Where your data goes, exactly.
Beyond Venn's whole pitch is showing our working. That applies to how we handle your data too. This page explains what happens to the documents and data you share with us for analysis. It accompanies our data processing agreement, which we sign with you before any work starts; it doesn't replace it.
What we take in
Only what you give us for the agreed piece of work: reports, operational data exports, KPI extracts. Where we connect to a system rather than receive a file, the connection is read-only. We don't collect anything beyond the agreed scope without asking first.
Where it goes
Your data touches three providers, all under GDPR-compliant data processing agreements:
| Step | Provider | What happens | Where |
|---|---|---|---|
| Analysis | Anthropic (Claude API) | Documents are analysed by the Claude model. Anthropic does not train models on this data. | US, covered by the UK Extension to the EU‑US Data Privacy Framework |
| Storage & processing | Google Cloud | Files and results are stored and processed. | UK/EU region (London, europe-west2) |
| Interface | Vercel | The dashboard you log into is hosted here. Nothing is publicly accessible; all content sits behind authentication. | EU-routed deployment |
No other parties see your data. We don't sell it, share it, or reuse it across clients.
How long we keep it
For the duration of the engagement, plus 30 days for handover. After that it's deleted from all three providers. You can ask for earlier deletion at any time and we'll confirm within 5 working days.
Your role and ours
You stay the data controller; Maxie Earle Ltd acts as your processor under UK GDPR. That means we only process your data on your written instructions, we flag any personal-data concerns before processing rather than after, and we notify you without undue delay if anything goes wrong.
Due diligence, on request
If your procurement or IT team needs paperwork before we start, ask. Available today from security@beyondvenn.com:
- Our data processing agreement, or a review of yours.
- A completed supplier or security questionnaire in your format.
- The full sub-processor list with regions and safeguards.
- Company details for vendor onboarding: Maxie Earle Ltd, company no. 16070758, registered in England and Wales.
- Your NDA or ours, whichever you prefer.
Cyber Essentials certification is in progress; this page gets the badge and certificate number when it lands. If a document you need isn't listed, ask anyway. If we don't have it, we'll say so rather than improvise one.
Found a security problem?
If you've spotted a vulnerability in this site or in the product, email security@beyondvenn.com with enough detail to reproduce it. You'll get a reply from the person who can fix it, normally within one working day. Please don't test against systems holding client data.
Last updated 29 September 2026.