COMPLIANCE & DATA

Honest about
where we are.

Belgian operators ask compliance questions early. The answers below are the ones we'll actually defend in a meeting. Where we're catching up, we say so. Where we're solid, we say what's signed and shipped. Compliance is a product feature, not a marketing strip.

01 · HOSTINGMIGRATING TO EU-FIRST
EU hosting on request today. EU-first by default by Q4 2026.

Mixed today: client systems run on EU regions (eu-west, eu-central) when the buyer asks; some model APIs (Anthropic, OpenAI) still touch US infrastructure depending on the endpoint. If your project needs EU-only from day one, we configure it.

02 · DPAAVAILABLE ON REQUEST
Data Processing Agreement, lawyer-reviewed before signing.

Standard GDPR Article 28 DPA in preparation. We share the current draft on request once we're scoping an engagement together, after counsel review. We don't publish a self-serve PDF until the language is enforceable.

03 · EU AI ACTAWARE, INTEGRATING
AI Act-aware. Not yet a structured part of every engagement.

The Act is in force; obligations land in waves through 2026–2027. We can flag risk-tier classification on Audit deliverables and we're building it into the Build template. If a system you're scoping looks like it might land in High-risk or GPAI territory, we'll say so before we contract.

04 · GDPRDEFAULT POSTURE
No training on your data. Ever.

Client data is encrypted in transit and at rest, never used to train models (we contract this with the model providers we use), and exportable on request at any time. Standard GDPR rights are wired into the DPA. Access, rectification, erasure, portability. With Article 12 timelines.

SUB-PROCESSORS · ON REQUESTFull list, regions, and safeguards · available with the DPA
Disclosed in full when we contract.
Anthropic · OpenAI · Google Cloud · n8n · Vercel

A full sub-processor list. Including purpose, region, and safeguard (DPA / SCCs / no-training opt-out / etc.). Comes with the DPA we share before an engagement signs. We don't publish the table on a public page because the list and the SCCs both change; we'd rather share the current version, not the SEO version.

REQUEST
Need the DPA, sub-processor list, or AI Act risk note before we talk?
Email hey@innops.ai
Honest disclaimerNone of this is legal advice. We bring lawyer-reviewed templates to engagements; you bring your counsel; we negotiate what's enforceable. Same energy as the work itself: audit before we build.