1. Who we are
Re:group B.V., Albertusstraat 32, 5261 AD Vught, the Netherlands. Chamber of Commerce 98144081, VAT NL868374416B01. For privacy questions, write to luuk@inconcept.ai.
inConcept is a trading name of Re:group B.V. Below is which data we process, why, who we involve and how long we keep it. Plainly written, so you can actually read it back.
Version 11 September 2026
Re:group B.V., Albertusstraat 32, 5261 AD Vught, the Netherlands. Chamber of Commerce 98144081, VAT NL868374416B01. For privacy questions, write to luuk@inconcept.ai.
For our own data we are the controller: your account details, your organisation's details, your invoices and the contact we have with you. That is what this statement covers.
For what you put into inConcept we are the processor and you are the controller: your sources, your brand information and the texts you write. We only do with it what you instruct us to. Those arrangements are in the data processing agreement, which you can request from us and which we enter into when the subscription starts.
Four kinds, each for a different reason.
A brand or person in inConcept can be connected to a website and to an account on LinkedIn, Instagram or Facebook. The customer sets up that connection, or inConcept fills it in when the brand's website links to the account. We only read what is public there, and we never sign in to an account.
What we read and keep:
What for: so inConcept knows what the organisation does and how it writes. The text of a website goes to the language model to derive the brand voice and the description of the brand. Of the posts, we suggest the best ones as example texts, and we adopt a profile picture or logo as long as the brand or person has none yet. A post kept as an example text goes to the language model when inConcept writes a text.
How: we read LinkedIn, Instagram and Facebook through Apify, and only the last three posts of an account at a time. We read websites ourselves, and we follow what a site asks in its robots.txt.
What we do not do with it: we do not sell this data, do not use it for advertising, share it with no one outside the parties in article 6, and do not use it to train language models.
This data belongs to the account of the customer who made the connection. We are the processor for it, as article 2 describes. When the customer removes a connection, we delete the posts read and the bio right away. How to have data deleted, also if you are not a customer yourself, is on inconcept.ai/gegevens-verwijderen.
To perform the agreement: creating an account, having texts written, tracking credits, invoicing.
Because we have a legitimate interest: securing the service, spotting misuse and excessive use, resolving faults and improving the product based on how it is used.
Because the law requires it: our accounting and tax records.
We don't sell data, and we don't use your content to train language models.
We work with a small number of parties needed to run inConcept. They may only use the data to provide their service to us.
Anthropic is based in the United States, and Stripe and Vercel have US parent companies. Those transfers are covered by the European Commission's standard contractual clauses, together with the arrangements these parties make with us. The current position is set out in the data processing agreement.
Not everything for the same length of time, because not everything has the same reason.
inConcept uses two functional cookies: one to keep you signed in and one to remember your language. Without those two the app doesn't work, so no separate consent is needed for them.
Our visitor statistics are cookieless: nothing is stored on your device and you are not tracked across websites. If we start measuring more for marketing later, we'll ask for consent first and update this statement.
Data is encrypted in transit and at rest. In the database, each row records which organisation may access it, so data from different customers can never touch. Access within our team is limited to those who need it and requires two-factor authentication.
To help with a fault or a question, an administrator of our platform can look inside an organisation. That is read-only: in that mode nothing can be changed, created or deleted. Every occasion is recorded, including who looked, at which organisation and when. You can request that overview from us.
You may access, correct, delete or transfer your data, and you may object to certain processing. Send a request to luuk@inconcept.ai; we respond within a month.
How to have data from a connected website or account deleted is set out step by step on inconcept.ai/gegevens-verwijderen.
If your request concerns data held in a customer's account, we are the processor for that and we'll refer you to that organisation. We help them carry out your request.
In the event of a data breach we notify the customers involved within 72 hours, with what happened, which data is affected and what we are doing about it. Where the law requires it, we also report it to the Dutch Data Protection Authority.
We may update this statement as the service changes. We'll announce substantial changes in advance.
If you disagree with how we handle your data, tell us. You can also lodge a complaint with the Dutch Data Protection Authority.