Your data, your rules
How daita protects your data, who processes it, and the controls that keep you compliant. Written plainly — ask us for the full DPA.
Sovereign by design
The EU AI Act applies in full from 2 August 2026, with fines up to €35M or 7% of global turnover. We turn that obligation into your advantage: agents engineered to run inside European or on-premises infrastructure, where your data stays yours and never trains third-party models.
EU / on-prem deployment
Run on European cloud or inside your own infrastructure — data residency by design.
Your data stays yours
Personal data never leaves your environment and never trains third-party models.
Compliant by design
EU AI Act & GDPR controls, transparency and risk assessments built into the architecture.
Fully auditable
Immutable decision logs and traceability for every action an agent takes.
Data residency
Your data at rest is stored in a European database (Google Cloud, eur3 / Europe). Communications are encrypted in transit, and every agent action is written to an immutable audit log. For regulated workloads we offer full EU-region or on-premises deployment of the entire stack on the Sovereign plan.
- Data at rest in the EU by default
- Encrypted in transit (TLS)
- Immutable, exportable audit logs
- Full EU-region / on-prem on the Sovereign plan
Who processes data, and where
We use best-in-class providers under data-processing agreements. Each is listed with its role and data-residency posture — transparently.
Google Cloud (Firestore, eur3)
Primary data store: leads, bookings, transcripts, audit logs
Jina AI (Berlin, Germany)
Neural reranking for retrieval quality
Anthropic (Claude)
Core reasoning & language understanding
ElevenLabs
Neural text-to-speech (default voice)
Twilio
Phone & WhatsApp connectivity
Resend
Transactional email (confirmations, invites)
OpenAI (gpt-realtime)
Native real-time voice — only if you enable it
Engineered to keep data safe
Encryption in transit
All traffic is served over TLS; secrets are held in a managed secret store, never in code.
Verified webhooks
Phone & WhatsApp callbacks are cryptographically signature-verified before anything runs.
Ephemeral voice tokens
Live voice uses short-lived tokens minted server-side — provider keys never reach the browser.
Least-privilege access
The admin console is password-gated; client workspaces are isolated and token-scoped.
Immutable audit trail
Every lead, booking and action is logged with timestamps for full traceability.
Bounded retention
Temporary artifacts auto-expire (voice clips ~1h, call state ~24h, analytics events ~30d).
GDPR & EU AI Act, by design
You remain the controller of your data. We act as your processor under a DPA, and we never use your data to train third-party models.
Working toward the certifications that matter
daita is building toward formal certification against the standards that govern trustworthy AI — ISO/IEC 42001, the EU AI Act and GDPR among them. We treat this as a continuous program, not a one-off badge.
AI Management System — the first certifiable AI-governance standard.
Regulation (EU) 2024/1689 — transparency & limited-risk obligations.
EU data protection — DPA, EU residency, data-subject rights.
Information security management — controls aligned; infrastructure certified (Google Cloud).
Trust services criteria — infrastructure attested (Google Cloud); program in progress.
AI Risk Management Framework + GenAI Profile — our operational playbook.
LLM application security — prompt-injection, excessive agency and more.
Honest status — we show what we’re working toward, not what we haven’t earned.
Compliance proven from our real source code
Unlike a questionnaire, we run an AI-native quality & trust management system that continuously evidences every control against our actual production system — and seals each approval cryptographically.
Status reflects our active program; certification of an AI management system is granted only by an accredited body. Ask us for documentation.
Need our DPA or a security review?
We are happy to share documentation and answer your security and compliance team’s questions.
This page summarises our practices in plain language and is not a contract. Email info@daita-ai.com for the full Data Processing Agreement and sub-processor list.