Privacy

GDPR-compliant AI. Your data stays with you.

Servers in Germany, no training on your data, a data processing agreement included. This page explains what GDPR-compliant AI actually means for SMEs.

Where your system runs
Hetzner in Germany or on your premises
Training on your data
None, confirmed in writing
Contract
Data processing agreement under Art. 28 GDPR included

What does “GDPR-compliant” mean for AI?

At Klarbeleg, GDPR-compliant means: your data stays in Germany and under your control, no provider trains on it, and every processing step has a legal basis and a contract.

  • Your data stays in Germany and under your control
  • No provider trains on your data
  • Every processing step has a legal basis and a contract

Those three points sound simple, but with many AI offers they are exactly the problem: data drifts into someone else's cloud, a language model learns from customer data without oversight, and nobody can say on what legal basis that happens. This page explains how Klarbeleg keeps to all three in practice.

In everyday terms, that means: you can ask any specific question about it and get a specific answer, not just a pointer to some outside provider's general terms and conditions. The sections below walk through the GDPR articles that actually matter for an AI system in a business, instead of repeating the entire text of the law.

Where does the data run?

As a rule, on a server at Hetzner in Germany, with the language models at a German provider in Berlin. Entirely on your own hardware on-premises if you prefer.

Your system
Documents and the search index live on a server at Hetzner in Germany. I run the server for you.
Language models
A German provider supplies them from its data centre in Berlin: open models, billed by usage. Which provider it is is stated in your offer and in the data processing agreement.
Contracts
Data processing agreements are in place with both providers before your system starts. Your data is neither used for training there nor passed on to third parties. I provide the contracts and evidence of both providers (data processing agreement, technical and organisational measures, certificates) on request.
On-premises if you prefer
If you want to run your own server environment, I install the same system there. Then no document leaves your building.

You keep full control of your documents, receipts and company knowledge at all times.

What legal basis applies under Art. 6 GDPR?

The legal basis does not change because of the system: you already process your records today, usually to perform contracts or because of statutory retention duties.

Performing contracts
Art. 6(1)(b) GDPR: invoices, contracts and files sit with you because you perform contracts.
Retention duty
Art. 6(1)(c) GDPR: you have to retain records.
My role
Processor under Art. 28 GDPR, on your behalf.
Personnel records
Stricter rules under Section 26 of the German Federal Data Protection Act. We check those separately in the intro call.

Making those records searchable is a new form of processing, not a new purpose. As a rule, no additional legal basis arises from it.

This is a practical assessment, not legal advice. If you have a data protection officer or a lawyer, I am happy to involve them.

Do I need a data processing agreement under Art. 28 GDPR?

Yes: Klarbeleg signs a data processing agreement with you under Art. 28 GDPR, and it is already included in the offer.

  • Sets out in writing who processes which data for what purpose
  • Defines which technical and organisational measures apply
  • Is in place before work starts, not added afterwards as a formality
  • You read it before signing on and ask questions about it

You don't have to arrange it yourself.

Is a data protection impact assessment needed under Art. 35 GDPR?

That depends on the individual case: a data protection impact assessment is only required where there is likely a high risk to the people concerned.

A DPIA is a written check done in advance: what risks arise for the people concerned, and what measures reduce them. Whether one is needed in a given case is checked before the project starts, not afterwards. Three questions decide it in practice:

Does the system make decisions about people, for instance on job applications or payment reminders?
Not at Klarbeleg: it searches and cites, you decide.
Is particularly sensitive data processed at scale, such as health data?
For a medical practice or a care service, yes, and then a DPIA is mandatory.
Are employees systematically monitored?
No, the system evaluates documents, not people.

For the typical trade or office business, no DPIA is needed on that basis. If one is, I prepare it together with you as part of the project, at no extra charge.

What happens when you delete data or leave?

You can delete data or end the system at any time, without staying tied to one provider.

This is called freedom from lock-in: a system that binds you to a single provider because your data is trapped in its format is a lock-in. At Klarbeleg, the opposite applies:

  • Your documents stay with you as PDFs with a text layer
  • I deliver analyses as CSV or Excel
  • You do not need Klarbeleg to get at your data, and you take it with you if you stop using the system

In practice that means: no provider switch that starts from zero. Your prepared documents stay usable, even if you choose a different system afterwards.

How do I recognise a GDPR-compliant AI provider?

By six points you should have confirmed in writing before you sign anything.

  • Server location in Germany or the EU, named in writing
  • A data processing agreement under Art. 28 GDPR is in place
  • A written commitment that your data is not used for training
  • A clear statement of the legal basis under Art. 6 GDPR
  • A deletion plan and the ability to export your data
  • Open formats instead of a closed system that locks you in

A serious provider answers all six points briefly and in writing, without detours. If an answer stays vague or only verbal, that is already an answer in itself.

Frequently asked questions

Does the language model itself run in Germany?

Yes. The language models run at a German provider in Berlin, your system at Hetzner in Germany or in your own building.

Does that also apply to personnel data such as payroll?

Yes, with the stricter rules for employee data under German law. Personnel data is neither used for training nor passed on, and we check in advance whether a DPIA is needed.

Does my website also become GDPR-compliant?

Yes. The “Website ready to go” package makes the legal notice, privacy policy, consent banner and forms legally sound, independent of the knowledge system.

What if I want to stop using the system?

You can stop at any time. Your documents are stored in open formats, there is no lock-in.

Who is responsible for data protection on your side?

Martin Haferanke personally, with no middle steps. Contact details and address are in the legal notice.