Zweite Schicht DE, Deutsche Fassung Book a call

Commitment

Updated

Data sovereignty means you decide. We show you what you are deciding on.

"GDPR compliant" is on every website. It says nothing about which of your data goes where when artificial intelligence (AI) is used for a given task. That is why it is set out here: per service, per operating mode, with the sentence that is in every contract.

Contract clause

In every contract with us, word for word

No customer data leaves your systems without your written decision, and none of your data ever trains a third-party model.

Sketch of an open safe with three compartments labelled IM HAUS, EUROPA and UNTER VERTRAG (on your own servers, Europe, under contract), with a key hanging in each.

Operating mode

Three operating modes

You choose one per workflow. The analysis makes a recommendation, with reasons.

  • On your own servers

    for personal data, contracts, health data, anything confidential

    Open models such as Llama or Mistral run on your hardware or on a dedicated server in Germany that only you and our team can access. No data leaves the network. Costs: set-up and computing power, no fees per request. A rented server with a graphics card costs roughly €200 to €1,500 a month depending on model size (rough guide, as of 2026). The set-up is part of the build. The limit: these models are good for language at volume, but weaker than the large cloud models on difficult individual cases.

  • EU data centre

    for customer data, enquiries, CRM content

    Large models from providers with processing in the EU: Google Vertex AI in Frankfurt or Belgium, Microsoft Azure in Germany, Mistral in France. A data processing agreement, no use of your data for training, storage only for processing. The compromise for most workflows involving personal data.

  • Cloud under contract

    for product texts, translations, datasets without personal data

    Models from Anthropic, OpenAI or Google directly via the interface, with a data processing agreement and the contractual commitment that inputs are not used for training. The strongest results for language. Suitable where no personal data is involved, or where you decide in writing after weighing it up.

Data flow

Data flow per service

What goes where, and what never leaves the building. The table is the starting point; the analysis turns it into your plan.

Data flow and recommended operating mode per service
ServiceWhich dataRecommended operating modeNever leaves the building
Texts and content at scaleProduct texts, data sheets, glossary, existing website textsCloud under contract; EU data centre if texts contain customer dataPrices, terms, customer names in texts (replaced before processing)
Putting data in orderCRM contacts, product master data, manufacturer listsRules and matching without a language model, inside the system; where a model helps, on your own servers or in an EU data centrePersonal data in full, unless you decide otherwise
Sales and communicationIncoming enquiries, email texts, knowledge documents, CRM recordsEU data centre or cloud under contract, as you decide; knowledge base on your serverThe knowledge base itself, conversation histories, customer data in the CRM
Tools that fit youPersonnel data, receipts, contracts, cases, depending on what the tool managesThe tool runs on your server, in a German data centre or in your cloud; AI components on your own servers or in an EU data centreThe tool's data in full. No vendor who sees it, no add-on module that sends it to a third-party cloud
System integrationRecords transferred between systemsNo language model needed; transfer directly between your systemsEverything. We see logs, not content, unless agreed otherwise
Ongoing operationRun logs, error messages, countersMonitoring on our systems in GermanyThe content of the processed data; logs contain identifiers, not texts

Documents

What your data protection officer gets from us

  • A data processing agreement with us under Article 28 GDPR, before the first access to any data.
  • A list of the sub-processors used per workflow: which model provider, which data centre, which legal basis for any transfer to a third country.
  • A data flow sketch per workflow as part of the analysis, as the basis for your record of processing activities.
  • A deletion policy: what we hold for processing, for how long, and proof of deletion after the project ends.
  • Access only via named accounts with two-factor authentication, logged, and revocable by you at any time.
  • No access credentials sent by email. Access via your system or a shared password vault.

Works council

Employees and the works council

We build workflows, not surveillance. What a workflow logs is fixed before it runs.

The work nobody likes doing

The second shift takes over the copying, checking and transferring. The decisions stay with people, and they get more time for them. Employee data is not used to steer people: no workflow evaluates who works how fast or how accurately.

We log cases, not people

The log records the case ID, the time, the rule applied and the result of the check. Who approved a case is recorded only where it is needed for traceability, for that purpose only and with a fixed deletion period. Our proposal for the works agreement: twelve months, shorter on request. The workflow does not generate processing times or correction rates per employee in the first place. What is not recorded cannot be evaluated by anyone.

Documents for the works agreement

Almost every AI workflow is subject to co-determination under Section 87(1) no. 6 of the German Works Constitution Act (BetrVG). That is why every workflow comes with the documents a works council needs for its review. These include the description of the workflow, the data flow sketch, the list of what is logged, the roles and permissions model, and a statement of which model runs where. It is the same documentation your IT team receives at handover, and it fits into a works agreement as an annex.

Introduced together with the people affected

Every analysis starts with conversations with the people who do the work today. In the trial run they check the outputs, and their corrections become rules. Anyone who helped write the rules knows what the workflow does and what it does not.

The article Introducing AI with the works council explains how co-determination, a framework agreement and a positive list for the log fit together. The checklist for introducing AI on a sound legal footing shows what else should be settled before you start. As of October 2026, not legal advice.

AI Act

The EU AI Act in five points

The AI Act does not ask about the technology but about how it is used. For most workflows in mid-sized companies, it results in few obligations.

  1. The EU AI Act, Regulation (EU) 2024/1689, classifies AI systems into risk categories according to their use. There are prohibited practices, high-risk systems, systems with transparency obligations, and all others with minimal risk.
  2. Our workflows mostly work with factual data: texts, product data and enquiries. That puts them in the minimal-risk category. The main requirement there is the AI literacy of the people involved, under Article 4.
  3. Since 2 August 2026, the transparency obligations under Article 50 have applied, for example the notice in a chat window that a visitor is talking to an AI.
  4. The Digital Omnibus, Regulation (EU) 2026/1744, has postponed the obligations for high-risk systems, for example for selecting job applicants. They apply from 2 December 2027, and from 2 August 2028 for AI in products that are already regulated.
  5. Where obligations for documentation and human oversight arise, the workflow meets them with what it has anyway: rules, a log for every case and approval by a person on your side.

Capturing job applications in structured form and presenting them to the business department is not selection; we do not build filtering or scoring.

As of October 2026, not legal advice. A table in the article The EU AI Act for mid-sized companies shows which typical workflow falls into which risk category.

Limits

What we do not promise

We do not promise "local AI" for everything. The strongest language models run in the cloud today, and for some tasks their results are clearly better. We tell you where that is the case, and you decide whether the difference justifies the operating mode.

Nor do we promise that language models are free of errors. That is why every workflow has rules, checks and a log, and approval of texts, data and customer contact stays with you. The details are in our terms and conditions.

Handover

The first step is a 30-minute call.

You tell us about the workflow that costs you the most time. We tell you honestly whether AI pays off there and what the next step would be. Whether a workflow analysis follows is up to you.

Book a callApproach and prices