Separate customer environments
The starter provisions a separate PostgreSQL database, storage volumes, application secret and network for each customer instance. Shared infrastructure still requires host-level security and operational review.
Compliance depends on the purpose, data, users and deployment. We document those decisions alongside the software, with a named owner and evidence for the controls that matter.
Define controller and processor roles, lawful basis, retention, rights handling and processor agreements. Privacy by design and appropriate security are addressed from the start. Assess international transfers and whether a DPIA is required for the actual use case.
Record the provider/deployer role, screen prohibited and high-risk uses, provide appropriate AI literacy and disclose AI interaction where required. Relevant transparency obligations apply from 2 August 2026. Review the official timeline for other obligations and transitional provisions before each launch.
The starter provisions a separate PostgreSQL database, storage volumes, application secret and network for each customer instance. Shared infrastructure still requires host-level security and operational review.
The starter assistant receives only published website content selected by the server. It has no shell, deployment credentials, public publishing tool or access to private resource records.
Internal records require authentication and role permissions. Changes are recorded. Draft outputs require a person to review and publish through the CMS.
Run a compatible model on approved infrastructure. Check outbound traffic, logging, backups, hardware capacity and model licensing before claiming that all data stays local.
Document provider terms, processing locations, retention and transfer arrangements. An API proxy does not hide prompt content from the model provider.
A labelled, repeatable simulation works without model credentials. It uses synthetic examples and must not be represented as a live model evaluation.
The implementation provides a technical starting point. Signed processing agreements, the subprocessor register, risk classification, retention operations, independent security review and recovery evidence remain launch requirements for each customer. This is not a certification or a guarantee of legal compliance.
GDPR official text ↗
European Commission: AI transparency ↗
EU AI Act implementation timeline ↗