ClaudeLab

Trust

Using AI does not mean giving your data away.

The most common concern in a first conversation is not whether it works, but what happens to the data. Here is how we handle that - technically and contractually.

How we handle your data

The principle is simple: only what the process genuinely needs leaves your company. We work per process with the smallest slice of data that supports the task, and we record in writing which slice that is.

Which model is used is decided per case. For many tasks a model operated within the EU is enough; for particularly sensitive cases a locally operated one is an option. What is possible in your case is settled after the audit - not promised before it.

What is settled contractually

Data processing agreement
An agreement under Art. 28 GDPR belongs to every project in which we process personal data - before the first processing, not after it.
Data slice
Which fields and sources the process touches is stated in the specification. What is not in there is not processed.
Scope of action
What the system may trigger itself and what a person signs off is fixed and documented per process.
Logging
Traceable record of what the system did and when. Without a log you can prove neither an error nor an improvement.
Deletion
How long something is kept and when it disappears - aligned to your existing retention periods, not to our convenience.

On the EU AI Act

The European AI Act classifies applications by risk, and the obligations follow from what the system does - not from which model sits underneath it. A flow that matches invoices falls into a different class from one that decides about people.

We settle that during the audit against your actual case and align the build accordingly: documentation, human oversight and logging to the extent the classification requires.

Frequently asked

Will our data be used to train AI models?

Not without your explicit decision. We choose accounts and contract forms so that use of your content for training is excluded, and we record that in writing.

Where do the models run?

That is decided per use case. For many processes models operated within the EU are an option; for particularly sensitive cases a locally operated one. What is possible in your case is stated in the audit.

Do you sign a data processing agreement?

Yes, in every project where personal data is processed - before processing begins.

Does the AI decide about people on its own?

No. We do not build systems that decide about individuals without human approval - regardless of whether it would be legally permissible.

Who is liable if the system does something wrong?

We are liable for our work within the agreed contractual scope: architecture, integration, tests and guardrails. Nobody can vouch for the substance of a third-party model output - which is why the scope of action is contractually bounded and anything leaving the company is generally subject to approval.

Can our data protection officer review this?

Explicitly yes. We deliver the technical description in a form that can be reviewed - that is part of the work, not an extra.

Open questions belong before the contract.

If something is missing that you need settled before you can start, ask for it. We answer in writing.