplinary decisions.

[TO COMPLETE before presenting capabilities as available] Explain what each score measures, which rubric applies, what evidence supports feedback, who can see results, and how a learner can report an error or seek review. Document testing for scoring consistency and bias. State the actual boundaries on personality, emotion, protected-characteristic and employment-suitability inferences. Do not claim these inferences are technically excluded without evidence.

The Terms prohibit specified unacceptable-risk uses, competing-model extraction and harmful content. Their restrictions should remain in the Terms of Use, rather than being rewritten here into new contractual obligations.

08 / Privacy rights and cookies

The Privacy & Cookie Policy describes legal bases, access, rectification, erasure, restriction, portability and objection rights, and a complaint route to the Belgian Data Protection Authority.

Privacy contact: [TO COMPLETE: replace the source's “[Insert Privacy Email]” with a monitored, approved address]. The source lists Support@reps.be as its corporate contact; it does not establish that this is the designated privacy mailbox.

Policy-stated cookie commitments. Non-essential cookies activate only after consent. The policy describes a first-visit banner and a footer “Cookie Settings” route for changing or withdrawing consent. [VERIFY] Test prior blocking, reject/customize choices, withdrawal and the actual footer control. This document contains no working consent-management control.

[TO COMPLETE] The source says cookies fall into three groups but supplies no group descriptions or inventory. Add actual cookie/storage names, purposes, providers, durations and consent categories to the adjacent policy after verification. Do not label REPS tracker-free or claim that clearing a browser cache reliably withdraws consent without checking the implementation.

09 / Compliance and supporting evidence

The Privacy Policy states compliance with the GDPR, Belgian legislation and the EU AI Act. Those statements remain in the source policy; their presence does not demonstrate compliance or constitute independent assurance.

[VERIFY] Review the applicable obligations, intended uses and supporting records. The files do not establish REPS SOC 2, ISO 27001 or ISO 42001 certification, an audit in progress, or a dated certification roadmap. No such claims are made here. A provider's certification must not be presented as REPS certification.

Supporting item Status for this draft
Terms of Use Supplied; September 23, 2026 baseline preserved
Privacy & Cookie Policy Supplied; September 23, 2026 baseline preserved
DPA Referenced by both policies; not supplied
Provider agreements and transfer records Not supplied
Security overview and control evidence [TO COMPLETE]
AI evaluation and governance evidence [TO COMPLETE]
Independent assurance reports None supplied; availability unverified

[TO COMPLETE] Confirm which documents exist, who can request them and any access conditions before offering downloads or a procurement evidence portal.

10 / Contact and changes

Corporate contact: Support@reps.be, as listed in the Privacy Policy.
Unauthorized account access: support@reps.be, as specified in the Terms.
Privacy requests: [TO COMPLETE: designated privacy contact].
Vulnerability reports and procurement questions: [TO COMPLETE: approved routes].

September 30, 2026 — v0.1 draft: Prepared from the two supplied September 23 policies. Added a complementary Trust Center structure, policy cross-links and explicit verification markers. No policy amendments, certifications or additional vendor guarantees are established by this draft.

[TO COMPLETE] Assign a page owner, review cadence and publication date. Record subsequent factual changes here; contractual notices follow the applicable agreement.


Trust Center · Terms of Use · Privacy & Cookie Policy

Internal companion: Source review and publication decisions.