Manual · Chapter 20 · Part E Privacy and law

Processing region and sovereignty

Purpose

Where a question is processed is no minor matter for many companies: privacy policy, data processing agreements, promises to customers. dAI Pro makes the processing region a setting of the collection, checks it against all services involved and shows visitors the result as an attest in the chat: "AI processing only in the EU" or "only in Germany", with an expandable chain of who processes what. There is also a machine-readable proof.

Where

In the settings of the collection under Further language models and processing region (Chapter 4).

Processing region with check of the services involved
OptionMeaning
No restrictionNo attest. Any model may answer.
EU onlyAttest "AI processing only in the EU" if all services involved process in the EU.
Germany onlyAttest "only in Germany" if all services involved process in Germany.

What is checked

The table below the selection shows the configuration and its region per purpose:

PurposeWhat is behind it
ChatThe language model that answers.
EmbeddingsThe model that generates the search index.
Voice, speech recognitionThe audio providers of the voice chat, if active.

The region of each configuration is entered by the administration when creating it (Chapter 24); for the well-known providers it is preset. One reservation is named but not checked: the text recognition for scanned PDFs during indexing.

The rule: an offer, not a lock

The processing region is a promise to visitors, not a technical lock:

  • If the main configuration meets the region, the chat shows the attest.
  • If it does not but a further configuration does, the attest appears only in embeds with that model. In the chat configurator, "Sovereignty" can then only be selected with a matching model (Chapter 8).
  • If no configuration meets the region, dAI Pro resets it to "No restriction" on saving and says so.
  • Nothing is rejected at runtime: a model outside the region answers, but without the attest.

The attest in the chat

Below the input field the attest appears as a seal. A click expands the chain: provider, model and region per purpose, in the language of the conversation. The link Proof (JSON) leads to the collection's machine-readable proof: providers, models, regions and reservations, without technical addresses. The proof is suitable for data protection officers, data processing agreements and audits; the responses of the endpoint for AI agents (Chapter 14) carry the region as well.

The log

Questions and answers are logged for quality assurance, without linking them to persons, and deleted after the period the administration sets for the instance (Chapter 26). The generated help text names this period. Details from handover forms are not in the log.

European and self-hosted language models

Besides the big providers, dAI Pro supports any server with an OpenAI-compatible interface. For European providers such as IONOS, STACKIT, Mittwald, OVHcloud and Scaleway there are templates with endpoint, models and region; a server of your own in the data centre, for instance with Ollama or vLLM, counts as "Germany". Chapter 24 describes the setup. With such servers the collection works without the provider's cache, i.e. without CAG mode, and the voice chat is not available.

Frequently asked questions

The attest is missing in the chat although the region is set. The embed uses a model that does not meet the region, or "Sovereignty" is switched off under "Features". The check in the settings form names the matching models.

Can I show the attest without checking the region? No. The attest arises only from the check. That is its value.

What about uploading photos? Uploaded files are evaluated by the chat model, i.e. in its region. They are not stored.

See also