Last updated: September 2026
Reclaim processes your financial data to find revenue you've earned but haven't received. We treat that data as a fiduciary duty — here's exactly how we handle it.
Reclaim is built on the Base44 platform. Your customer data — company profiles, recovery opportunities, and invoices — is stored in Base44's managed database infrastructure. Our primary processing region is the European Union.
The controls Reclaim maintains to keep your data confidential, intact, and available.
All data in transit over TLS 1.2+. Data at rest is encrypted by the managed platform.
Row-Level Security (RLS) ensures each company only ever sees its own records — one customer can never access another's data.
Managed auth provider with hashed passwords, optional Google / Microsoft SSO, and email verification.
Role-based access (admin / user). Operators access company data only to deliver the recovery service.
API keys and credentials live in a managed secrets vault — never committed to code or exposed to the client.
We only process what's needed to identify and invoice reclaims. We never sell or share your data.
When you connect Dinero or Fortnox, you provide OAuth client credentials so Reclaim can authorize on your behalf. Here's how those credentials are handled:
The third parties that process customer data on our behalf to deliver the service.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Base44 | Application hosting, managed database, authentication, and file storage | European Union |
| Stripe | Payment processing for success-fee invoices | United States (PCI-DSS Level 1) |
| Google Sheets daily export connector; AI language models | United States / European Union |
We notify customers at least 30 days before engaging a new sub-processor. To object to a new sub-processor, contact us before the engagement date.
We monitor for anomalies and receive reports through internal review and our providers' security alerts.
Within 72 hours of confirming an incident, we assess its scope, severity, and the data affected.
We isolate the issue, rotate affected credentials, and patch the root cause.
We notify affected customers without undue delay — and no later than 72 hours after assessment — including the nature of the breach, data affected, and steps taken.
Every incident is logged in our incident register and reviewed in a post-mortem to prevent recurrence.
To report a suspected security incident, email us immediately at hello@find-hidden-revenue.dk.
Need a Data Processing Agreement (DPA) for your procurement review? Submit the form below and we'll send it within 1–2 business days. The sub-processor list and security overview are shown above on this page.