Compliance

Data protection, the EU AI Act and security in every project: what gets signed, who reviews it and where your data is processed.

Our commitment

In artificial intelligence, the law comes first

In many AI projects, data protection and security are left until the end. Or not dealt with at all. Here they come first.

  • Every project goes through a regulatory compliance review: data protection and the EU AI Act.
  • Our data protection and compliance partner, Forrellat Consultors, is also our Data Protection Officer registered with the AEPD, and reviews the data protection documentation of every project before it is signed.
  • Before we touch a single piece of data: non-disclosure agreement and data processing agreement signed.
  • Each person signs in with their own identity and only sees and does what their permissions allow. Every operation is logged: who, what and when.
  • Data in Europe: processing on the platform runs on AI infrastructure and services located in the European Union. Using Claude or ChatGPT as the work interface is covered by the provider’s data processing agreement, with the European Commission’s standard contractual clauses.

It isn’t a certification: it’s a documented process, and we’ll show it to you.

Step by step

What gets signed in each phase

We work in two phases: first a diagnosis and, if you decide to go ahead, the implementation. In each one, the right documents are signed, always before any personal data is processed. The order is always the same: you accept the quote, Forrellat reviews the data protection documentation, we sign it, and only then does the work begin. The non-disclosure agreement does not replace the data processing agreement: they are two different documents and both are needed.

Phase 1 · Diagnosis

  • Non-disclosure agreement, always, before we see anything about your company.
  • Data processing agreement, if we’ll be working with personal data during the diagnosis, which is usually the case. In this phase, the providers involved are authorized by category, and the list with their names reaches you before the implementation.

Phase 2 · Implementation

  • Before starting, the documentation goes through Forrellat again, which reviews it before it is signed, just as in the diagnosis.
  • Full data processing agreement, with an annex naming each subprocessor: who else is involved in the processing, for what and where.
  • Impact assessment, assessed on a case-by-case basis. If your processing requires it, it’s done. If not, we give you the reasons in writing why it isn’t needed.
  • System classification under the EU AI Act, with the transparency and training obligations that apply to it.
  • Your obligations as data controller, in writing: what’s up to you, such as the record of processing activities, informing people, your own agreement with the AI provider you use, and training your team.

Who reviews what

Our data protection partner

Forrellat Consultors is our data protection and regulatory compliance partner and our Data Protection Officer, registered with the AEPD.

We prepare the data protection documentation for each project —confidentiality, data processing agreement, impact assessment— and Forrellat reviews it before it is signed.

The EU AI Act review —classifying each system and documenting its obligations— is done by us, because it requires knowing from the inside how the system is built. And before closing each document we check the regulations in force: the AI Act is still evolving, and we follow it closely.

Most of what we do —connecting the programs your company already legally uses to AI, with a person who decides— is not usually considered high-risk under the AI Act. But it’s always checked, case by case: some uses, such as recruitment, creditworthiness assessment or biometrics, require different treatment.

Data in Europe

Where your data is processed

The platform’s processing runs on AI infrastructure and services located in the European Union. Users’ use of Claude or ChatGPT as a work interface is covered by the provider’s Data Processing Agreement with the European Commission’s Standard Contractual Clauses (international transfer with appropriate safeguards, Art. 46 GDPR).

Put simply, there are two parts and it is not advisable to mix them:

  • The platform —everything we run: the central system, the Robust Autopilots, document reading— is processed in the European Union, and the AI provider is contractually committed not to use your data to train its models.
  • The screen you are working from. If you use Claude or ChatGPT with your company account, that provider can store the conversations outside the European Union. It is lawful because it is covered by their data processing agreement, with standard contractual clauses, and we reinforce it with minimization: the smart connector only brings the essential data into the conversation, and sensitive operations are limited by permissions.
  • Never with free or personal AI plans, because they don’t include that data processing agreement.

If your company needs the work screen to be in Europe too, there are alternatives, and we look at them in the diagnosis.

A person decides

Human in the Loop: AI proposes, a person decides

Our AI works with your data and never decides on its own: it proposes, and a person always makes the final decision. No sensitive action (money, contracts, customer data) is carried out without confirmation. Before anything changes, you see what it’s going to do and approve it.

Security and control

Who gets in, what they can do and how to leave

Your identity, your permissions

Everyone signs in with their own identity, with no shared users, and only sees and does what their permissions allow.

A record of every operation

Every operation is recorded: who, what and when. If something ever needs to be reviewed, it’s in writing.

We add, we don’t replace

We add, we don’t replace. Your ERP is still your ERP and your email is still your email. If you ever stopped working with us, you’d keep invoicing and reading your email exactly as you do today. And you have a documented exit plan to get your data back in a usable format.

What we don't do

We do not provide legal advice

We’re artificial intelligence consultants, not lawyers. We don’t tell you that your company is compliant, and we don’t replace your legal advisor.

What we do: we give you the map —which regulations affect your project, which documents are needed, what’s up to us and what’s up to you— and, when your case needs it, the path to a specialist.

Who we work with

Our partner in data protection and regulatory compliance: Forrellat Consultors

Meta Tech Provider verified

Technology we work with, selected to comply with European regulations: Google Cloud · Vertex AI · Microsoft Azure

Shall we talk about your case?

In the diagnosis we show you the documentation we would sign and what the regulations mean for your project.