Trust · Security & data protection

Your data, your rules

How daita protects your data, who processes it, and the controls that keep you compliant. Written plainly — ask us for the full DPA.

Sovereign AI

Sovereign by design

The EU AI Act applies in full from 2 August 2026, with fines up to €35M or 7% of global turnover. We turn that obligation into your advantage: agents engineered to run inside European or on-premises infrastructure, where your data stays yours and never trains third-party models.

EU / on-prem deployment

Run on European cloud or inside your own infrastructure — data residency by design.

Your data stays yours

Personal data never leaves your environment and never trains third-party models.

Compliant by design

EU AI Act & GDPR controls, transparency and risk assessments built into the architecture.

Fully auditable

Immutable decision logs and traceability for every action an agent takes.

EU AI Act — the timeline
Aug 2024In force
Feb 2025Prohibited practices
Aug 2025GPAI obligations
Aug 2026Full application
Data residency

Data residency

Your data at rest is stored in a European database (Google Cloud, eur3 / Europe). Communications are encrypted in transit, and every agent action is written to an immutable audit log. For regulated workloads we offer full EU-region or on-premises deployment of the entire stack on the Sovereign plan.

  • Data at rest in the EU by default
  • Encrypted in transit (TLS)
  • Immutable, exportable audit logs
  • Full EU-region / on-prem on the Sovereign plan
EU eur3data residency
GDPR · EU AI Act · DPA on request
Sub-processors

Who processes data, and where

We use best-in-class providers under data-processing agreements. Each is listed with its role and data-residency posture — transparently.

EU

Google Cloud (Firestore, eur3)

Primary data store: leads, bookings, transcripts, audit logs

EU

Jina AI (Berlin, Germany)

Neural reranking for retrieval quality

US · EU-region / on-prem available

Anthropic (Claude)

Core reasoning & language understanding

US · EU-region / on-prem available

ElevenLabs

Neural text-to-speech (default voice)

US · EU-region / on-prem available

Twilio

Phone & WhatsApp connectivity

US · EU-region / on-prem available

Resend

Transactional email (confirmations, invites)

Opt-in · outside the EU

OpenAI (gpt-realtime)

Native real-time voice — only if you enable it

Security

Engineered to keep data safe

Encryption in transit

All traffic is served over TLS; secrets are held in a managed secret store, never in code.

Verified webhooks

Phone & WhatsApp callbacks are cryptographically signature-verified before anything runs.

Ephemeral voice tokens

Live voice uses short-lived tokens minted server-side — provider keys never reach the browser.

Least-privilege access

The admin console is password-gated; client workspaces are isolated and token-scoped.

Immutable audit trail

Every lead, booking and action is logged with timestamps for full traceability.

Bounded retention

Temporary artifacts auto-expire (voice clips ~1h, call state ~24h, analytics events ~30d).

Your rights & compliance

GDPR & EU AI Act, by design

You remain the controller of your data. We act as your processor under a DPA, and we never use your data to train third-party models.

Access, export and erasure on request
Data-processing agreement (DPA) available
Your data never trains third-party models
EU AI Act-aligned: transparency, logging, human oversight
Non-EU options are strictly opt-in, clearly flagged
Certifications & compliance program

Working toward the certifications that matter

daita is building toward formal certification against the standards that govern trustworthy AI — ISO/IEC 42001, the EU AI Act and GDPR among them. We treat this as a continuous program, not a one-off badge.

ISO/IEC 42001Implementation in progress

AI Management System — the first certifiable AI-governance standard.

EU AI ActAligned

Regulation (EU) 2024/1689 — transparency & limited-risk obligations.

GDPRCompliant

EU data protection — DPA, EU residency, data-subject rights.

ISO/IEC 27001Controls aligned

Information security management — controls aligned; infrastructure certified (Google Cloud).

SOC 2Infrastructure attested

Trust services criteria — infrastructure attested (Google Cloud); program in progress.

NIST AI RMFAdopted

AI Risk Management Framework + GenAI Profile — our operational playbook.

OWASP Top 10 for LLMImplemented

LLM application security — prompt-injection, excessive agency and more.

Honest status — we show what we’re working toward, not what we haven’t earned.

Evidenced, not just claimed

Compliance proven from our real source code

Unlike a questionnaire, we run an AI-native quality & trust management system that continuously evidences every control against our actual production system — and seals each approval cryptographically.

Code-grounded — controls are assessed against our real production source, not a checklist.
Cryptographically sealed — approvals are digitally signed and tamper-evident (ES256 + RFC 3161).
Continuously re-verified — every control is re-checked as the product evolves.
Accountable sign-off — a named owner approves each record; nothing is fabricated.

Status reflects our active program; certification of an AI management system is granted only by an accredited body. Ask us for documentation.

daita · München

Need our DPA or a security review?

We are happy to share documentation and answer your security and compliance team’s questions.

This page summarises our practices in plain language and is not a contract. Email info@daita-ai.com for the full Data Processing Agreement and sub-processor list.