Skip to content

Trust and data

Your data stays yours.

How we handle data, security and AI governance on every project. Written for the people who have to sign off.

Your data stays yours

We process it to do the work you asked for and nothing else. Models trained on your data belong to you.

Minimum data

We ask for the fields a project needs, not a copy of everything. Personal data is pseudonymised wherever the model does not need it.

EU by default

Processing and hosting in EU regions unless you choose otherwise. On-premise when data cannot leave the building.

Explainable systems

Every prediction and alert carries the factors behind it. Investigators, planners and auditors get reasons, not just scores.

Data handling.

What happens to your data on a project, step by step.

What we collect
The datasets agreed in the blueprint, transferred through a channel you control: a cloud bucket, a database user with read access, or an export you send.
Where it lives
In your infrastructure whenever possible. When we host, in EU regions of a major cloud provider, in a project dedicated to you.
How long we keep it
For the duration of the engagement. Working copies are deleted within 30 days of handover unless you ask us to keep them for support.
Who can access it
The named people on your project, with individual accounts and least-privilege access. No shared credentials.
How it leaves
Only to subprocessors listed below, only for the purpose named, and never to train a third-party model.

Security practices.

The controls we apply on every project, whether we host or you do.

Access control

Individual accounts, hardware keys and multi-factor authentication for every system that touches client data.

Encryption

In transit everywhere; at rest on every disk and bucket. Keys managed by the cloud provider or by you.

Secrets

Credentials live in a secrets manager, never in code, notebooks or chat. Rotated at handover.

Code review and CI

Every change reviewed by a second person and run through automated checks before it reaches an environment with data.

Backups

Automated backups for systems we run, tested restores, and retention agreed with you.

Incident response

A named contact, notification within 72 hours of a confirmed incident, and a written post-mortem.

AI governance.

How we keep models honest, safe and useful after launch.

Evaluation before release

Every model and assistant is scored against a test set built with you before it ships, and again on every change.

Guardrails

Permission-aware retrieval, input and output filters, and limits on what an assistant or agent can do without a human.

Human fallback

Low-confidence cases go to a person. The path is designed in, not bolted on.

Monitoring and drift

Inputs, outputs, cost and latency watched in production. Alerts when the world changes.

Model choice and residency

Commercial or open-weight models chosen per case. Where data cannot leave the EU, models run in EU regions or on your hardware.

No training on your data

Provider agreements are set so that your prompts and documents are not used to train third-party models.

Compliance and subprocessors.

We work under the GDPR and sign a data processing agreement with every client before data moves.

SubprocessorPurposeRegion
Cloud provider of your choiceHosting and compute for project systemsEU regions by default
OpenAI, Anthropic or an open-weight hostLanguage models, when the blueprint calls for themEU endpoints where offered, or EU-hosted open-weight models
CloudflareHosting and form handling for this websiteEU and global edge
ResendDelivery of website form submissions by emailEU
Google AnalyticsWebsite analytics, only after consentUS, under the EU-US Data Privacy Framework

Certifications

We do not hold a formal certification such as ISO 27001 today and we will not claim one we do not have. We complete client security questionnaires, provide evidence for the controls above, and adopt client-specific requirements in the data processing agreement.

Your rights and ours

You can audit the controls on your project, request deletion of working copies at any time, and receive a written record of subprocessors involved. We in turn ask for a named data owner on your side and a channel for security questions. Contact: contact@dataminds.gr.

Send us your security questionnaire.

We answer procurement and security questionnaires within five business days, with evidence attached.