GDPR-compliant AI

GDPR-compliant AI is not a badge. It is a setup you control.

No AI tool is GDPR-compliant on its own. Compliance is always the combination of vendor, contract, data location, model connection and your own operations. This page shows which questions a data protection officer asks, how the three deployment paths differ and how Pharen Hub handles each of them.

Published Reviewed
Server infrastructure under a company's own control as a visual for GDPR-compliant AI

Direct answer

What does GDPR-compliant AI mean for a business?

GDPR-compliant AI is not a product feature a vendor can simply promise. The GDPR regulates how personal data is processed and puts the obligation on you as the controller, not on the software maker. An AI tool can make that processing easier or harder; it only becomes compliant through the complete setup: who operates the software, where the data lives, which models see which content, whether a processing agreement exists, how data is deleted, who may do what and what is logged. A marketing claim like "GDPR-compliant AI" usually means only this: the vendor has arranged its own side of the processing so that you have a realistic chance of meeting the requirements. The rest, meaning legal basis, purpose limitation, data subject rights and internal processes, remains yours to cover. For a mid-sized company in Saxony that wants to analyse job applications, customer emails or supplier contracts with AI, this means: first decide which data may enter a model at all, then choose vendor and deployment path, then document the process. Pharen Hub is built so that these decisions stay with you: managed cloud on Hetzner in the EU, self-hosting via Docker or deployment in your own cloud. Workspace data is not used to train models. Whether your setup ultimately meets every requirement still depends on configuration, contracts, model providers and processes.

Context

The six questions your data protection officer will ask

The term is only the entry point. What matters is whether it becomes an operating model that connects people, data, workflows and AI agents in daily work.

01

Processing agreement: who processes on whose behalf?

As soon as a vendor processes personal data for you, you need a data processing agreement under Art. 28 GDPR, including every sub-processor. Ask specifically: which subcontractors are involved, in which country are they based and what changes when a model provider is added? With self-hosting, your IT runs the workspace itself; external models still remain separate processors that need their own review.

02

Data location: where does the data actually live?

An EU data centre sounds reassuring but says nothing about support access, backups or the location of the model provider. Clarify where workspace data, backups and logs are stored and whether prompts or documents leave the data centre once a model answers. Pharen runs its managed cloud on Hetzner Cloud in the EU; with self-hosting, you choose the location yourself.

03

Training: does the model learn from our data?

Many consumer AI services use inputs to improve their models by default. For companies that is a deal-breaker as soon as customer data, HR files or contract content is involved. Demand a written commitment that your content does not flow into training, and check whether it also covers connected third-party providers. With Pharen Hub, workspace data is not used to train Pharen or generally available models; third-party providers remain subject to their own terms.

04

Deletion concept: how is data removed again?

Art. 17 GDPR requires that you can delete data once its purpose ends or a data subject requests it. With AI tools the question doubles: are documents, chat histories and search indexes deleted, and how long do copies remain in backups or at the model provider? In a self-hosted Pharen Hub setup you control storage location, access and deletion timing. Retention and backups follow your own rules.

05

Roles and approvals: who may see and trigger what?

AI makes information easier to find. That is an advantage until an assistant suddenly summarises salary tables it should never have seen. Roles and permissions have to apply equally to people and agents. In Pharen Hub, roles control which content and tools are reachable, and critical actions can be tied to approval steps handled by people.

06

Logging: can we reconstruct later what happened?

Accountability under Art. 5(2) GDPR means you must be able to show which data was processed and how. With agents that is decisive, because they execute steps without a direct human input. Ask whether an agent run remains visible with its sources, result and approval. In Pharen Hub, tasks, decisions and workflows stay traceable in the workspace context; with self-hosting, logs can follow your own requirements.

GDPR-compliant AI

Checklist: what to settle before the first AI rollout

These situations are good starting points because they already create operational friction today.

  1. Record of processing activities extended to cover the AI use case, with a legal basis named per data category
  2. Data processing agreement reviewed, including sub-processors and model providers
  3. Storage location for workspace data, backups and logs documented in writing
  4. Written commitment obtained that your content does not enter training, for the software and for connected models
  5. Deletion periods and deletion paths defined for documents, chats and search indexes
  6. Role model agreed: which data may people and agents see, which actions require approval?
  7. Data protection impact assessment checked as soon as applicant, health or customer data is affected at scale
  8. Employees informed and works council involved where AI could touch performance or behaviour data

Approach

Self-hosting, managed cloud or US SaaS: three deployment paths compared

A limited, verifiable starting point creates more clarity than a broad AI initiative without process ownership.

  1. 01 · US SaaS with standard terms

    Fast to start, but data leaves the EU or becomes reachable through group structures. You need standard contractual clauses or a Data Privacy Framework certification, a transfer impact assessment and usually an opt-out from training. Often defensible for marketing copy, frequently not for HR or customer data.

  2. 02 · Managed cloud in the EU

    A European vendor runs the software in an EU data centre and handles updates, backups and maintenance. You need a processing agreement and clarity about connected models. In this variant Pharen Hub runs multi-tenant or single-tenant on Hetzner Cloud in the EU. A good entry point for teams without their own operations capacity.

  3. 03 · Self-hosting or your own cloud

    Your IT runs Pharen Hub via Docker in your own data centre, in a Kubernetes cluster or in your Azure, AWS, Google Cloud or Hetzner environment. Storage location, access, deletion and logs are entirely yours. That simplifies the assessment because fewer external parties are involved, but it does not replace it: backups, updates and monitoring become part of your operating model.

  4. 04 · Assess models separately

    Regardless of the deployment path, the model connection decides the data flows. Depending on the setup, Pharen Hub can work with selected, customer-owned, self-hosted or OpenAI-compatible models. A self-hosted workspace with a US model behind it is a different privacy case than the same workspace with a model inside your infrastructure.

Product evidence

How Pharen Hub handles these questions

Deployment models and status disclosed

The security page shows managed cloud, bring your own cloud and on-premise, plus the honest status: ISO/IEC 27001 in progress, external GDPR review planned for Q1 2027.

View security & self-hosting

Self-hosting in detail

When self-hosting really simplifies the assessment, what your IT takes on and when managed cloud is the better start.

Read the self-hosted guide

Agents with boundaries

Roles, approved sources and human approval points are the foundation for AI agents that only see and do what they are allowed to.

Enterprise AI agents

Platform evaluation

The enterprise AI platform page walks through shared context, agent boundaries, workflows and deployment options for a first pilot.

Evaluate the platform

Compare cost and tool stack

Calculate what a consolidated workspace costs compared with Slack, Notion, Asana and separate AI chats.

Open the comparison tool

FAQ

Common questions about GDPR and AI

Direct answers for platform selection, a first pilot and ongoing operations.

Is Pharen Hub GDPR-compliant?

That depends on the complete setup. Pharen aligns processes and deployments with GDPR; an external review is planned for Q1 2027. Self-hosting gives you more control over storage, access and deletion. Your configuration, connected models, contracts and internal processes determine whether the requirements are met.

Is an EU data centre enough for GDPR-compliant AI?

No. Location is a necessary condition, not a sufficient one. Model providers, support access, sub-processors, the deletion concept and your own legal basis all matter. An EU server with a US model behind it changes little about the data transfer.

Do we need a data protection impact assessment for AI?

Probably, as soon as you systematically analyse personal data such as applications, customer communication or employee records. The DPIA documents risks and safeguards. It is not an obstacle but the place where the six questions on this page get answered.

Can we start in managed cloud and self-host later?

Yes. Many teams start in managed cloud on Hetzner in the EU and move to self-hosting once customer, privacy or IT requirements become concrete. The product direction stays the same; plan the move with us early.

Next step

Find the right starting point together.

GDPR-compliant AI is a setup, not a badge: the six questions your data protection officer asks, self-hosting vs. managed cloud vs. US SaaS, and a checklist.