Security and data

Your firm’s data must remain protected and under control.

This page explains where the data is stored, who can access it, how AI is used and what we do when something goes wrong. First in simple words; the legal details remain available in the dedicated documents.

The short answer.

Each firm can access only its own data.

The information in one firm is separate from that of the others. Access depends on the user and the role assigned.

Data is protected during transfer and when saved.

We use encrypted connections and the protection services made available by the cloud infrastructure. Credentials are not stored in clear text.

Important activities remain tracked.

Accesses, operations and sensitive passages produce registers useful for reconstructing what happened and who intervened.

Providers are selected and documented.

For cloud, AI and payments we use specialized providers. Roles, places of processing and guarantees are described in the privacy documents.

Where is the data

Different locations, clearly documented.

We do not say generically "in Europe": we indicate the main places and distinguish the use of AI from normal data saving.

Documents
Archived in Italy, in the Milan area.
Databases
Hosted in Switzerland, recognized by the European Union as a country with adequate protection.
Cloud services
The main application processing takes place in the Brussels area.
AI functions
When an AI function is used, we send only the necessary information to the provider. The data is not used to train the models; processing is not guaranteed exclusively in the EU.

When AI comes into play

AI assists the work. It does not remove responsibility.

Defined permissions

The operational functions are enabled for activities and users agreed with the firm.

Uncertainty goes to review

When data is missing or a choice requires judgment, the case is stopped and shown to the accountant.

Traceable activity

Relevant operations remain tracked in order to monitor the work carried out.

If something is wrong

There is a process—not a vague promise.

We control services and access. Anomalous events are analyzed and access can be revoked.

We protect continuity. We use infrastructure backups and recovery tools to reduce the risk of data loss.

We manage incidents. If an event involves personal data, we assess the impact and follow the reporting obligations under the GDPR.

The firm maintains control. You can manage users and roles, request assistance, exercise privacy rights and obtain processing documentation.

Common questions.

Short answers to questions a firm should ask before entrusting its data to software.

Does Optlyx use firm data to train AI models?

No. The data sent to AI providers to perform a function is not used to train their models according to the agreements applicable to the service.

Can AI act without control?

Functions are enabled with defined permissions and rules. Uncertain cases are brought for review and professional decisions remain under consideration.

Can data from different firms mix?

No. Access to data is limited to the firm and authorized users. Controls are applied both in the application and in the database.

Where can I find the legal details and list of suppliers?

In the Privacy Policy, in the DPA and in the privacy dossier. For specific questions you can write to privacy@optlyx.com.

Documents and contacts.

This page helps you orient yourself, but does not replace the contractual and privacy documentation.

Cloud and payment vendor certifications are not Optlyx-registered certifications. The updated list of suppliers and the applicable conditions are indicated in the privacy and contractual documentation.