Compliance

GDPR-compliant AI and EU hosting.

Data protection is the biggest hurdle when introducing AI. We treat it as the starting point of the architecture, with EU hosting, data minimisation and a clear classification under the AI Act.

01

Data protection as an architecture principle

  • EU hosting: processing and storage within the EU
  • Data minimisation: only the data the use case genuinely needs
  • Access control and logging from the start
  • Your data stays in your environment

02

The AI Act, put into practice

For most mid-sized use cases (documents, knowledge search, quotes), the AI Act classes them as “limited risk”. The compliance effort is manageable. We include the conformity check for your specific use case.

03

On-premise: locally operated models

Where data must not leave the building, we run the language model locally in your environment. The choice between a hosted model API in the EU and local operation depends on data sensitivity and requirements. We tell you which route fits your use case — and why.

04

NIS-2 and security

Where your company falls under NIS-2, we account for the heightened requirements on security and auditability right in the design.

05

Why appDev

  • Salaried senior engineers build the solution themselves and connect it to your systems.
  • Experience from ePA and health-insurer projects, in tightly controlled, audited environments.
  • Full code hand-over: you stay independent and free to switch at any time.

06

What it costs

  • Discovery (one-off, creditable): €1,900. Result: a sharpened use case, a feasibility assessment and a concrete fixed-price offer.
  • AI pilot (one use case, six to eight weeks): from €39,000. The exact price depends on your data situation and the depth of integration.

Reference

From our projects

Health and telematics large

Electronic patient record for a large statutory health insurer

Native Android app in the German telematics infrastructure

A new interface on an existing white-label base, FHIR data models, sign-in via the sectoral identity provider, consent management, connection of further specialist services such as e-prescription and emergency data. Complete traceability and documentation designed for the Gematik audit.

Passed the Gematik audit and in regular operation.

View project

All references Get in touch

FAQ

Common questions

Is GDPR-compliant AI achievable?

Yes. With EU hosting, data minimisation and clean access control, AI can be built in a GDPR-compliant way. These principles are standard with us and built in from the start.

What does the AI Act require of mid-sized companies?

For typical use cases the classification is usually “limited risk”, with manageable obligations such as transparency. We include the conformity check for your use case.

Do the data have to stay in the EU?

We use EU hosting by default. For especially sensitive data, locally operated models are also possible.

Can we run AI fully on-premise?

Yes. For particularly sensitive data we run models locally or in your private cloud instead of via external APIs. The fixed-price model stays in place; the extra effort goes mainly into infrastructure and model selection. Whether on-premise is necessary is settled in the Discovery.

Get in touch

Discuss your data protection requirements. A reply the same business day.

Tell us briefly about your use case and your data protection requirements. You'll learn whether and how it can be built in a GDPR-compliant way.

Pick an open slot in the calendar directly. Free and without obligation.

Book a call online

Scheduling is provided by Zeeg (zeeg.me, servers in the EU). Loading it opens a connection to Zeeg and cookies may be set. More on this in the privacy policy.