Compliance · Europe
GDPR-compliant AI starts with where the data goes.
Self-hosted AI keeps personal data, including health and biometric data, inside your environment, which removes most of the transfer and processor questions cloud AI raises.
- Applies to
- Personal data of people in the EU
- Sensitive data
- Article 9: health, biometric and more
- Fines
- Up to €20m or 4% of turnover
- Our approach
- No AI vendor in the data path
In short
For AI, GDPR mainly asks where personal data flows, who processes it, on what legal basis, for how long and how securely. Running the AI on infrastructure you control means no transfer to an AI vendor, a processor chain you define, and logs that show exactly what was used.
What it asks
Requirements, and how we meet them.
| Requirement | How DeepVox addresses it |
|---|---|
| Lawful basis and purpose limitation | Each agent is scoped to defined sources and purposes; access control enforces it. |
| Special-category data (Article 9) | Health, biometric and similar data stay in your environment; voice recordings are optional and consented. |
| Processors and sub-processors (Article 28) | No AI vendor processes your data; where we operate the system, terms are agreed. |
| International transfers (Chapter V) | Data stays in the region you host; nothing goes to a third-country AI service. |
| Storage limitation | Retention set per source and per log type. |
| Security of processing (Article 32) | Role-based access, encryption options and a full audit trail. |
FAQ
Questions, answered.
Is a cloud AI service in an EU data centre enough for GDPR?
It can be lawful, but a provider subject to the US CLOUD Act can be compelled to produce data it controls, wherever it is stored. Self-hosting removes that exposure.
Are chat logs personal data?
Often yes. Questions and answers can contain personal data, so they get the same access control and retention rules as the sources.
Related
EU AI Act
Most internal knowledge assistants are not high-risk, but the classification must be documented.
Learn more →DORA
Since 17 January 2025, EU financial entities must manage ICT third-party risk, keep a register of ICT arrangements and plan exits.
Learn more →Other markets
Europe, the United States and India.
Learn more →General information, not legal advice. Have your counsel confirm how each rule applies to you. Updated October 2026.
Start with two weeks of evidence, not a sales call.
A fixed-price discovery sprint, credited against whatever comes next. Or write to sales@deepvox.ai.