ServicesAI agentsAutomationCustom softwareIntegrationsGrowth & marketingAll servicesHow we workSectorsAboutAI Process AuditMap out your process

Secure and European

Your data staysin Europe.Here is where.

Plenty of agencies put a padlock on their site and call it secure. This page lists which suppliers I use, which country their servers are in, what they get to see of your data and how long anything is kept. If your company sits outside the EU and wants customers inside it, this is the part you will be asked to show. Your IT lead can check every line.

Everything on this page can be checked. If the setup changes, this page changes before that change goes in.

Where your data will sitAll inside the EU
Your database
everything the application stores
Frankfurt
Site and application
with a fallback if something goes down
Frankfurt
Amsterdam
Outgoing email
confirmations and alerts
Dublin
No part of this setup sits outside the EUsetup as written on 21 September 2026
Frankfurtthis is where your database will sit, in Germany
Amsterdamthe application keeps running from here if Frankfurt drops out
Dublinthis is where your email goes out from

This is the setup I put in place for a project, with the regions fixed in the settings. These are not numbers about systems already running at clients, because there are none yet.

Open books

This stays with you. This is what leaves.

With AI the question that matters comes down to one thing: which text leaves your company, and where does it end up. Here it is per type of data, with nothing dressed up.

Stays inside

This stays where it is

  • Your database and your files. They sit in Frankfurt and are never copied over to an AI service.
  • Your passwords and keys. They live in a sealed vault. They are not in code and not in a chat window.
  • Your admin as a whole. An agent that handles invoices gets to see invoices. The rest of your system stays shut.
  • What your staff type into a screen I build stays inside your own environment.
Goes out

This is exactly what leaves

  • The piece of text the model has to read. For an invoice that is that invoice. For an email that one email. Your customer list does not travel with it.
  • Which provider it goes to is agreed in advance and named in your data processing agreement.
  • Business accounts only. Those state that your text is not used to train their model. If a provider will not put that in writing, I do not use them.
  • If you want nothing to leave at all, the model runs on your own server. That works. It is slower and it costs more.

Why this split matters. The worry about AI is almost never the database. That sits in Germany, same as your accounting package. The worry is that one moment when text goes to a model. So for every process I write down which text that is, how long it sits there and who can ask for it.

The full list

Everyone who sees any of your data, in one list.

This is the complete list for a standard project. If something gets added for you, you hear about it before I switch it on and it goes into your data processing agreement. The region codes are there so your IT lead can look them up.

WhoWhat forWhere the servers areWhat they get to see
Vercel
US company, EU servers
Runs the site and the application.
Frankfurt, with Amsterdam as fallbackfra1 ams1
Traffic to and from the site, and whatever you type into a form at the moment you hit send.
Supabase
US company, EU servers
The database and file storage.
Frankfurt, Germanyeu-central-1
Everything the application stores. This is where your data actually lives.
Resend
US company, EU servers
Sends the email the system sends out.
Irelandeu-west-1
The recipient address and the contents of that one email. Nothing beyond that.
Plausible
EU company
Counts how many people visit the site.
European Unionno cookies
Counts per page. No cookies, no profiles, no way to recognise a visitor.
The AI model
chosen per project
Reads and judges the text the process hands it.
Agreed togethersee the section below
Only the piece of text that one step needs, plus the answer that comes back.

What to notice here. Three of these are US companies with servers in Europe. For most companies that is fine and their European contracts cover it properly. If you want no US parent company in the chain either, the EU-only option is further down this page. I am not going to pretend that question does not exist.

Which model

Which AI model gets used is your call.

There is no single answer that fits everyone. It depends on how sensitive your data is and what you want to spend. Here are the three routes, with the downsides stated up front.

A European model

A provider from France or Germany, for example, processing inside the EU. Your text never leaves Europe from start to finish. For reading, summarising and sorting this is more than good enough. For the heaviest reasoning work it still trails the top of the market.

A large model on a business contract

The best known models come from the United States. I only use them through a business account that states your text is not retained for training, with processing inside Europe where that is offered. If you say no to this route, I do not use it.

A model on your own server

In your own server room, or with a host you pick. Nothing leaves your building. You pay for the machine and the upkeep, and a model like that is slower than the best online ones. For sensitive files that is usually worth it.

Whatever we pick, it goes on paper. The name of the provider, the country of processing and the terms are in your contract. If I want to change something later, because a better model turns up for instance, I ask you first. You do not hear about it afterwards.

GDPR

The GDPR, translated into what I actually do.

The law is abstract and most privacy statements are too. This is what it looks like inside a project, in steps you can check.

The processing agreement comes first

You sign it before a single record is touched. The parties in the list above are named in it. If you would rather use your own template, I sign that, as long as it contains nothing I cannot deliver on.

As little data as possible

I only pull what the process needs. An agent for your purchase invoices has no business reaching your HR files. Every connection gets the narrowest access that still does the job.

Retention you decide on

By default processed documents stay for 90 days so you can check what happened. After that they go. If it should be 7 days, or 7 years because of a statutory retention period, that is how I set it.

Who can get in is fixed

Me, with two-factor authentication, and the systems that do the work. There is no team of onlookers behind me. Every time a person or a process reaches production, it is in the log.

Access and erasure requests

If what I build holds personal data, the button to find it and wipe it is built in from the start. When one of your customers asks, you handle it yourself without calling me.

If your company sits outside the EU

The GDPR asks non-EU companies with customers here to appoint a representative in the EU under Article 27. That is a legal appointment, so I point you to a party that takes that role on. What I do handle is the technical half: EU regions, a processing agreement with named sub-processors, and records you can hand to a supervisory authority.

If it does go wrong

With a data breach you hear from me within 24 hours, with what happened and which data it touches. You file it with your supervisory authority within 72 hours, and I supply everything you need for that.

The EU AI Act

The AI Act lands in stages. These are the dates that count.

The law has been in force since August 2024 and arrives in pieces. For most small and mid-sized companies it is lighter than the headlines suggest. What I build almost always sits in the light category, with a few things you simply have to arrange.

2 February 2025

Banned uses, and knowing what you are doing

A handful of uses are no longer allowed, such as scoring people on social behaviour. On top of that, staff who work with AI have to understand enough about it. At most companies that last part is a half-hour explanation.

2 August 2025

Rules for the model makers

The companies behind the large models have to document how their model is built and what it was trained on. That is useful for you: the information becomes available on request and it helps fill your own file.

2 August 2026

The bulk of it applies

High-risk systems, in recruitment or credit scoring for example, get heavy requirements. Anyone talking to an AI also has to be able to tell that it is an AI. If you work in one of those corners, we start there.

2 August 2027

The last category

AI sitting inside a product that already goes through other certification, such as machinery or medical devices, follows last. If you build products like that, this belongs in your design work from now on.

What I do as standard, whichever category you fall into. For every system I write down what it does, what goes into it and who is accountable, so you have a file before anyone asks for one. Where a decision touches money or people, a human signs off. Every action lands in a log, so afterwards you can see why something happened. And if one of your customers talks to an agent, it says that it is an agent.

How strict do you want it

Three ways to set this up.

Stricter is almost always more expensive or slower. So you choose, and I tell you what it costs. All three work, including if you want to move over later.

European cloud, the standard

Everything runs with the parties in the list, on servers in Frankfurt, Amsterdam and Dublin. Quick to set up and reasonably priced. For most companies this is the right call, and you can always move off it.

EU-only, down to the companies themselves

Then I look for a European company for every part, so no US parent anywhere in the chain. It takes more setup work and a few handy services drop out. In government and healthcare this tends to clear review more easily.

On your own server

In your own server room or with a host you choose. Nothing goes out, the model included. You pay for the machine and the upkeep, and you give up some speed. For genuinely sensitive files this is the way.

Torn between the three? In the AI Process Audit I work out the difference in euros per month, and write down which risk the more expensive option actually buys off. Then you decide for yourself whether that is worth it.

If we stop

What happens to your data if we part ways.

This is where working relationships get stuck. So it is fixed up front, not at the moment you want to leave. You do not have to ask me for permission for any of it.

The accounts are in your name already

You pay for the hosting and the database yourself, on accounts that belong to you. I work inside them as an administrator for as long as we work together. If it ends, you remove my access and everything keeps running.

You get everything handed over

Within ten working days I deliver an export of your database in a plainly readable format, plus the source code and the notes on how it runs. Enough to carry on yourself, or to hand to someone else.

I wipe what is left on my side

Within 30 days of the end everything on my side is gone. The automatic backups roll off after that, 90 days at the outside. You get written confirmation with the date on it.

In between as well. You can ask at any moment what I hold of yours and where it sits. You get that list within five working days. The right is in the processing agreement, so it does not depend on my calendar.

Fair is fair

What I do not have.

A page about security that only carries good news is not an honest page. These are the things you get at a large agency and do not get from me yet.

  • No ISO 27001 and no SOC 2.Those certificates cost a one-person company a lot of money and a lot of time. If a client genuinely needs one, we start that process and I say up front how long it takes and what it costs. I am not putting a badge on the site I cannot back up.
  • No legal advice.I am not a lawyer. I know how to set this up technically and what the law asks of your system. For a watertight opinion on your situation I send you to someone allowed to give one, and I would rather say that now.
  • No row of client stories behind this.Diginesso is new, so I do not have those numbers and I am not going to invent them. What you can do instead is check this page. Every supplier above is publicly documented, regions included.
  • No years of running systems behind this setup.Diginesso has just started. The suppliers above are chosen and those are the regions I set for every project, but there is no client system running that I can point you at. What is live on this site itself is in the privacy statement.
  • No promise that it is a hundred percent safe.That does not exist, and anyone saying it is selling you something. What I do is write down where your data sits and who can reach it, so you can judge for yourself whether the risk is acceptable.
The short version

Three things that always hold.

Whatever you have built and however strictly you set it up, these are fixed.

Built inside the EUYour data does not drift off to the United States. On-premise if you want it.
GDPR and the new AI ActBuilt in from the start, not bolted on once somebody asks.
You hold the keysNothing leaves without your sign-off. The accounts are in your name.
For your IT lead and your DPO

The questions they ask.

Feel free to forward this page. The answers below are written for someone who has to assess this for a living.

Who is controller and who is processor?
You are the controller. It is your data and your process, and you decide what it is used for. Diginesso is the processor and does exactly what the agreement says. The parties in the list above are sub-processors and are named in it.
Do I get a data processing agreement, and when?
Before we start, so before a single record is touched. I work from a standard template with the sub-processors listed. If you have your own template you use everywhere, send it over and I will sign it. If it contains something I cannot deliver on in practice, I say so up front rather than signing anyway.
Is our data used to train models?
No. Not by me and not through a supplier. I only use business accounts that state input is not used for training. A provider that will not put that in writing does not get in. If you want something harder than that, your own model on your own server is the route.
What about the US Cloud Act?
Honest answer: three of my suppliers are US companies with European servers. Lawyers disagree on whether a US authority can demand anything from those, and I am not going to pretend the argument is settled. If that risk is too much for your data, pick the EU-only option or your own server. That part of the debate then disappears.
Where are the backups and for how long?
In the same region as the database, so in Frankfurt. They rotate automatically. By default they are kept for 30 days, and the oldest is gone after 90 days at the latest. If you have a longer statutory retention period, that gets set up separately and we record where those copies sit.
What if something does have to be processed outside the EU?
Then I ask you first and explain why it is needed. If you say no, we find another way or drop that feature. It is written into the agreement too, so it does not hang on my good mood.
Can we run our own pentest or audit?
Yes. Bring in your own firm, I supply the access and the documentation and set up an environment to test against. The reports go straight to you. If something comes out of it, I fix it and you see in the log when that happened.
Who can reach production?
Me, with two-factor authentication, and the system accounts that may only do what they need to. There is no team behind me looking over my shoulder and nothing is subcontracted. Every login is recorded in the log you can ask for.
Who builds it

I cannot pass you on to a security department.

At a large agency you get a certificate and a department that owns it. With me you get this page and my email address. I build it, I run it, and if something goes wrong I am the one you get hold of.

I am strict about your data staying in Europe and about the thing still working six months in. If something here looks wrong to you, mail me at info@diginesso.com. Then I either fix it or explain why it reads the way it does.

Wesley Beerendonk · Diginesso

Want your own IT lead to go over this? Send them this page, it is written for them.

Map out your process.

Digi, my AI colleague, walks you through where it pinches in a few minutes. After that I read it myself and get in touch personally.

  • Free and no strings attached, a few minutes
  • Then a personal message from me, within one working day
  • Questions about the setup above are welcome right away
Rather write directly? info@diginesso.com

Talk to Digi about your process. A few questions, and you know where the gain sits and how it gets set up safely.

Talk to Digi

Free and no strings attached. I use your details only to answer you.