Security and data handling

PensionChart is operated by MagicCompany.AI BV, registered in Haarlem, the Netherlands (KvK 91269199).

Where the data is

Ireland, for both halves. The application's server-side functions are pinned to a single region — Dublin (eu-west-1) — and the database, authentication and document storage sit in that same region. One region, inside the EU, for the code that processes personal data and for the store that holds it.

That is a deliberate configuration rather than a default: our hosting platform offers several execution regions and only Dublin is selected, so a request is not served from wherever happens to be nearest.

Static assets — the pages, scripts and images that contain nobody's data — are cached on a global network, as they are for any site. What is pinned to Ireland is the part that touches a person's information.

That covers where we host and store. It does not, on its own, describe where every sub-processor operates. If your assessment turns on that, ask — we'll send you the named list with each one's role and processing location, rather than have you infer it from this paragraph.

Encryption

In transit: HTTPS everywhere, with HSTS. At rest: AES-256, applied by the platform to the database and to stored documents alike — so an uploaded pension statement sitting in a client's vault is encrypted on the same terms as the figures extracted from it.

Access control

Every table carries row-level security, so a client's rows are reachable only by that client's session. There are no adviser accounts, so there is no cross-client access to grant or revoke. Administrative access is restricted to the operator; server-side service-role access is used only for the specific operations that cannot run under a user session, such as consuming a redemption code.

Sign-in is passwordless — a one-time code to an email address. There is no password to reuse, leak or rotate.

Backup and recovery

The database is backed up daily, with seven days of retention.

The plain consequence, since a firm will work it out anyway: the worst case is losing up to a day of changes, and anything older than a week cannot be recovered from a backup. We don't publish a recovery-time objective, because we would rather name none than name one we had not measured.

Sub-processors

Six, and these are all of them. We describe them here by what they do rather than by name. The named list — each provider, its role and its processing location — goes to any firm that asks, as part of the security pack we send on request.

What it doesWhat it receives
Application hosting and function executionAll application traffic, served from the pinned region
Database, authentication and document storageAccount data, pension records, uploaded documents
Automated reading of uploaded pension documentsThe document, plus the client profile below
Payment processingEmail address, payment details, and an internal order reference. No pension data
Transactional emailRecipient address and message contents
Appointment schedulingName, email and anything you type when booking a call. No client or pension data

Documents are read by a third-party AI provider under a zero-retention agreement: the file is not stored after processing and is not used to train models. Your client's profile goes with the document — name, date of birth, nationality, where they live and have worked, and the accounts already recorded — and the upload screen tells them so at the moment they choose a file.

Our product analytics provider is not in the list above because it receives no personal data: EU-hosted, proxied through our own domain, with autocapture and session recording off. It gets which pages were viewed, never pension figures, document contents, names or email addresses.

Clients choose at upload whether their original file is kept in their encrypted vault or discarded immediately after analysis.

If something goes wrong

Report a suspected breach or vulnerability to info@pensionchart.com. It reaches a person directly — there is no triage queue in front of it, and no form.

If we become aware of a breach affecting data we hold, we will tell the people affected within 72 hours of becoming aware of it. That is the same clock the GDPR sets for notifying a supervisory authority, and there is no reason for the people whose data it is to hear later than the regulator does.

Breach-notification wording is draft pending Dutch counsel, as is everything on this page touching contract or liability.

Data protection

In the ordinary case a client is our customer and we are the controller of their data, because they hold their own account and we never receive anything about them from you. That is what the code mechanism is for: you hand over a string, so there is no client personal data flowing from your firm to us at all.

Where an arrangement does put us in a processor relationship, a data processing agreement applies. A DPA is available on request ask and you'll get one. There is deliberately no link here to a standing document, because there isn't one to link: it is drawn up with counsel for the arrangement it covers, and a page offering a download of something that does not exist would be the first thing a firm found wrong about us.

Contract, liability and data-protection wording is draft pending Dutch counsel and is not settled.

What we do not hold

No certification is claimed here because none is held. We are not SOC 2 audited, not ISO 27001 certified, and hold no Cyber Essentials assessment. A security page that lists them as planned is telling you about a gap in a way designed to sound like a plan, so this one does not.

Asking something this doesn't answer

Email Marco. It goes to one person, who will either know or say so. If it is easier to talk it through, book a call. See also the privacy policy.

Last reviewed 29 August 2026. PensionChart is operated by MagicCompany.AI BV, Haarlem, The Netherlands.