Resource center · Platform

What happens to the data you upload for a test run.

A free test means uploading real regulatory data to a supplier you have not contracted with yet. These are the questions a compliance function asks before that happens, answered plainly.

Q & A Data handling · All frameworks · platform behaviour

What a test run does

A test run takes the file you upload, maps it against the framework you selected, applies the validation rules in force, and returns a validation report. On the free tier the output package is not produced; on a paid plan it is. Nothing else happens to the file. It is not used to train anything, it is not analysed for commercial purposes, and it is not shared.

Where the data sits

Customer regulatory filing data is processed and stored within the European Union. Supporting services that do not handle filing data — analytics, consent management, email, payments — are separate, are disclosed in the privacy notice and subprocessor list, and do not receive uploaded filing data.

Scope of the residency statement. It covers the regulatory filing data you upload. It is not a statement that every service the website uses is located in the Union, and the distinction is set out in the privacy notice rather than blurred here.

Who can access it

Access is limited to the account that uploaded the file, and to the smallest set of staff who need it for support and platform operation, under access controls and audit logging. Where support is requested, access is on request rather than standing, and it is logged.

Where several people share an organisation account, they share visibility of what is uploaded to it. Groups filing for multiple entities that require separation between teams should raise that before uploading, because it is an account structure question rather than a permission toggle.

How long it is kept

Test data is retained for a limited period so you can re-open the validation report and compare runs, and is then deleted. You can delete an upload before that point. Deletion removes the source file and the derived working data; where a validation report has been downloaded, that copy is yours and is outside the platform.

The retention period for test data is set out in the retention schedule referenced from the privacy notice, and differs from retention on a paid plan, where the filing record has a longer useful life.

What leaves the platform

  • Nothing is submitted to any authority. The platform produces a file. Transmission to a supervisor or tax authority is yours to make.
  • No output is sent anywhere automatically. Reports and packages are downloaded by you.
  • Notification emails carry no filing data — they tell you a run finished, not what was in it.

Reducing what you upload

The most effective control is not uploading more than the test needs. Three approaches work without weakening the test:

  1. Test with a subset. A representative slice exercises the mapping and the validation rules as well as a full population does.
  2. Pseudonymise identity fields where the test is about structure rather than about identity. Format-preserving substitutes still exercise format validation.
  3. Test structure before substance. A first run on shape and coded values catches most findings before any live identity data is involved.

These reduce exposure during evaluation. They are not a substitute for the contractual position when you move to production, which is what the data processing terms exist to settle.

Official sources

Primary instruments only. Each is named in full so the reference remains traceable even if a link moves.

  1. Regulation (EU) 2016/679 (General Data Protection Regulation), in particular the principles of purpose limitation, data minimisation and storage limitationEUR-Lex · Regulation · the framework these practices are built against
  2. REGREP privacy notice, retention schedule and subprocessor listREGREP · the operative statements, including retention periods

Questions, answered

Is uploaded data used to improve the platform?

No. Uploaded filing data is processed to run the conversion and validation you asked for. It is not used to train models and it is not analysed for commercial purposes.

Can we test without uploading live client data?

Yes, and it is the approach we would suggest during evaluation. A representative subset with pseudonymised identity fields exercises the mapping and validation rules fully, because format validation works on structure rather than on whether a name is real.

Who at REGREP can see our file?

The account that uploaded it, and the smallest set of staff needed for support and platform operation, under access control and audit logging. Support access is granted on request rather than held as standing access.

What happens if we do not proceed after the test?

Test data is retained for a limited period and then deleted, and you can delete it sooner. Nothing is submitted anywhere, and no output leaves the platform unless you download it.

REGREP is an independent software provider. This record explains a reporting framework in plain language and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.

Keep reading

More on this framework, and the module that produces the filing.

All platform resources

Test on a subset first.

Run a representative slice through the mapping and validation, read the full report, and decide from evidence rather than from a demonstration.