Processed solely within the European Union
Compliance, explained for the people who have to sign it off
This page summarises what the legal documents say. If in doubt, the documents prevail.
- region
- European Union
- training on your data
- off
- retention
- you choose (1 to 365 days, or delete now)
- isolation
- one database per customer
- backups
- encrypted · EU
- contract
- DPA · GDPR Art. 28
Where the data lives
The application, each customer's database, the files and the backups all sit in data centres inside the European Union. Language model inference runs at a European sub-processor, on European servers, with no prompt retention. There are no transfers outside the European Economic Area.
Never used to train models
Conversations, files and account data are never used to train, fine-tune or evaluate models, neither by us nor by our sub-processors. That commitment lives in the data processing agreement, not on an FAQ page.
Retention controlled by the customer
The administrator sets, in days, how long conversations, attached files and derived memories are kept. Once the period is up they are deleted automatically. Any user can delete their own conversations at any time.
Isolated per customer
Each customer has their own database and their own file store, on their own subdomain. No tables are shared between customers.
The European rules, one by one
We do not say that we comply with «all European legislation»: that is a claim nobody can check. We say which ones apply to us, what each one requires of us and where it is written — so you can confirm it, clause by clause.
| Regulation | What it requires of us | What we do |
|---|---|---|
| GDPR Regulation (EU) 2016/679 |
Processing the data on the customer's behalf, under contract, and returning or deleting it at the end. | An Article 28 data processing agreement included in every paid plan, at no cost, and processing in the European Union. See the contract. |
| Artificial Intelligence Act (EU) 2024/1689 |
Saying it is a machine, owning what is generated by AI, not deciding on its own, and training whoever operates the system. | It is in the Terms, point 7: an AI system, fallible answers, no automated decisions and no high-risk use. The team's training is on record. |
| Data Act (EU) 2023/2854 |
Letting you switch provider: exporting the data, help with the transition, and nothing to pay for leaving. | In the account, one button takes everything — conversations, files, memory and tasks — and the owner takes the whole workspace, one folder per user. At no cost and with no prior request. Terms, point 9. |
| Digital Services Act (EU) 2022/2065 |
A published point of contact and a route for reporting illegal content. | Both in Contact and in the Terms, point 5, in Portuguese or in English, with a reasoned decision and the possibility of contesting it. |
| NIS2 Directive (EU) 2022/2555 |
Cybersecurity measures and incident reporting, for entities of a certain size and sector. | Not applicable to us by size, and we do not pretend otherwise. We apply the measures all the same: they are in Annex II of the contract, ready for your supplier file. |
This table describes what we do today. European obligations come into force in stages: when what is required of us changes, it changes here and in the documents.
Security
In transit and at rest
Encrypted in transit (TLS) and at rest.
Two-factor
Optional two-factor authentication and lockout after repeated attempts.
Daily and encrypted
Daily encrypted backups, held in the European Union.
90 days
Access and security events are logged for 90 days.
Limited access
Administrative access by the provider is limited, logged, and only for support.
Documents for your GDPR file
Read it online or download the PDF to hand to your data protection officer.