Trust and data
Your data stays yours.
How we handle data, security and AI governance on every project. Written for the people who have to sign off.
Your data stays yours
We process it to do the work you asked for and nothing else. Models trained on your data belong to you.
Minimum data
We ask for the fields a project needs, not a copy of everything. Personal data is pseudonymised wherever the model does not need it.
EU by default
Processing and hosting in EU regions unless you choose otherwise. On-premise when data cannot leave the building.
Explainable systems
Every prediction and alert carries the factors behind it. Investigators, planners and auditors get reasons, not just scores.
Data handling.
What happens to your data on a project, step by step.
- What we collect
- The datasets agreed in the blueprint, transferred through a channel you control: a cloud bucket, a database user with read access, or an export you send.
- Where it lives
- In your infrastructure whenever possible. When we host, in EU regions of a major cloud provider, in a project dedicated to you.
- How long we keep it
- For the duration of the engagement. Working copies are deleted within 30 days of handover unless you ask us to keep them for support.
- Who can access it
- The named people on your project, with individual accounts and least-privilege access. No shared credentials.
- How it leaves
- Only to subprocessors listed below, only for the purpose named, and never to train a third-party model.
Security practices.
The controls we apply on every project, whether we host or you do.
Access control
Individual accounts, hardware keys and multi-factor authentication for every system that touches client data.
Encryption
In transit everywhere; at rest on every disk and bucket. Keys managed by the cloud provider or by you.
Secrets
Credentials live in a secrets manager, never in code, notebooks or chat. Rotated at handover.
Code review and CI
Every change reviewed by a second person and run through automated checks before it reaches an environment with data.
Backups
Automated backups for systems we run, tested restores, and retention agreed with you.
Incident response
A named contact, notification within 72 hours of a confirmed incident, and a written post-mortem.
AI governance.
How we keep models honest, safe and useful after launch.
Evaluation before release
Every model and assistant is scored against a test set built with you before it ships, and again on every change.
Guardrails
Permission-aware retrieval, input and output filters, and limits on what an assistant or agent can do without a human.
Human fallback
Low-confidence cases go to a person. The path is designed in, not bolted on.
Monitoring and drift
Inputs, outputs, cost and latency watched in production. Alerts when the world changes.
Model choice and residency
Commercial or open-weight models chosen per case. Where data cannot leave the EU, models run in EU regions or on your hardware.
No training on your data
Provider agreements are set so that your prompts and documents are not used to train third-party models.
Compliance and subprocessors.
We work under the GDPR and sign a data processing agreement with every client before data moves.
| Subprocessor | Purpose | Region |
|---|---|---|
| Cloud provider of your choice | Hosting and compute for project systems | EU regions by default |
| OpenAI, Anthropic or an open-weight host | Language models, when the blueprint calls for them | EU endpoints where offered, or EU-hosted open-weight models |
| Cloudflare | Hosting and form handling for this website | EU and global edge |
| Resend | Delivery of website form submissions by email | EU |
| Google Analytics | Website analytics, only after consent | US, under the EU-US Data Privacy Framework |
Certifications
We do not hold a formal certification such as ISO 27001 today and we will not claim one we do not have. We complete client security questionnaires, provide evidence for the controls above, and adopt client-specific requirements in the data processing agreement.
Your rights and ours
You can audit the controls on your project, request deletion of working copies at any time, and receive a written record of subprocessors involved. We in turn ask for a named data owner on your side and a channel for security questions. Contact: contact@dataminds.gr.
Send us your security questionnaire.
We answer procurement and security questionnaires within five business days, with evidence attached.