SKAI.BG
Security · GDPR · EU AI Act

Trust is part
of the product.

GDPR and EU AI Act requirements are built into how we design, build and run every integration — with documents you can check, not badges you have to trust.

Request security pack
Straight talk

We don't sell "100% GDPR-compliant AI". No vendor honestly can — compliance depends on your whole implementation. What we do is below, step by step.

01 / Principles

Four rules
we don't bend.

01

Minimum data

The AI only sees the fields the task needs. Personal data is redacted or tokenised where practical.

02

Least privilege

Per-client isolation, role-based access and SSO where appropriate. Every action is logged.

03

Humans decide

Consequential actions pass deterministic checks and, where the risk calls for it, human approval.

04

You can leave

Vendor-neutral architecture, exportable data and a documented exit plan in every contract.

Our core engineering rule

AI output is never trusted as fact. Refunds, account changes and commitments are validated before they happen.

02 / GDPR by design

The privacy pack
every project gets.

Lightweight, but auditable. It's delivered with the solution, so your DPO or counsel can review real documents.

01Data mapWhat enters the system, from where, where it travels, who receives it.
02RolesController and processor roles for you, us and each vendor.
03Purpose & legal basisWhy each processing activity happens and on what basis.
04MinimisationUnneeded fields removed; redaction where practical.
05Provider reviewDPA, subprocessors, retention, training policy and processing locations.
06TransfersAdequacy, SCCs or another safeguard where data leaves the EU.
07Access controlIsolation, least privilege, SSO and RBAC where appropriate.
08RetentionDefined periods for prompts, outputs, logs, vectors and documents.
09SecurityEncryption, secrets management, logging and an incident process.
10EvaluationAccuracy and safety tests matched to the use case.
11DPIA screeningWhether the processing needs a full impact assessment.
12Exit planHow your data is exported, returned or deleted.
03 / EU AI Act

Article 50
is already live.

Since 2 August 2026, people must be told when they are interacting with an AI system such as a chatbot or agent, and AI-generated content must be marked. Fines for breaches can reach €15 million or 3% of worldwide turnover.

  • Disclosure built in — every assistant we ship identifies itself as AI.
  • Classification per use case — a product assistant isn't high-risk just because it uses an LLM. We assess what the system actually does.
  • Governance checklist — model and vendor register, evaluation evidence and human controls, reviewed as the rules evolve.
Our standard assistant disclosure
You are interacting with an AI assistant operated by skai.bg. AI-generated responses can be incomplete or incorrect. Do not enter sensitive personal information unless it is necessary and you have been asked to provide it. You can request human assistance at any time.
Shown in Bulgarian and English. Adapted per client with legal review.
04 / Where your data goes

Every layer
has a guard.

The reference architecture behind every skai integration. Swapping the model is easy; your controls stay in place.

  1. InterfaceWebsite, e-store or internal tool — with consent and privacy controls.
  2. GatewayIdentity, role-based access and rate limits.
  3. OrchestrationGuardrails, PII controls and human approval — the layer we own and operate.
  4. Model routerEU-hosted model APIs, alternative providers or private, self-hosted models.
  5. KnowledgeYour documents and data in PostgreSQL and a vector index, with search and reranking.
  6. Business toolsStore, CRM, ERP, helpdesk and workflow APIs — each action validated.
  7. Evaluation & monitoringTests before release; logs, traces, cost and quality in production.
05 / Subprocessors

Who touches
your data.

For each production service we keep a current list of AI, cloud and infrastructure providers, with purpose, location and retention.

We share the current list for your project together with the DPA — before any of your data is processed — and update it under that agreement.

For DPOs, IT and procurement

Request the
security pack.

  • — Architecture & data-flow overview
  • — DPA template & subprocessor list
  • — Security questionnaire answers
  • — AI governance checklist
Request security pack