European-hosted · CLOUD Act-secure

GDPR-Compliant AI for Businesses European & secure

Deploy AI without giving up control over your data: European language models, an on-premises option, and data protection built in from the start.

Many providers advertise EU servers. We go further: European or self-hosted models, GDPR by design, and full traceability of every AI call. This keeps data sovereignty in your hands — without compromising on utility.

  • European language models – Mistral (France) instead of US providers: fully within the European legal framework, without any Cloud Act risk.
  • Self-hosted on request – the AI runs on your own infrastructure; your data never leaves your premises.
  • GDPR by Design – data minimisation, data processing agreement and deletion concepts from the outset, not as a retrofit.
  • Traceable – every AI call is logged; answers cite their sources.
  • Freely selectable – You decide per use case which model works – transparent and documented.
Does this fit your project? Arrange an initial consultation Without sales pressure · honest assessment
dconnect.dreistein.de
GDPR-compliant AI for companies, European & secure
CLOUD Act-safe
Mistral or self-hosted

For whom?

For companies, public authorities and organisations that want to use AI – but in a legally compliant way

You see the benefits of AI, but data protection officers, IT security or works councils raise the right questions: Where does our data go? Who can access it? What happens to our users' inputs? On this page you will find the answers – and a way to use AI without giving up control over your data. The technical implementation is handled by our platform dAi Pro.

Why “Hosted in the EU” Isn’t Enough – and How We Close the Gap

The US CLOUD Act obliges US companies to hand over data to American authorities – regardless of where the servers are located. An EU data center operated by a US provider therefore does not solve the problem.

Since the CLOUD Act of 2018, the following applies: American providers must hand over data upon official order, even if it is stored exclusively in Europe. Anyone who uses OpenAI, Google or Microsoft as an AI engine transmits content and user inputs to precisely such providers – and potentially relinquishes control. Since the ECJ's Schrems II ruling at the latest, it has been clear how legally fragile data transfers to the USA are.

Our approach:

  • European models. Upon request, we use exclusively models such as Mistral (France) – powerful and fully subject to the European legal framework, without CLOUD Act risk.
  • Self-hosted models. Where maximum sovereignty is required, the AI runs locally on your own infrastructure. Your data never leaves your premises.
  • No US providers unless you want them. You decide which models are used – transparently and documented. And when a US model is the best choice for a non-critical use case, you make that decision consciously – per use case, not across the board.
  • GDPR by design. Data minimization, data processing agreement (DPA), clear deletion concepts and EU hosting are part of the solution, not an afterthought.

How this works technically – model selection per use case, logging, on-premises operation – is demonstrated by our platform dAi Pro – AI with your knowledge.

GDPR by Design: Data Protection Implemented at the Technical Level

For us, data protection is not a paper promise but architecture

These principles are built into our AI solutions – not bolted on afterwards:

  • Data minimisation. Only the passages needed for the respective response go to the language model – never the entire knowledge base, never whole data sets.
  • No training with your data. Your content and your users' inputs are not used to train third-party models – contractually secured through the providers' API terms or excluded entirely in self-hosted operation.
  • Original data stays with you. Only what you release is indexed; your systems remain authoritative. Controlled bridges instead of data copies.
  • Data processing agreement & deletion concepts. Data processing, retention periods and deletion procedures are defined at the start of the project – together with your data protection officer.
  • Rights & roles. Who may maintain which knowledge sets, use which models, view which analyses? A group-based rights system governs this transparently.
  • Complete logging. Every AI call is recorded with its purpose, scope and cost – the basis for accountability (Art. 5(2) GDPR) and internal audits.

How to Recognise GDPR-Compliant AI – The Checklist

Whether you speak with us or another provider, these six questions separate genuine GDPR compliance from marketing:

  1. Where do the language models run – and who owns them? "EU servers" alone are not enough if a US provider stands behind them (CLOUD Act).
  2. Which data leaves your organisation? Entire document collections – or only the passages needed for the answer?
  3. Are your inputs used to train models? If that is not clearly excluded: stay away.
  4. Are there a data processing agreement, deletion concept and TOMs? A data processing agreement and technical and organisational measures must be in place from the outset – not only on request.
  5. Is it traceable what the AI does? Without logging of requests, sources and costs, you cannot fulfil your accountability obligation.
  6. Can you switch? If the knowledge base and configuration are locked in at the provider, the next dependency is pre-programmed. Your data should remain portable.

You will find our answers to all six questions on this page – and in detail on the product page for dAi Pro.

The Technical Foundation: Our dAi Pro Platform

Everything stated on this page is not a declaration of intent, but implemented in our AI platform dAi Pro – as a TYPO3 extension or standalone web application:

  • Model selection per use case. Mistral (EU), OpenAI or Anthropic – configurable separately per knowledge collection, with your own API keys. European first, US models only where you consciously decide.
  • Your data remains authoritative. dAi Pro reads knowledge from your existing systems – without migration; only the relevant passages are sent to the AI.
  • Traceability built in. Query log and cost overview in euros for each individual AI call – exportable for audits and controlling.
  • On-premises capable. A standard web hosting environment with its own database is sufficient – on request, everything runs entirely on your infrastructure.

Functions, screenshots and application scenarios in detail: dAi Pro – AI with your knowledge

Questions and Answers

Is the use of ChatGPT & Co. in the company possible in a GDPR-compliant way?

In principle yes – but not by having employees simply use the public chat. What is needed is a controlled integration via the API with a data processing agreement, clear rules on which data may be transmitted, and the exclusion of use for model training. For many use cases, a European model such as Mistral is the considerably more straightforward choice – we will advise you honestly on what suits your scenario.

What is the US CLOUD Act – and why does it also affect EU servers?

The CLOUD Act (2018) obliges US companies to hand over data to American authorities upon order – regardless of where that data is stored. A data centre in Frankfurt therefore offers no protection if the operator is a US provider. This is why we rely by default on European providers such as Mistral or on self-hosted models.

Isn't it sufficient if the AI provider has servers in the EU?

No. What matters is not only the server location, but who has legal access. US providers are subject to the CLOUD Act – including for their European data centres. You achieve true data sovereignty with European providers within the European legal framework, or with models on your own infrastructure.

Do we need a data processing agreement (DPA)?

As soon as personal data is involved – and with user inputs that is practically always the case – yes. A DPA with the AI provider is mandatory, along with technical and organisational measures (TOMs) and a deletion concept. We provide the necessary documentation and processes and coordinate them with your data protection officer.

Can the language models run entirely on our premises (on-premises)?

Yes. Where maximum sovereignty is required – for example with public authorities or particularly sensitive data – we run the AI on your own infrastructure. Your data then does not leave your premises at all. Our dAi Pro platform is designed for this and requires no special infrastructure.

What happens to our users' input?

User input is processed only to answer the respective query and is not used to train models. Every call is logged, so you can demonstrate at any time which data was processed for what purpose. We define storage periods and deletion procedures together in your deletion concept.

How We Proceed

We minimise risks through a step-by-step build with clear milestones – instead of one large, unpredictable project:

  1. Free initial consultation. We clarify your goal and give an honest assessment of whether and where AI delivers real added value for your scenario – without sales pressure.
  2. GDPR check & quote. You receive a concrete assessment of the data protection requirements and a transparent quote.
  3. Pilot with a clear scope. We start with a defined use case in which the benefit becomes measurable.
  4. Expansion & support. Step by step, we expand sources, features and reach – with ongoing maintenance.