Back to homeSecurity & Trust

How we protect your data

Last updated: September 2026

Reclaim processes your financial data to find revenue you've earned but haven't received. We treat that data as a fiduciary duty — here's exactly how we handle it.

Data residency

Reclaim is built on the Base44 platform. Your customer data — company profiles, recovery opportunities, and invoices — is stored in Base44's managed database infrastructure. Our primary processing region is the European Union.

  • Customer records never leave the Base44 managed environment.
  • AI analysis is performed via our LLM providers (see Sub-processors). Only the business context you submit for analysis is sent — raw bank or accounting exports are never transmitted to LLM providers.
  • Sub-processors may process limited data outside the EU under Standard Contractual Clauses (SCCs) and equivalent safeguards.
  • Specific data-residency requirements (e.g. single-region storage) can be arranged on request.

Security controls

The controls Reclaim maintains to keep your data confidential, intact, and available.

Encryption

All data in transit over TLS 1.2+. Data at rest is encrypted by the managed platform.

Data isolation

Row-Level Security (RLS) ensures each company only ever sees its own records — one customer can never access another's data.

Authentication

Managed auth provider with hashed passwords, optional Google / Microsoft SSO, and email verification.

Access control

Role-based access (admin / user). Operators access company data only to deliver the recovery service.

Secrets management

API keys and credentials live in a managed secrets vault — never committed to code or exposed to the client.

Data minimization

We only process what's needed to identify and invoice reclaims. We never sell or share your data.

How we protect your accounting credentials

When you connect Dinero or Fortnox, you provide OAuth client credentials so Reclaim can authorize on your behalf. Here's how those credentials are handled:

  • Server-side storage only. Your client secret is written to a separate, admin-only credential store — never to your company profile, and never returned to the browser on any read.
  • Used solely for authorization. The secret is used server-side, only during the OAuth handshake with Dinero or Fortnox, to obtain a short-lived access token that pulls your invoices.
  • Not visible to your browser. The connection page shows your public client ID (needed to build the authorize URL) and a "connected" status — the secret field is masked and never pre-filled.
  • Operator access only. Only Reclaim operators (admins) can read or manage the credential store, solely to maintain the integration.
  • Revocable anytime. Disconnect by revoking the app in your Dinero or Fortnox developer portal; the stored secret can be cleared on request.

Sub-processors

The third parties that process customer data on our behalf to deliver the service.

Sub-processorPurposeProcessing location
Base44Application hosting, managed database, authentication, and file storageEuropean Union
StripePayment processing for success-fee invoicesUnited States (PCI-DSS Level 1)
GoogleGoogle Sheets daily export connector; AI language modelsUnited States / European Union

We notify customers at least 30 days before engaging a new sub-processor. To object to a new sub-processor, contact us before the engagement date.

Breach notification process

  1. 1

    Detection

    We monitor for anomalies and receive reports through internal review and our providers' security alerts.

  2. 2

    Assessment

    Within 72 hours of confirming an incident, we assess its scope, severity, and the data affected.

  3. 3

    Containment & remediation

    We isolate the issue, rotate affected credentials, and patch the root cause.

  4. 4

    Notification

    We notify affected customers without undue delay — and no later than 72 hours after assessment — including the nature of the breach, data affected, and steps taken.

  5. 5

    Record & review

    Every incident is logged in our incident register and reviewed in a post-mortem to prevent recurrence.

To report a suspected security incident, email us immediately at hello@find-hidden-revenue.dk.

Request a Data Processing Agreement

Need a Data Processing Agreement (DPA) for your procurement review? Submit the form below and we'll send it within 1–2 business days. The sub-processor list and security overview are shown above on this page.

Questions about our security practices? Reach us at hello@find-hidden-revenue.dk.