- Where the data sits
- On your own servers, in a data centre in the EU or at the model provider. For each type of data we define which of these three locations is permitted, before the first connection is made.
- What the model sees
- A language model receives only the section the task requires. The permissions from your existing system continue to apply: anyone who may not open a document there will not see it through the AI function either.
- What the model does not see
- Personal data fields that are not needed for the task are removed or replaced before handover. That is effort in the interface, and it spares you the later discussion with the data protection officer.
- Training with your data
- As a rule no. We choose services in which processing is contractually limited to the individual request, and we put that in writing rather than assuming it.
- Operation on your own premises
- Possible. Open models run on your own hardware if data protection, the works council or a client requires it. The results are somewhat below those of the large providers, but for search and pre-sorting they are sufficient in practice.
- Traceability
- Every answer is delivered with its sources and logged. Without that trail an AI function cannot be used in an audited process, and in a public tender it certainly cannot.
For the European legal framework we also assign your use case to a risk class and record that classification in writing. Most cases in mid-sized companies fall into the lowest class. That belongs on the record.