# GDPR compliance: AI your DPO can sign off

Data kept in the EU, personal data pseudonymized before it leaves, a per-user right to erasure, and a metadata-only audit trail. Evidence, not assurances.

## AI a DPO can sign off.

The platform is built around the controls the GDPR asks for: data kept in the EU, personal data pseudonymized before it leaves, a per-user right to erasure, and a metadata-only audit trail. It will not pretend to make your obligations disappear. It gives you the evidence to meet them.

privacy by design · erasable · auditable

Five controls, and the article each one answers.

## Most AI tools hand the GDPR problem back to you.

They send personal data to a US model, keep no record you can show an auditor, and leave residency, erasure and transfer safeguards as your problem. Pseudonymizing the data does not end it either: under GDPR, pseudonymized data is still personal data. You are the controller, and a tool that ignores that is a liability, not a solution.

## The controls built in, the burden made lighter.

Three of the questions a data protection officer asks have platform answers rather than process answers, which is the difference between a control and an intention.

### Privacy by design

The firewall is on by default, so personal data is pseudonymized before any request leaves the platform. Turning it off takes a recorded acknowledgment, never a silent default.

### Data subject rights

A single call erases everything stored for an end-user, so a deletion request in your app flows straight through to the platform. Retention is bounded and pruned automatically.

### Accountability

Every request writes a metadata-only audit entry with its model, region and services, so your Art. 30 records and reviewer questions are answered with a log, not a guess.

## Every control maps onto a service.

The controls a data protection officer asks about are not a compliance module bolted on the side. Each one is a service, metered on its own and switched on per request.

- Firewall: Pseudonymize-and-restore, on by default.

- Model Router: Fail-closed egress guard for non-EU routing.

- Recall: Per-user facts and documents, erasable on request.

- Audit Trail: One metadata-only record per request, retained on your policy.

- Compliance Center: Art. 30 records built from what actually ran.

- Inference API: Served on EU-resident models.

## We will not sell you a compliance checkbox.

No platform can make you GDPR-compliant on its own, and any that claims to is one to distrust. Here is the split between what we do and what stays yours.

### Pseudonymized is still personal data

The firewall reduces exposure. It does not remove the obligation. Routing pseudonymized data to a non-EU model is still a transfer that needs the right agreements.

### You stay the controller

You decide what is processed and why. The platform acts as your processor and gives you the controls and records to hold up your end.

### The DPA is a real document

A data processing agreement and the sub-processor list are part of the relationship, and they belong with your legal team, not behind a single checkbox.

### Evidence, not assurances

What the platform does provide is provable: per-request residency, recorded overrides, and a metadata-only audit trail you can export for a review.

## Questions a DPO asks first.

### Does this make us GDPR-compliant?

No, and no platform can. You stay the controller. What the platform gives you is the controls the regulation asks for and the evidence that they ran.

### Can personal data reach a model outside the EU?

Only where you have allowed it, with the firewall on or an acknowledgment on record. The default is to refuse, and the refusal is recorded.

### How do we answer an erasure request?

One call wipes everything stored for an end-user, so a deletion request in your own app flows straight through. Retention is bounded and pruned automatically.

### What do we show an auditor?

An export of the audit trail for a date range, the residency evidence, the sub-processor list, and the Art. 30 record the Compliance Center builds from them.

### Is prompt content stored?

No. The audit trail is metadata only: what ran, when, in which region and under which policy.

## Build on controls, not promises.

Create a key and ship with the GDPR controls on from the first request, or talk to us about your DPA.
