Jurisdictions
Controls, residency, retention and the subprocessor position in full.
Read about security →A free test means uploading real regulatory data to a supplier you have not contracted with yet. These are the questions a compliance function asks before that happens, answered plainly.
A test run takes the file you upload, maps it against the framework you selected, applies the validation rules in force, and returns a validation report. On the free tier the output package is not produced; on a paid plan it is. Nothing else happens to the file. It is not used to train anything, it is not analysed for commercial purposes, and it is not shared.
Customer regulatory filing data is processed and stored within the European Union. Supporting services that do not handle filing data — analytics, consent management, email, payments — are separate, are disclosed in the privacy notice and subprocessor list, and do not receive uploaded filing data.
Access is limited to the account that uploaded the file, and to the smallest set of staff who need it for support and platform operation, under access controls and audit logging. Where support is requested, access is on request rather than standing, and it is logged.
Where several people share an organisation account, they share visibility of what is uploaded to it. Groups filing for multiple entities that require separation between teams should raise that before uploading, because it is an account structure question rather than a permission toggle.
Test data is retained for a limited period so you can re-open the validation report and compare runs, and is then deleted. You can delete an upload before that point. Deletion removes the source file and the derived working data; where a validation report has been downloaded, that copy is yours and is outside the platform.
The retention period for test data is set out in the retention schedule referenced from the privacy notice, and differs from retention on a paid plan, where the filing record has a longer useful life.
The most effective control is not uploading more than the test needs. Three approaches work without weakening the test:
These reduce exposure during evaluation. They are not a substitute for the contractual position when you move to production, which is what the data processing terms exist to settle.
Primary instruments only. Each is named in full so the reference remains traceable even if a link moves.
No. Uploaded filing data is processed to run the conversion and validation you asked for. It is not used to train models and it is not analysed for commercial purposes.
Yes, and it is the approach we would suggest during evaluation. A representative subset with pseudonymised identity fields exercises the mapping and validation rules fully, because format validation works on structure rather than on whether a name is real.
The account that uploaded it, and the smallest set of staff needed for support and platform operation, under access control and audit logging. Support access is granted on request rather than held as standing access.
Test data is retained for a limited period and then deleted, and you can delete it sooner. Nothing is submitted anywhere, and no output leaves the platform unless you download it.
REGREP is an independent software provider. This record explains a reporting framework in plain language and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.
More on this framework, and the module that produces the filing.
Controls, residency, retention and the subprocessor position in full.
Read about security →Purposes, legal bases, retention schedule and your rights.
Read the privacy policy →How to build a test file that exercises the rules without carrying more than it needs.
Read the tutorial →Run a representative slice through the mapping and validation, read the full report, and decide from evidence rather than from a demonstration.