Compliance by design · last updated 2026-05-11
AI transparency policy
If we advise on the EU AI Act, we have to practise what we preach. Here is exactly how we use AI in engagements, what happens to your data, and what choices you have.
§ 01
Models
Which AI models we use
Primarily Claude with EU residency. Other models only for non-sensitive tasks or with an explicit client agreement. Self-hosted mode is offered as a premium option.
- Claude (Anthropic)
- Primary model for client engagements, EU residency where possible
- ChatGPT (OpenAI)
- Non-sensitive tasks or with an explicit client agreement
- Gemini (Google)
- Secondary for research, demo arsenal
- Perplexity, Copilot
- Demo and specialised tasks
- Llama, Mistral (self-hosted)
- Self-hosted mode for particularly sensitive engagements
§ 02
Data rules
Which data we send where
- → Personal data is processed ONLY under a separate Data Processing Agreement (DPA) in accordance with GDPR Art. 28
- → Trade secrets and particularly confidential information are not sent to cloud AI without a separate agreement
- → Anonymised extracts from interviews and documents may be processed by the Claude API with EU residency
- → You can always choose self-hosted mode (premium surcharge)
§ 03
Audit trail
Traceable on every engagement
Every client engagement carries an audit trail PDF. Immutable log in our self-hosted Gitea LXC. Can be presented on an auditor's request or in a GDPR enquiry.
- → Which AI model and version
- → Which prompts (with fingerprint hash)
- → When (ISO timestamp)
- → Who reviewed manually (typically Jesper Sachmann)
§ 04
- → All client-specific interview transcripts are deleted
- → Client-specific documents are deleted from our Drive
- → Vector embeddings belonging to the client are deleted
- → Anonymised aggregated insight may be retained (without identification)
§ 05
Opt-out
Your choices
- Self-hosted mode
- Only local AI models (Llama, Mistral) on our Proxmox. Premium surcharge.
- Manual mode
- No AI tools at all. About 40 percent longer delivery, hence high-touch pricing.
- Restricted model selection
- You specify which models may or may not be used on your data.
- Early deletion
- You request deletion before T+90, executed the same week.
01
02
03
04
Last updated: 2026-05-11 · Policy revised when significant changes occur in AI stack or vendors