DevBit

GDPR-compliant AI — on-premise if you need it.

Everyone claims GDPR compliance. We show you the architecture behind it: on-premise options, EU hosting with a DPA, PII masking — built by engineers from projects where mistakes are not an option.

The privacy architecture

Three privacy levels — honest by architecture.

GDPR compliance is not a promise — it is an architectural decision. Before any project starts, we agree on the level your data requires, and we build exactly that.

  1. 01

    Fully on-premise — your data never leaves your premises (local language models on your infrastructure).

  2. 02

    EU hosting with a data processing agreement (DPA) and zero data retention — your inputs are not stored by the model provider.

  3. 03

    PII masking before anything reaches a cloud model — names and identifiers never arrive there.

  • Model-agnostic architecture: the language model stays swappable at any time — no vendor lock-in.
  • No training on your data — contractually agreed.
  • Transparent token and operating costs, systems running in your accounts.

Built to be audited

Proof, not promises

Anyone can write "GDPR-compliant" on a website. Here is what you can actually verify before you sign anything:

  • EU/Austrian jurisdiction: an Austrian contract partner under GDPR law, a data processing agreement (DPA) as the standard process, and full transparency on subprocessors.
  • High-security track record: projects in critical infrastructure, with highly sensitive security data, and in payment systems — environments where mistakes are not an option.
  • Engineering artifacts: a security review as a named deliverable, audit logs, role and permission concepts — ready to connect to ISO 27001 and NIS2 requirements.
  • Discretion as a principle: our clients never learn from us who our other clients are.

For regulated industries

Where professional secrecy and regulatory oversight apply, full automation is the wrong goal. We build assistive AI: the system prepares, a human approves.

In practice that means: every automated step is logged and traceable, approval workflows make sure no decision leaves the building without human review, and the boundaries of responsibility between system and people are defined before the project starts.

If you serve EU customers from outside the EU, this is also a commercial advantage: a European contract partner and a GDPR-ready architecture make it much easier for your clients' legal teams to say yes.

Prefer to talk confidentially first? On request we start under NDA — before you share a single detail of your case.

Work from high-security environments

We don't name clients — in this field, that is part of the point. Two anonymized industry examples:

Critical infrastructure

Software for highly sensitive security data

Highly sensitive data with strict requirements for access, logging and availability — in an environment where mistakes are not an option.

Healthcare

Health apps for a wide range of use cases

A wide range of use cases in the health space — all involving sensitive data and data-protection requirements that allow no compromise.

Frequently asked questions

Is GDPR-compliant AI actually possible?

Yes — but not as a blanket statement. Whether an AI system is GDPR-compliant depends on the architecture and the implementation: where the models run, which data reaches them, who has access and what is logged. That is exactly what we build — fully on-premise, EU-hosted with a DPA, or with PII masking before any cloud call. We also deliver the documentation your data protection officer or your clients' legal teams need to verify it. Anyone promising blanket compliance without knowing your implementation is overselling.

What is on-premise AI and when do we need it?

On-premise means the AI models run on your own infrastructure — your servers or your private cloud — so your data never leaves your premises and no external model provider sits in the data flow. It makes sense for professional secrecy, highly sensitive data or strict internal policies. We are equally honest about the trade-off: on-premise means your own hardware and ongoing operations. For many use cases, EU hosting with a DPA or PII masking is the better fit — the AI readiness audit determines which level you actually need.

Which data ever reaches a cloud model?

That depends on the privacy level we agree on — and it is documented in every project. Fully on-premise: none. With EU hosting, the models run with European providers under a DPA and zero data retention — nothing is stored there. And where a cloud model is used, personal data is masked or pseudonymized first: names, addresses and identifiers never reach the model at all. We document the data flows so you can verify them.

Do you train models on our data?

No — and we put it in the contract. Your data is not used for training, neither by us nor by the model providers we deploy; we select and configure providers so that no training use takes place and nothing is stored (zero data retention). Because the architecture is model-agnostic, the language model also stays swappable at any time — you are never tied to one vendor.

Can you work under NDA and with regulated industries?

Yes. On request we start under NDA before you share any details of your case. For regulated industries we build assistive AI with human approval instead of full automation, with complete audit trails and clearly defined boundaries of responsibility. Our background includes projects with highly sensitive security and payment data — and discretion is standard practice: we never name clients.

What about the EU AI Act?

The obligations depend on the risk class of your use case. Many back-office applications — document processing, internal assistants — fall into lower risk classes with manageable duties such as transparency, logging and human oversight. We classify your use case as part of the AI readiness audit and build the technical requirements into the architecture from day one. We don't replace legal advice — we deliver the engineering side your counsel can work with.

Start a project

Tell us briefly what you need — your message lands directly with the people who build your project.

Discretion is part of the offer: happy to sign an NDA before you share a single detail of your case.

WhatsApp — the fastest way

A quick question, a small project, or just want to start simple? Message us directly.

Chat on WhatsApp

Email

office@devbit.at

Replies on business days within 24 h.