Governance & your data - Digi Duck AI
GOVERNANCE & YOUR DATA

The more the AI does for you,
the more it matters that you can check it.

Every call, every booking, every change is logged in your own environment. You can open it without asking me.

An AI that answers your phone and fills your calendar is doing work with money attached to it. At that point you don't want reassurance. You want a list you can read yourself: who called, what was said, what got booked, and why. That's what's on this page - including the parts we can't claim.

No contract, no sales pitch. You get the questions before the call.

{{ b }}
FOUR PRINCIPLES

Four rules that don't bend.
Not even when bending would be faster.

{{ p.title }}

{{ p.body }}

WHAT IT RUNS ON

The full list of what sits under your system.

Other companies' logos tell you nothing. Knowing which kind of vendor sits where tells you something.

{{ r.cat }}
{{ r.detail }}

This list gets updated whenever something changes. What counts is the last column of the subprocessor table, not the logo.

SECTOR DATA, NOT OUR NUMBERS

Most companies do this with no rules
and find out when something goes wrong.

13%

of Belgian companies using AI have a formal policy on how they use it.

Source: Wolters Kluwer SME study 2026 / lecercle.ai 2026. Sector data, not our number.

14.4% / 20.7%

of micro businesses and of small businesses use AI today.

Source: Wolters Kluwer SME study 2026 / lecercle.ai 2026. Sector data, not our number.

38%

in Flanders know what it is and don't use it. Usually because nobody explains who is responsible for what.

Source: Wolters Kluwer SME study 2026 / lecercle.ai 2026. Sector data, not our number.

"The bot isn't the work. The connection is the work. And every connection leaves a trail you should be able to read."
Iliace Vermeulen, Digi Duck AI
ON THIS PAGE
Overview GDPR What gets logged What we keep Subprocessors Documents FAQ
Last updated: 7 September 2026

What this system actually touches
and what it never gets to see.

Digi Duck AI builds the layer that answers, books and follows up. To do that, the system needs three things: it has to hold a conversation, look at your calendar, and write something back into the software you already run. That's it.

In practice it touches: the name and number of whoever called, what was said, which slot got booked, and the status fields in your CRM or calendar. It does not touch your bookkeeping, your payroll or your staff files - unless you specifically ask and we agree on it separately.

Everything built sits in your environment. I get access as a guest, with a key you can revoke. That's not a favour - it's the only setup where you still own something when it's over.

Who is what, under the law.
In plain words.

You're the controller. They're your customers, your data, your decision about why it's kept. Digi Duck AI is the processor: we do what you instruct, and nothing else.

That gets written into a data processing agreement we sign before a single connection goes live. It covers the instructions, the retention periods, the subprocessors, and what happens at the end.

We're a Belgian business. GDPR applies to us - that's not a choice and not a badge. What you can reasonably ask for is proof that the arrangements are on paper.

Digi Duck AI holds no ISO 27001 and no SOC 2 Type II. We're also not going to borrow one from a vendor.
Request the DPA

A log you can open yourself,
without having to ask me first.

{{ l }}

If any of this isn't visible to you, it isn't finished.

Keeping data needs a reason
and an end date.

Retention periods get set per client, not imposed as a default. A dental practice has different obligations than a roofer. We write them into the DPA and the system clears things out automatically after that.

TYPE OF DATA
WHERE IT SITS
HOW LONG
{{ k.type }}
{{ k.where }}
{{ k.long }}

Who else is at the table
and what exactly they see.

The honest version: a system like this never runs on one party. Here's which kind of party sees which piece.

{{ s.party }}{{ s.role }}

{{ s.sees }}

If a party gets added, you hear about it before it happens - not after.

What you can ask for
and what doesn't exist yet.

{{ d }}

What we don't have: an audit report, a pentest report or a certificate. If you need one of those to get internal sign-off, say so on the call. Then I'll tell you whether I can arrange it or not.

Request the documents

Twelve questions,
answered straight.

{{ f.q }}+

{{ f.a }}

NEXT STEP

Twenty minutes,
your questions and an honest no if it doesn't fit.

You tell me what's coming in and where it's getting stuck. I tell you what I'd tackle and what it costs. If it doesn't fit, I'll say so - that's shorter for both of us.

Explore my options See the Operations Audit

No contract. No sales pitch. Every build opens with the Operations Audit, and one automation goes live during it.

The risk sits with me, not with you.