Minimum data
The AI only sees the fields the task needs. Personal data is redacted or tokenised where practical.
GDPR and EU AI Act requirements are built into how we design, build and run every integration — with documents you can check, not badges you have to trust.
We don't sell "100% GDPR-compliant AI". No vendor honestly can — compliance depends on your whole implementation. What we do is below, step by step.
The AI only sees the fields the task needs. Personal data is redacted or tokenised where practical.
Per-client isolation, role-based access and SSO where appropriate. Every action is logged.
Consequential actions pass deterministic checks and, where the risk calls for it, human approval.
Vendor-neutral architecture, exportable data and a documented exit plan in every contract.
AI output is never trusted as fact. Refunds, account changes and commitments are validated before they happen.
Lightweight, but auditable. It's delivered with the solution, so your DPO or counsel can review real documents.
Since 2 August 2026, people must be told when they are interacting with an AI system such as a chatbot or agent, and AI-generated content must be marked. Fines for breaches can reach €15 million or 3% of worldwide turnover.
The reference architecture behind every skai integration. Swapping the model is easy; your controls stay in place.
For each production service we keep a current list of AI, cloud and infrastructure providers, with purpose, location and retention.
We share the current list for your project together with the DPA — before any of your data is processed — and update it under that agreement.