The EU AI Act arrives August 2. Can you prove where your AI data goes?
GDPR compliance

AI a DPO can sign off.

The platform is built around the controls the GDPR asks for: data kept in the EU, personal data pseudonymized before it leaves, a per-user right to erasure, and a metadata-only audit trail. It will not pretend to make your obligations disappear. It gives you the evidence to meet them.

privacy by design · erasable · auditable

Compliance posture per organization
EU data residency Art. 44, transfers built in
PII pseudonymization Art. 25, by design built in
Right to erasure Art. 17 built in
Audit trail, metadata-only Art. 30, records built in
DPA and sub-processors Art. 28 with your DPA

Most AI tools hand the GDPR problem back to you.

They send personal data to a US model, keep no record you can show an auditor, and leave residency, erasure, and transfer safeguards as your problem. Pseudonymizing the data does not end it either: under GDPR, pseudonymized data is still personal data. You are the controller, and a tool that ignores that is a liability, not a solution.

The controls built in, the burden made lighter.

Privacy by design

The PII firewall is on by default, so personal data is pseudonymized before any request leaves the platform. Turning it off takes a recorded acknowledgment, never a silent default.

Data subject rights

A single call erases everything stored for an end-user, so a deletion request in your app flows straight through to the platform. Retention is bounded and pruned automatically.

Accountability

Every request writes a metadata-only audit entry with its model, region, and modules, so your Art. 30 records and reviewer questions are answered with a log, not a guess.

Every module is governed and metered on its own.

The controls a DPO asks about map directly onto the platform's modules.

PII Firewall Pseudonymize-and-restore, on by default. Model Router Fail-closed egress guard for non-EU routing. Recall Per-user facts and documents, erasable on request. Observability A metadata-only trace of every request. Inference API Served on EU-resident models.

We will not sell you a compliance checkbox.

No platform can make you GDPR-compliant on its own, and any that claims to is one to distrust. Here is the honest split.

Build on controls, not promises.

Create a key and ship with the GDPR controls on from the first request, or talk to us about your DPA.