Data protection and GDPR

The data-processing agreements (DPAs) we sign individually with each client bind us to strict confidentiality,
and this obligation survives the end of our relationship.

We work only with large-language-model providers that have committed, in their privacy statements, data-use pages,
Docs or FAQs (as of March 2026), not to train models on data from business clients who pay for the services.
(See the contractual agreements for the legally binding text)

OpenAI

"By default, we do not use data from ChatGPT Enterprise, ChatGPT Business … or our API platform—including inputs or outputs—for training or improving our models."

Google

"Your data—including prompts, outputs, and training—isn’t used to train Google models or models for any other customer" (Google Cloud, Gemini Enterprise)

Anthropic

"By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models."

xAI

"xAI never trains on your API inputs or outputs without your explicit permission." "Your data stays yours: no training on it, ever" (Grok Enterprise, December 2025)

Privacy by design

The privacy-by-design model we offer for our AI agents supports compliance with the General Data Protection Regulation (GDPR)

The agent can be built to anonymise or pseudonymise personal data before it is processed by a language model such as ChatGPT,
Gemini, Claude or Grok. Filters can also be set to restrict retrieval to information about legal entities drawn from your CRM or ERP,
avoiding the processing of personal data

Data minimisation

We can configure it so that only the small fragments of text or the vector representations needed for contextual retrieval are stored

Purpose limitation

We can configure it so that only certain data is used, and only to answer authorised user queries

Accuracy

Synchronisation with your document repository can keep the information the agent uses up to date

Right to erasure

We can configure so that when a document is deleted from your SharePoint, Google Docs or similar repository, the associated derived representations are removed from the retrieval index

Integrity and confidentiality

AES-256 encryption is applied to protect data at rest and TLS 1.2+ to protect data in transit