GDPR / DSGVO · EU AI Act · Security by design

Build trust into the setup.

Compliance depends on the purpose, data, users and deployment. We document those decisions alongside the software, with a named owner and evidence for the controls that matter.

GDPR / DSGVO: purpose, access and responsibility.

Define controller and processor roles, lawful basis, retention, rights handling and processor agreements. Privacy by design and appropriate security are addressed from the start. Assess international transfers and whether a DPIA is required for the actual use case.

EU AI Act: classify the use, then apply the requirements.

Record the provider/deployer role, screen prohibited and high-risk uses, provide appropriate AI literacy and disclose AI interaction where required. Relevant transparency obligations apply from 2 August 2026. Review the official timeline for other obligations and transitional provisions before each launch.

Security by design, in practical terms.

Separate customer environments

The starter provisions a separate PostgreSQL database, storage volumes, application secret and network for each customer instance. Shared infrastructure still requires host-level security and operational review.

Constrained assistant

The starter assistant receives only published website content selected by the server. It has no shell, deployment credentials, public publishing tool or access to private resource records.

Visible responsibility

Internal records require authentication and role permissions. Changes are recorded. Draft outputs require a person to review and publish through the CMS.

Choose the inference route explicitly.

Local inference

Run a compatible model on approved infrastructure. Check outbound traffic, logging, backups, hardware capacity and model licensing before claiming that all data stays local.

Approved external provider

Document provider terms, processing locations, retention and transfer arrangements. An API proxy does not hide prompt content from the model provider.

Demonstration mode

A labelled, repeatable simulation works without model credentials. It uses synthetic examples and must not be represented as a live model evaluation.

Evidence before production.

The implementation provides a technical starting point. Signed processing agreements, the subprocessor register, risk classification, retention operations, independent security review and recovery evidence remain launch requirements for each customer. This is not a certification or a guarantee of legal compliance.

Primary sources · reviewed 4 September 2026

GDPR official text ↗
European Commission: AI transparency ↗
EU AI Act implementation timeline ↗

Start with one real problem.

Review your requirements