Grassfeld's Artificial Intelligence Policy
This Artificial Intelligence Policy (“AI Policy”) describes how Grassfeld B.V. uses artificial intelligence (“AI”) within its application, services, and infrastructure. This spolicy applies to users of the application and the website of Grassfeld.
Last updated on June 17, 2026

This Artificial Intelligence Policy (“AI Policy”) describes how Grassfeld B.V. uses artificial intelligence (“AI”) within its applications, services, and infrastructure. This policy applies to users of the application and the website of Grassfeld.
Grassfeld uses advanced AI technologies to support users in obtaining financial insights, automating processes, and improving the user experience. In doing so, privacy, security, transparency, and responsible use remain central.
The purpose of this policy is to inform users about:
- how AI is applied within Grassfeld;
- the responsibilities of users when using AI functionalities;
- how Grassfeld handles data, security, and governance surrounding AI;
- the measures taken to ensure AI is used in a safe, ethical, and responsible manner.
Grassfeld applies a risk-based approach to the development and implementation of AI systems and aligns, where relevant, with generally recognized standards and guidelines, including:
- ISO/IEC 27001;
- ISO/IEC 42001;
- applicable European laws and regulations;
- relevant principles relating to privacy, information security, and AI governance.
Practical Principles for AI Usage
AI functionalities within Grassfeld are supportive in nature. Users should take the following principles into account:
- AI-generated output should always be critically reviewed for accuracy, completeness, and applicability;
- AI functionalities do not constitute binding financial, legal, or professional advice;
- users remain fully responsible for decisions made based on AI-generated output;
- users should handle personal and confidential information carefully when using AI functionalities;
- AI systems may not always possess complete context or up-to-date information;
- AI-generated results may contain inaccuracies, omissions, or interpretational errors.
Grassfeld advises users to use AI functionalities solely as supportive tools within their financial decision-making process.
1.
Use of AI Within the Application
1.
AI for Transaction Categorization and Analysis
Grassfeld uses AI systems to automatically analyze, recognize, and categorize financial transactions.
This technology assists users by:
- automatically classifying transactions;
- identifying recurring payments;
- generating financial insights;
- detecting unusual transactions;
- improving overview and structure within the application.
AI systems may automatically place transactions into categories such as groceries, subscriptions, transportation, or housing based on recognition patterns and historical data.
1.2
AI for Comparisons, Insights, and Suggestions
Grassfeld uses AI technology to provide users with insights, comparisons, and suggestions relating to financial choices, spending behavior, and market developments.
If desired by the user, the AI may compare costs with market information or regional averages in order to help users make more efficient and informed financial decisions.
These analyses and suggestions are supportive in nature and explicitly do not constitute binding financial, legal, or professional advice.
Users remain fully responsible for decisions made based on AI-generated output, insights, or recommendations.
Certain AI functionalities may be in a beta phase. This means functionalities are continuously being tested, improved, and optimized.
2.
Governance and Responsibilities
2.1
Governance
The management of Grassfeld is ultimately responsible for compliance with this AI Policy and the responsible use of AI within the organization.
New AI applications, functionalities, or integrations are assessed in advance based on, among other things:
- strategic value;
- privacy impact;
- information security;
- ethical risks;
- reliability;
- compliance with applicable laws and regulations.
Grassfeld reserves the right to modify, restrict, or discontinue AI functionalities if legal, technical, security-related, or ethical reasons require it.
2.2
Training and Awareness
Grassfeld aims to ensure that employees, partners, and users possess sufficient knowledge regarding AI, the functioning of AI systems, and the associated risks.
This is supported through:
- internal guidelines;
- documentation;
- knowledge bases;
- instructions;
- additional training where relevant.
Grassfeld may require participation in relevant training or awareness programs for employees or partners involved in AI-related activities.
3.
Ethical Principles
Grassfeld recognizes that AI technology involves important ethical responsibilities. Therefore, Grassfeld applies the following core principles in the development, implementation, and use of AI systems.
3.1
Human Oversight and Autonomy
Grassfeld ensures that human oversight and decision-making remain central when using AI systems.
AI functionalities are designed to support users and do not replace human judgment or responsibility.
3.2
Safety and Robustness
Grassfeld strives to maintain technically secure, reliable, and robust AI systems.
Security measures are implemented to protect AI systems against misuse, manipulation, unauthorized access, and cyber threats.
3.3
Privacy and Data Governance
Grassfeld treats personal and financial data with the highest level of care.
Data processing takes place in accordance with the Privacy and Cookie Policy and the Information Security Policy of Grassfeld.
3.4
Transparency
Grassfeld aims to communicate clearly about the use of AI within its services.
Users are informed about the nature of AI functionalities, their limitations, and the ways AI-generated output may be produced.
3.5
Diversity, Non-Discrimination, and Fairness
Grassfeld strives to prevent discrimination, unfair bias, and undesirable outcomes within AI systems wherever reasonably possible.
AI functionalities are developed with attention to accessibility, inclusivity, and fair treatment of users.
3.6
Societal and Environmental Well-Being
Grassfeld considers the societal impact of AI technology and strives for responsible, sustainable, and transparent use of AI.
3.7
Accountability
Grassfeld takes responsibility for how AI systems are deployed within its services.
Where relevant, controls, evaluations, and improvement measures are applied to minimize negative impact.
4.
Privacy and Data Governance
Grassfeld maintains a strict Privacy and Cookie Policy and Information Security Policy. Personal and financial data are not sold to third parties.
Grassfeld applies appropriate technical and organizational measures to protect data against loss, misuse, unauthorized access, and data breaches.
AI systems and supporting infrastructure are managed within secure environments and protected network connections.
Where relevant, data is encrypted and processed in accordance with current security standards.
More information regarding data processing, security, and privacy can be found in:
- the Privacy and Cookie Policy;
- the Information Security Policy of Grassfeld.
5.
User Responsibilities
Users are responsible for the data they enter and use within the application.
As a user, you are expected to:
- critically review AI-generated output for accuracy, completeness, and applicability;
- handle confidential information carefully;
- use AI functionalities responsibly;
- take into account the limitations of AI systems.
Grassfeld assumes users possess basic knowledge regarding the functioning and limitations of AI functionalities.
Users remain solely responsible for the consequences of decisions made based on AI-generated output.
When a user chooses to delete their account, the associated data is removed in accordance with applicable retention periods and internal procedures.
Residual data that may remain within anonymized or technical learning mechanisms cannot be traced back to an individual.
6.
Privacy by Design and Security by Design
Grassfeld applies the principles of “Privacy by Design” and “Security by Design” in the development of AI functionalities, systems, and infrastructure.
This means that privacy, information security, and data protection are structurally integrated from the earliest stages of product and service development.
Examples of implemented measures include:
- data encryption;
- secure network connections;
- strict access controls;
- logging and monitoring;
- pseudonymization where relevant;
- data storage within secure infrastructures.
Grassfeld strives to limit the collection of personal data to only what is necessary for the functioning of its services.
7.
Premium Services
Grassfeld offers premium functionalities through which users may obtain additional control over the processing and application of data within certain AI functionalities.
Certain premium services may allow users to store documents, transactions, or additional data without such data being used for training purposes of specific AI functionalities.
Future intelligent functionalities may include smart connections between documents, transactions, and financial insights.
8.
Incident Management
8.1
Incident Response
Security and AI-related measures are proactively integrated into Grassfeld’s systems and infrastructure.
In the event of a security incident, AI-related incident, or suspected misuse, Grassfeld immediately escalates the matter to the responsible core team.
Affected systems may be temporarily isolated to limit further damage. Where necessary, forensic investigations are conducted into the cause, impact, and scope of the incident.
Grassfeld maintains a security and incident response process aligned with applicable laws and regulations.
More information can be found in the Information Security Policy of Grassfeld.
8.2
User Reporting Obligations
Users are requested to report suspicions of:
- misuse;
- security incidents;
- data breaches;
- ethical violations;
- other AI-related incidents.
Reports should be submitted as soon as possible through Grassfeld’s official communication channels.
9.
Compliance and Legislation
Grassfeld operates in accordance with applicable laws and regulations relating to:
- data protection;
- information security;
- AI governance;
- digital services.
Information regarding compliance with legal obligations is included in:
- the Privacy and Cookie Policy;
- the Information Security Policy;
- other relevant policy documents of Grassfeld.
10.
Policy Updates
This policy may be periodically updated to reflect changes in:
- laws and regulations;
- technological developments;
- AI functionalities;
- security measures;
- organizational changes.
Grassfeld advises users to review this policy regularly to remain informed of any updates.
Contact Details
For questions regarding this policy, AI-related incidents, or reports, please contact:
Rodezand 80
3011 AN Rotterdam
The Netherlands
Grassfeld B.V.
support@grassfeld.com


