Processed solely within the European Union

Compliance, explained for the people who have to sign it off

This page summarises what the legal documents say. If in doubt, the documents prevail.

recato · compliance in writing
region
European Union
training on your data
off
retention
you choose (1 to 365 days, or delete now)
isolation
one database per customer
backups
encrypted · EU
contract
DPA · GDPR Art. 28

Where the data lives

The application, each customer's database, the files and the backups all sit in data centres inside the European Union. Language model inference runs at a European sub-processor, on European servers, with no prompt retention. There are no transfers outside the European Economic Area.

Never used to train models

Conversations, files and account data are never used to train, fine-tune or evaluate models, neither by us nor by our sub-processors. That commitment lives in the data processing agreement, not on an FAQ page.

Retention controlled by the customer

The administrator sets, in days, how long conversations, attached files and derived memories are kept. Once the period is up they are deleted automatically. Any user can delete their own conversations at any time.

Isolated per customer

Each customer has their own database and their own file store, on their own subdomain. No tables are shared between customers.

The European rules, one by one

We do not say that we comply with «all European legislation»: that is a claim nobody can check. We say which ones apply to us, what each one requires of us and where it is written — so you can confirm it, clause by clause.

RegulationWhat it requires of usWhat we do
GDPR
Regulation (EU) 2016/679
Processing the data on the customer's behalf, under contract, and returning or deleting it at the end. An Article 28 data processing agreement included in every paid plan, at no cost, and processing in the European Union. See the contract.
Artificial Intelligence Act
(EU) 2024/1689
Saying it is a machine, owning what is generated by AI, not deciding on its own, and training whoever operates the system. It is in the Terms, point 7: an AI system, fallible answers, no automated decisions and no high-risk use. The team's training is on record.
Data Act
(EU) 2023/2854
Letting you switch provider: exporting the data, help with the transition, and nothing to pay for leaving. In the account, one button takes everything — conversations, files, memory and tasks — and the owner takes the whole workspace, one folder per user. At no cost and with no prior request. Terms, point 9.
Digital Services Act
(EU) 2022/2065
A published point of contact and a route for reporting illegal content. Both in Contact and in the Terms, point 5, in Portuguese or in English, with a reasoned decision and the possibility of contesting it.
NIS2
Directive (EU) 2022/2555
Cybersecurity measures and incident reporting, for entities of a certain size and sector. Not applicable to us by size, and we do not pretend otherwise. We apply the measures all the same: they are in Annex II of the contract, ready for your supplier file.

This table describes what we do today. European obligations come into force in stages: when what is required of us changes, it changes here and in the documents.

Security

01 · Encryption

In transit and at rest

Encrypted in transit (TLS) and at rest.

02 · Sign-in

Two-factor

Optional two-factor authentication and lockout after repeated attempts.

03 · Backups

Daily and encrypted

Daily encrypted backups, held in the European Union.

04 · Logging

90 days

Access and security events are logged for 90 days.

05 · Provider

Limited access

Administrative access by the provider is limited, logged, and only for support.

Documents for your GDPR file

Read it online or download the PDF to hand to your data protection officer.