Skip to content
← Blog

Private AI in the EU: what it means for your data not to leave your environment

· 4 min read · Sertoria

Can a provider use your data to train an AI model? The answer depends on the service, contract and configuration. Before entering company information, check where it is processed, who can access it and what they can use it for.

Three ways to use AI

These three options have different data terms:

  • Consumer tools on personal accounts. Whoever pastes a contract into a free chat sends that text to the tool’s provider. Depending on the plan and the settings, the provider may keep the conversations or use them to improve its service.
  • Business accounts for AI tools. Some plans exclude model training on your data by contract. Data still reaches the tool provider. Check the plan, region, retention and permissions. We use corporate accounts and authorized documents in our training.
  • Models used from your own cloud. Managed AI services give access to models from your company’s cloud account. We use this architecture in our integration projects. We check the terms of each service and model.

What it means for your data not to leave your environment

In our deployments, the third option meets these conditions:

  • Processing happens in your own cloud and only in European Union regions. The applications are deployed in your company’s account, and requests to the model are handled in data centers in the EU.
  • Model developers do not receive your data. The cloud’s AI service runs the model. The developer cannot access requests or responses. Your data is not used to train models.
  • You control query logs. If you enable a log to audit the system, it stays in your account. You define the retention period.
  • Data travels encrypted and is stored encrypted in your account.

The cloud provider does process the data. It acts as a data processor under your company’s contract, in accordance with article 28 of the GDPR, Regulation (EU) 2016/679. Here, your environment means your account, your contract and European Union regions. EU hosting alone does not guarantee GDPR compliance.

Conditions we check before deployment

Data location depends on the service and configuration. We check these conditions in each deployment:

  • Routing limited to the EU. Some services offer to spread requests across regions worldwide to gain capacity or lower the cost. We limit processing to EU regions.
  • Models available in the EU. Not every model is offered in the EU. We exclude models that require global routing.
  • No retention by the service. We verify that the service does not retain requests or responses. We disable optional retention. The client’s own logs are managed separately.
  • Narrow permissions. The system can only call the allowed models and regions, and every configuration change is logged.

Six questions for any AI provider

Ask for written answers to these questions:

  1. Which region is my data processed in, and can routing ever leave the EU?
  2. Does the model maker receive my data or have any access to it?
  3. Is my data used to train any model, yours or anyone else’s?
  4. Are my queries stored? Where, for how long and who can read them?
  5. Who is the data processor, and which contract covers it?
  6. What happens to my data and to the system if we stop working together?

If an answer depends on a plan or configuration, ask the provider to identify those conditions.

How we do it

We deploy applications in your cloud account. We use models from several developers through that cloud’s AI service, only in EU regions. You own the code and infrastructure from day one. The AI integration report includes data and security measures for each use case. Our way of working applies privacy by design.

Privacy needs verifiable conditions, not just a private AI label. Check the contract, configuration and data access before deployment. Repeat the review when the service changes.

We can review your case in a free 30-minute call. We then propose a starting point in writing.

Let’s talk