Supplier statement
Privacy Notice
How Summa collects, uses, protects, retains and shares personal data.
Trust Centre · Public supplier information
A current, structured source for legal, privacy, security, architecture, AI governance and operational due diligence.
This selection controls downloaded files only. It is independent from the website language.
Document catalogue
Each published document remains available in PDF and Word. When a document changes, the previous version and a plain-language change summary stay visible here.
01
The privacy notice, the terms you contract on, the processing agreement, and what the service commits to deliver.
Supplier statement
How Summa collects, uses, protects, retains and shares personal data.
Supplier statement
The terms organisations contract on.
Supplier statement
The terms governing personal use of the service.
Supplier statement
What the service covers, which service levels apply to a pilot as against production, and how support works.
Supplier statement
The standard processor agreement for business customers, reviewable before you make contact.
02
The safeguards behind the service, who is involved in running it, where the data physically sits, and how government requests are handled.
Supplier statement
Which parties are involved, for what, and which country the data sits in.
Supplier statement
The safeguards behind the service, at the level of detail a customer needs to form their own judgement.
Supplier statement
Where the service runs, how data moves through it, and how government requests are handled.
Supplier statement
The state of certification, audits and compliance — including what has not been demonstrated yet.
03
What the AI system may be used for, and the limits it operates under.
Supplier statement
What the service may be used for, and what the AI system explicitly cannot or must not decide.
04
Retention and deletion, the formats your data comes back in, and how leaving works.
Supplier statement
Retention periods, deletion, export formats and the switching arrangement under the Data Act.
Public sector & procurement
GIBIT 2025, BIO2, AI Act, DPIA support, archiving and procurement documentation exists and is shared for customer due diligence. It is not published here: it is written for one buyer’s assessment, and some of it would tell an attacker more than it tells you.
Het volledige technische dossier: systeembeschrijving, risicoclassificatie, menselijk toezicht en conformiteitsonderbouwing.
Analyse van de toepasselijkheid van elk kader en de gevolgen voor de dienst.
Artikel-voor-artikel beoordeling tegen de GIBIT 2025-voorwaarden, inclusief de afwijkingen en de onderbouwing daarvan.
Beoordeling tegen BIO2, de gemeentelijke ICT-kwaliteitsnormen en de pas-toe-of-leg-uit-lijst.
Ondersteunend materiaal voor een gemeentelijke DPIA, AI-toets en inkooptraject.
Archiefwet- en Woo-implicaties, DUTO-conformiteit en het exitdossier.
Productverklaring en ondersteunde standaarden voor de GEMMA Softwarecatalogus.
De volledige componenteninventaris van de dienst. Op verzoek, omdat een publieke componentenlijst vooral aanvallers helpt.
Use of these materials
These materials help security, privacy, legal, procurement and IT teams evaluate Summa. They do not complete a customer's DPIA, AI Act assessment or internal approval. Each organisation remains responsible for its own use case, risks and decisions.
Contact us about due diligence