Data security

How we protect your company’s data

In many companies the biggest risk shows up before any rollout: staff paste company data into personal, free AI chats because nobody gave them a better tool. Working with us puts that in order. These are the rules we follow on every project.

  1. 1Business-grade AI
  2. 2Access only to what is needed
  3. 3A person approves
  4. 4Audit log and backups

Nine principles

You get the same rules in writing with our offer. Each one can be checked.

  1. Business-grade AI only

    We use paid services under contract. Your data is not used to train AI models.

  2. Access only to what is needed

    The system sees only the data its task requires. Where reading is enough, it cannot write.

  3. A person approves

    An email to a customer, a record in a company system, any irreversible action: a named person approves it, not the AI.

  4. Personal data kept away from AI

    If the AI does not need to see names or numbers, we mask them before the data reaches the model.

  5. Passwords in a vault

    Passwords and access keys live in an encrypted vault, separately for each client. They never go into emails or code.

  6. Outside content is only data

    Emails, web pages and attachments from strangers cannot give the system instructions. We protect it against manipulation attempts (prompt injection, the number one risk on the OWASP Top 10 for AI applications).

  7. A complete activity log

    Every action the system takes is recorded. You always know what happened, when, and on whose instruction.

  8. Backups

    Data is backed up automatically and changes can be rolled back. A failure does not mean lost data.

  9. A clean exit

    When our work ends, we remove all our access and delete the data. We confirm it in writing.

Where your data lives: your call

Three options, chosen according to the data the system handles. We agree on it before the quote.

EU cloud

Data stored and processed on servers in the European Union. The fastest rollout.

Hybrid

Data stays in the company. Only what is strictly needed goes to external AI, without personal data.

Fully on-premises

Database and AI model on a server in your company. For data that must not leave the building, such as medical records.

Paperwork

Data processing agreement (GDPR art. 28)

Signed together with the main contract, with a list of sub-processors.

Transparency towards customers

Voice and chat assistants tell people they are talking to AI, as the AI Act requires.

Supplier assessment

For companies covered by NIS2 rules we provide the information needed to assess us as a supplier.

What we do not promise: one hundred percent security. Nobody can honestly guarantee that. We promise the risk is kept to a minimum and every principle above can be checked.

Common questions about AI and data security

Will my data be used to train AI?

No. We only use business versions of AI services whose contracts exclude training on customer data.

Can the data stay in my country or in my company?

Yes. You can choose an EU cloud, a hybrid setup or a full installation on a server in your company.

Can the AI send an email or change data on its own?

Not without a person’s approval. Any outgoing or irreversible action is approved by a named person.

What about GDPR?

We sign a data processing agreement together with the main contract, including a list of sub-processors.

Can you guarantee nothing will leak?

No honest supplier can give a one hundred percent guarantee. We promise the risk is kept to a minimum and each of the nine principles can be checked.

My staff already use ChatGPT. Is that a problem?

If those are personal, free accounts, yes: in many companies that is the biggest risk today. A company tool with clear rules is safer than a ban nobody follows.

Let’s talk about your data before we talk about automation

Tell us what data the system will handle and we will propose a setup and access rules. All in writing, before the quote.