Privacy statement
Last updated 31 July 2026 · Version 1.2
Narutai is a platform for keeping track of your wealth, your bookkeeping and your property in one place. That means sensitive data passes through our hands: bank transactions, invoices, valuations, tenant records and documents. This statement sets out what we do with it.
We do not sell your data and we do not advertise against it. We have built no analytics software, no tag manager and no advertising or social media trackers into Narutai.
In case of doubt, the Dutch text prevails.
1. Who we are
Narutai is operated by Kempen Tax & Finance, with its registered office at Pastoor van Delftlaan 1c, 5845 AJ Sint Anthonis, The Netherlands. We are registered with the Dutch Chamber of Commerce under number 16038685 and our VAT identification number is NL802408849B01.
If you have a question about your data, or want to exercise one of your rights, email us at privacy@narutai.com.
We have not appointed a data protection officer. One is mandatory for public authorities. Beyond that, only for organisations whose core activity is large-scale monitoring of individuals, or large-scale processing of special categories of data (Article 37 GDPR). Given our size that is not currently the case. We will reassess as we grow.
2. Our two roles
Narutai acts in two roles, and which one applies to a given set of data affects your rights.
We are the controller for the data belonging to your account itself: your name and email address, your subscription and payments, the questions you ask us, and the log needed to run the platform securely. For that data we determine the purpose and the means. This statement describes it.
We are a processor for the data you put into Narutai about other people: your clients, your tenants, your contacts and the counterparties on your invoices and bank transactions. You determine the purpose there. We process that data only on your behalf and on your instructions.
That has a consequence which is easily missed: for that data you are the responsible party, even if you are a private landlord with a single property. So your tenant's question about their data comes to you, not to us. A data processing agreement belongs with that role; it forms part of our terms and we will send it to you separately on request.
Are you a tenant, a client of an adviser, or a contact of a user, and would you like to know what has been recorded about you? Address your request to the landlord, adviser or business that uses Narutai. If you do not know who to approach, email us: we will point you in the right direction, and we will help that party carry out your request.
3. Whose data we process
Not everyone whose data appears in Narutai has an account. We distinguish five groups.
| Who | Which data | Where it comes from |
|---|---|---|
| Individual users | Everything listed below, to the extent you record it | You provide it yourself, or it arrives through a connection you set up (bank, broker, cloud storage) |
| Advisers and firms | Name, email address, role and use of the platform | The user themselves, or the organisation that invites them |
| Clients of an adviser | Everything listed below, to the extent the adviser records it | The adviser enters it or invites the client, who then completes the details themselves |
| Tenants | Name, address, contact details, date of birth, rent, deposit and — if the landlord records them — income and identity details | The landlord enters it when drawing up a tenancy agreement, or it comes from documents the tenant has supplied |
| Counterparties on invoices and bank transactions | Name, IBAN, address, amount, date and the description shown on the invoice or statement | From the invoices you upload and the bank transactions that arrive through your bank connection |
For the last two groups we do not obtain the data from the person concerned. We process it purely as a processor, on the instructions of the user who enters it or sets up the connection, and only for the purpose that user needs it for: performing a tenancy agreement, booking an invoice, or matching a payment to the invoice it belongs to.
Informing these people about the processing is the responsibility of the user who enters their data. That is not a brush-off: it is the same rule that lets them exercise their rights with that user. We support them in doing so.
4. What data we process
- Identity and contact details: name, email address, telephone number, address, date of birth, nationality and marital status.
- Account data: your sign-in details, your role, your language preference, your notification settings and when you last signed in. Your password is held by our authentication provider; we never see it.
- Financial data: assets and valuations, debts and loans, income and pensions, securities positions and trades.
- Payment and banking data: IBANs, bank transactions with description and counterparty account, balances and bank statements.
- Tax numbers: RSIN (the tax number of a legal entity) or Dutch citizen service number (BSN), VAT identification number (btw-id) and Chamber of Commerce number — see below.
- Bookkeeping data: purchase and sales invoices, journal entries, the general ledger, VAT returns and the supporting documents.
- Property and rental data: addresses, WOZ valuations, tenancy agreements, rents, deposits, service charges and tenant records.
- Documents: anything you upload or pull in through a connection, including invoices, contracts and bank statements.
- Email: messages you send through Narutai or receive at your Narutai address, including sender, recipients, subject, content and attachments.
- Usage data: a log of which actions were carried out, when and by whom.
The Dutch citizen service number (BSN) deserves a separate note. Under Article 46 of the Dutch GDPR Implementation Act a BSN may only be used where a statute prescribes it. Narutai offers the option of recording a tax number because an income or corporate tax return requires it. Entering it is always optional, and the field is not used to identify individuals or match them to one another.
Narutai never asks for special categories of personal data within the meaning of Article 9 GDPR and has no fields for them: no health data, religion, political opinion or biometrics.
Take care when uploading documents. A copy of an identity document contains a photograph and a BSN. The Dutch Data Protection Authority takes the view that a landlord should not keep such a copy and that nationality is not relevant to letting residential property. Prefer to record only that you have seen the document. What you do upload is read like any other document — including by the AI feature described below.
5. Why we process data, and on what legal basis
The table below covers the processing for which we are responsible. For the data you record about other people we follow your instructions: your purposes, your legal bases and your retention periods apply there, not ours.
| Purpose | Legal basis |
|---|---|
| Creating your account and granting access | Performance of the contract (Art. 6(1)(b) GDPR) |
| Delivering the platform: tracking wealth, keeping books, managing property and tenancies, storing documents | Performance of the contract |
| Establishing and refreshing bank and broker connections | Your explicit consent, per connection and withdrawable at any time |
| Connections to cloud storage | Your consent, per connection and withdrawable at any time |
| Sending and receiving email at your Narutai address, and linking those messages to your files | Performance of the contract |
| Reading invoices and documents automatically using AI, and answering your questions to the assistant | Performance of the contract — it is a platform feature you choose to use |
| Keeping your AI conversations and extraction results so you can see what a proposal was based on | Performance of the contract |
| Subscription, invoicing and collection | Performance of the contract; for retaining our own books: legal obligation (Art. 6(1)(c) GDPR) |
| Answering your questions and communicating with you about the service | Performance of the contract |
| Security, abuse prevention and maintaining a log of actions | Legitimate interest (Art. 6(1)(f) GDPR): we must be able to establish who carried out which financial action and to detect unauthorised access. Without a log, a mistake or an abuse cannot be traced. |
| Resolving faults and improving the service | Legitimate interest: delivering a working, usable product. We never use more data for this than is needed to reproduce the problem. |
A legitimate interest means we have a substantial reason of our own for the processing and have weighed it against your privacy. You may object to such processing; see "Your rights".
We need your name, email address and payment details in order to enter into a contract with you: without them we cannot supply an account. Everything else — a bank connection, a tax number, an uploaded document — is voluntary. If you leave it out, at most certain features will not work.
6. Bank connections (PSD2)
If you want to connect a bank account, that runs through a party licensed by the regulator to retrieve bank data on your behalf: an account information service provider. Narutai is not itself a payment service provider and has no access to your bank. We receive only the data you release through that provider. Which providers we use is listed on our supplier list.
You give explicit consent for this separately from the rest of your agreement with us. That consent applies per connection and is never pre-ticked. You can withdraw it at any time by disconnecting in Narutai; after that we retrieve no further data.
Transactions already retrieved remain for as long as your bookkeeping needs them. You are the one required to keep your books for seven years (Article 52 of the Dutch General Tax Act), and we keep them for you. If you ask for deletion, we delete everything you do not need in order to meet that obligation.
A bank transaction almost always contains someone else's data: the counterparty to the payment. That person has no agreement with us and has asked us for nothing. We process their data only to display, book and match your transaction to the right invoice — no profiling, no enrichment, no onward sale. We do so on your instructions, and the legal basis is your legitimate interest in accurate bookkeeping, bounded by what that counterparty may reasonably expect.
7. Artificial intelligence
Narutai uses AI to take work off your hands: reading invoices and bank statements, proposing journal entries, drafting text and answering your questions about your own bookkeeping. Those features run only at the moment you use them — when you upload a document to be read, or when you address the assistant.
For those features we send the relevant content to Anthropic, the provider of the Claude models. That may be a complete document — an invoice, a loan agreement, a bank statement — or the text of an email, or a summary of your wealth. We send only the data that task requires.
- Anthropic processes this data as a processor, under a data processing agreement with us.
- Anthropic does not use the content to train models. That is fixed contractually.
- Processing takes place on servers in the United States. Anthropic currently offers no processing within the EU. The transfer rests on standard contractual clauses; see the section on transfers.
- If you would rather have no AI processing at all, contact us. There is currently no switch in the application for you to do this yourself; we will arrange it with you.
You can enter your own Anthropic or OpenAI API key on the billing page. If you do, AI requests go to your account with that provider, and the terms of your own contract apply rather than ours.
One exception to that, because it is surprising: automatic document extraction only works with Claude. So if you supply an OpenAI key, invoice extraction still runs over our connection to Anthropic. Only the assistant uses your own key in that case.
8. Automated decision-making
We do not let a computer take decisions about people on its own. That goes especially for decisions with legal consequences, or with a major effect on someone's life (Article 22 GDPR). Narutai does not assess creditworthiness, does not assign scores and does not accept or reject anyone on the basis of a calculation.
What AI does in Narutai is make proposals: this looks like the supplier, this looks like the amount, this looks like the right ledger account. You decide.
Two settings can record a booking automatically, and they deserve explanation. If you set a supplier to automatic booking, Narutai copies the booking you made yourself last time for that supplier. If anything differs, the invoice goes back for manual review. The booking is also flagged "still to be confirmed".
You can also create bank rules yourself that book a transaction immediately. Such a rule does exactly what you put into it and books without separate confirmation. AI can help draft the rule, but a rule only becomes active once you have approved it.
In both cases the booking decision itself is not made by AI. The amounts and lines it is applied to are read from your document by AI, and that remains something to check by hand. Either way this concerns your own bookkeeping, not a decision about a person.
9. Who we share data with
We do not sell data and do not share it for other parties' commercial purposes. We do engage suppliers needed to run Narutai: hosting, database, email, payments, bank connections, storage and AI.
A data processing agreement is in place with the suppliers that process on our behalf. Two parties fall outside that because they are independently responsible for what they do with your data: our payment provider and your broker. That too is stated per row in the list.
We think "categories of recipients" is too vague to be useful, so we name our suppliers, giving each one's country of processing and transfer safeguard:
We also query public registers and sources, such as the Dutch Land Registry (BAG and WOZ), PDOK, EP-Online and the European Commission's VAT validation service. We send an address, an identifier or a number — never a file or an overview of your wealth. Those parties are on the supplier list too.
Finally, we disclose data where the law obliges us to, for example to a supervisory authority or under a court order. We always assess such a request and disclose no more than is demanded.
10. Transfers outside the European Economic Area
Your data is held in the European Union. Our database, your documents and the servers running the application are in Frankfurt, Germany. Some supporting components of our hosting and database provider — logs in particular — run outside the EU.
A number of suppliers are established in the United States. For the AI functionality processing genuinely takes place there, because that provider has no European alternative.
For every transfer outside the EEA we use a valid safeguard under Chapter V GDPR. Where an adequacy decision exists — a decision of the European Commission that a country offers sufficient protection — we rely on it. Otherwise we use the standard contractual clauses adopted by the European Commission (Decision 2021/914), supplemented by an assessment of the situation in the receiving country.
Which safeguard applies to which supplier is stated per row in the supplier list. We will send you a copy of the safeguards used on request.
One thing we state explicitly because it is often left out: building and deploying new versions of Narutai happens at our hosting provider in the United States, and this is not configurable. That processes our program code, not customer data from the database.
11. How long we keep data
We do not consider "as long as necessary" an answer. Below is how long each kind of data stays. For your bookkeeping, note that the retention obligation rests on you; we keep those records for you for as long as that obligation runs.
| Data | Retention period | Why |
|---|---|---|
| Bookkeeping: invoices, journal entries, the general ledger, bank transactions, VAT returns and supporting documents | 7 years after the end of the financial year they relate to | You must keep your records for seven years (Article 52 of the Dutch General Tax Act); we keep them for you |
| Data on immovable property: real estate, tenancy agreements, service charges and the related invoices | 10 years after the year the property was first brought into use | VAT on a property can be recalculated for up to ten years after it is first used; the records must be kept until then |
| Fiscal-year archive files you download or share with your accountant | 7 days, then deleted automatically | A temporary copy so the records can be handed over; the original documents remain under the retention period above |
| Share links to such an archive and their log (recipient, date, number of downloads) | 90 days after the file has been deleted | Being able to show what was provided, when and to whom |
| Account, profile and preference data | For as long as your account exists; deleted thereafter | Performance of the contract |
| Our own invoices to you, and your payments | 7 years after the end of the financial year | Our own retention obligation |
| Bank transactions not booked into a set of accounts | For as long as your account exists, or sooner if you disconnect and ask for deletion | Performance of the contract |
| Email sent or received through Narutai | For as long as your account exists | The messages belong to your files and bookkeeping |
| AI conversations and document extraction results | For as long as your account exists | You must be able to see what a proposal was based on |
| Log of actions in the application | For as long as your account exists | Without a log there is no way to establish who carried out which financial action |
| Deleted drafts and messages in the bin | 30 days, then permanently deleted | A chance to recover from a mistake |
| Our correspondence with you about questions and faults | 2 years after resolution | Answering recurring questions and being able to trace complaints |
If you cancel your subscription or delete your account, we delete your data within one month, except for the records covered by the retention periods above. What remains, we no longer use: it is kept solely so that we can meet a statutory retention obligation.
Separately, our hosting provider keeps technical logs which contain IP addresses. Those logs are theirs and serve only to detect faults and abuse.
12. Your rights
- Access: you may ask which data we process about you and receive a copy.
- Rectification: if data is wrong, we correct it. Much of it you can correct yourself in the application.
- Erasure: you may ask us to delete your data, except what must be kept under a retention obligation.
- Restriction: you may ask us to halt processing, for example while a dispute about accuracy is running.
- Portability: you may receive the data you supplied, or that was retrieved with your consent, in a common file format.
- Objection: you may object to processing that rests on our legitimate interest.
- Withdrawing consent: consent you have given can be withdrawn at any time, without affecting the lawfulness of processing before that point.
Send a request by email to privacy@narutai.com. We respond within one month. If your request is complex we may extend that period by two months; we will tell you within the first month if we do.
You cannot yet delete your account yourself, and you cannot yet export your data with a single button. If you ask, we do it by hand. We may ask for additional details if we are not certain who is making the request: with financial data in particular, we do not want to disclose to the wrong person.
Two limits on the right to erasure come up often in practice. Data covered by a retention obligation is not deleted but restricted: we no longer use it, but it is kept until the period expires. And a document attached as supporting evidence to a posted invoice cannot be deleted while that entry exists — your bookkeeping would lose its substantiation.
13. How we secure your data
- All traffic between you and Narutai runs over an encrypted connection (TLS).
- Our database and your documents are held in the European Union and stored encrypted.
- Access tokens for connected services — your bank, your cloud storage, your broker — are stored encrypted, never as readable text.
- Connections request the least possible privilege. The OneDrive connection, for example, is granted access only to its own Narutai folder, not to the rest of your drive.
- Access within the platform is bound to roles and to the organisation you belong to.
- Financial actions are recorded in a log: who, what and when.
- Passwords are managed and stored encrypted by our authentication provider. We have no access to your password.
Who at Narutai can look. A small number of staff have technical access to the systems holding your data. They use that access only to resolve a fault or answer a question from you, are bound by confidentiality, and actions in the application end up in the same log. If an adviser temporarily takes over a client's environment, that is recorded too.
Two-factor authentication is available and optional. You switch it on yourself under Settings → Security: you pair an authenticator app and then enter a six-digit code alongside your password when signing in. With two-factor authentication on, you cannot reach the application without that code and our APIs release no data either.
When you switch it on you receive ten recovery codes, once. Keep them somewhere other than your phone — not in the same app or the same vault, or they are lost together with the factor they exist to replace. If you lose your authenticator, one recovery code switches two-factor authentication off, after which you sign in with your password and set it up again. Each code works once. Of your codes we keep only an irreversible mathematical fingerprint, not a readable copy: we cannot send them to you again. If you lose your codes as well as your authenticator, contact us — we will then switch two-factor authentication off by hand, once we have established that you are the account holder. Every use of a recovery code is recorded in our log and reported to you.
Do you suspect a vulnerability or a data breach? Report it via privacy@narutai.com. We investigate every report. Where it concerns data for which we are the controller, we report a breach posing a risk to the people concerned without undue delay and within 72 hours at the latest to the Dutch Data Protection Authority, and to you where required. Where it concerns data we process on your behalf, we report it to you as quickly as possible, so that you can assess whether a notification is needed.
15. Changes to this statement
We update this statement as Narutai changes, for instance when a supplier is added or a feature starts using different data. The version and the date of the last change are always shown at the top. For a significant change — including a new supplier processing your data — we notify you actively, by email or in the application, before it takes effect.
16. Contact and complaints
Questions, requests or complaints about your data can be sent to Kempen Tax & Finance, Pastoor van Delftlaan 1c, 5845 AJ Sint Anthonis, The Netherlands, or by email to privacy@narutai.com.
If we cannot resolve it together, you have the right to lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens (Dutch Data Protection Authority), Postbus 93374, 2509 AJ Den Haag. You may also go there directly; you do not have to come to us first.