The platform is built around the controls the GDPR asks for: data kept in the EU, personal data pseudonymized before it leaves, a per-user right to erasure, and a metadata-only audit trail. It will not pretend to make your obligations disappear. It gives you the evidence to meet them.
privacy by design · erasable · auditable
They send personal data to a US model, keep no record you can show an auditor, and leave residency, erasure, and transfer safeguards as your problem. Pseudonymizing the data does not end it either: under GDPR, pseudonymized data is still personal data. You are the controller, and a tool that ignores that is a liability, not a solution.
The PII firewall is on by default, so personal data is pseudonymized before any request leaves the platform. Turning it off takes a recorded acknowledgment, never a silent default.
A single call erases everything stored for an end-user, so a deletion request in your app flows straight through to the platform. Retention is bounded and pruned automatically.
Every request writes a metadata-only audit entry with its model, region, and modules, so your Art. 30 records and reviewer questions are answered with a log, not a guess.
The controls a DPO asks about map directly onto the platform's modules.
No platform can make you GDPR-compliant on its own, and any that claims to is one to distrust. Here is the honest split.
Create a key and ship with the GDPR controls on from the first request, or talk to us about your DPA.
We use privacy-friendly, EU-hosted analytics to understand how Akumi is used. Accept analytics cookies, or continue without them. See our cookie policy.