AI + engineering services
Only the personal data the task needs
AI systems tend to collect more personal data than anyone intended: whole email threads in prompts, customer records in vector indexes, transcripts in logs nobody deletes. We look at each workflow, work out which fields the task really needs, and build around that. Typical measures include masking names and identifiers before text reaches a model and keeping separate indexes for each permission group. We also set retention limits on prompts and logs, make sure deletion reaches embeddings and caches, and keep records of which supplier processes what. Your team works with its privacy specialist to document the purpose, lawful basis and whether a DPIA is needed. We give them an accurate description of the processing and implement the controls they ask for.
Start with your workflow. We agree the first deliverable, data boundaries, scope and budget before work begins.
What we can deliver
What your team receives.
- Field-by-field personal data map for each AI workflow
- Masking, minimisation and separate indexes per permission group
- Retention and deletion covering prompts, logs, embeddings and caches
- Supplier and transfer records
- Technical description of the processing for privacy and DPIA review
Illustrative project example
Data protection for AI
A group of clinics wants an assistant that drafts replies to patient emails. Reviewing sample threads shows that most replies need appointment dates and service names and none of the medical history. We strip clinical details before the model sees the message and keep drafts for 14 days. We also make sure that deleting a patient record removes its indexed text. The privacy lead reviews the processing description before launch.
The final design follows your systems, documents and operating requirements.
Keep your team in control.
Data protection
Map approved data sources, access rules, retention and provider use before connecting AI to company information.
EU infrastructure options
Scope EU servers or self-hosting and disclose the processing location of model APIs, logs and backups.
Human approval
Agree where AI may suggest, where it may act and where a person must approve the next step.
Can we start small?
Yes. Start with one workflow, one team and an agreed outcome. We scope the pilot after learning about your data, systems and constraints.
Can our data stay in the EU?
We can scope EU-hosted or self-hosted options. The proposal identifies where each component processes and stores data, which providers are involved, and any transfer or remote-access implications. EU hosting alone does not establish compliance.
Do you help with the AI Act, NIS2 and CRA?
We help prepare inventories, data flows, security controls, documentation and remediation work for specialist review. Applicability depends on your role, sector, jurisdiction and product. We do not offer a blanket compliance certificate.