All posts
Blog · 16 Jul 2026

GDPR-compliant AI on company documents: the questions to ask any vendor

Where the data rests, what leaves per answer, whether the rights articles exist as working mechanisms, and how to hear an honest certification answer. A DPO's short list.

AI over company documents reads mailboxes, contracts and HR folders, which means it processes personal data all day by design. That does not make it incompatible with GDPR. It makes the vendor's architecture a compliance document, and it gives your DPO a short list of questions that cut straight through the marketing. Here is that list, with the answers Naxis Assistant, our private knowledge engine, holds itself to.

Where is the data, and whose name is on it?

The clean answer is a single-tenant deployment: your company's instance, your database, your document store, shared with nobody, running on your own servers or in an EU data centre under the vendor's management. The client stays controller; the vendor processes only what it actually touches, under a signed Data Processing Agreement. If a vendor cannot say plainly where your documents rest and who can reach them, everything after that sentence is decoration.

What leaves the boundary when the AI answers?

The question to insist on: exactly what is transmitted per answer, is anything retained, and does anything train a model? The strongest configuration keeps even generation at home, a self-hosted deployment that answers entirely on its own hardware, so nothing leaves at all. Where a managed AI service is used, the defensible answer is the question plus the permission-filtered excerpts only, zero retention after the answer returns, no training on client data, all of it in the contract.

The rights articles have to exist as product mechanisms

Can the rights actually be exercised?

GDPR grants rights the software has to be able to perform, not merely promise:

  • Access and portability (arts. 15 and 20): a person's data exportable as a machine-readable file, self-service.
  • Erasure (art. 17): hard deletion that removes records from the store and the search index alike. A tombstone with a filename is not erasure; a file path can identify a person on its own.
  • Records of processing (art. 30): a register of what is processed, why and under which measures. The honest version is generated from the deployment's live configuration, so the paperwork cannot drift from the system it describes.
  • Accountability: an audit record that can prove it has not been edited, covering questions, answers, permission changes and erasures.

Ask to see each one performed, not described. In a Naxis deployment each of these is a working mechanism, not a promise: export and erasure are self-service, and the Article 30 record is generated from the configuration that actually runs.

What about the EU AI Act?

An internal knowledge engine is not an Annex III high-risk system, but deployers do carry transparency and AI-literacy duties. The product should discharge them by construction: every conversational surface declares that an AI is answering, answers stay grounded in the company's own record with citations, the system decides nothing about people and executes nothing, and high-risk uses are excluded contractually, so the system your counsel reviewed is the system your teams get.

Certifications

Ask for ISO 27001 and SOC 2, and expect a straight answer. Ours is public: the ISO 27001 and SOC 2 pages carry the current status, and the underlying controls are reviewable today.

The GDPR mapping, article by article Read the security record

The DPA template, the architecture overview and a sample of the generated Article 30 manifest are readable on the compliance pages, and signed copies are an account request away. Bring your DPO; the review is the product working as intended.

← All posts

More from the blog

30 Jul 2026 · 8 min read

Shadow AI: your people are asking someone else about your company

Every paste into a consumer chatbot is a question your own systems could not answer fast enough. Security vendors sell detection, which reads the app and never the question. What the 2026 breach data actually shows, how far Microsoft's new Shadow AI controls really reach, and why the only fix that scales is making the company answerable.

25 Jul 2026 · 8 min read

Naxis vs Glean: enterprise platform or private knowledge engine?

Glean is Google for your company: it finds where things are stored. Naxis is the private knowledge engine that knows what is actually true right now. Different machines, different questions, different prices. An honest way to choose, and the Glean alternative for companies of 5 to 200 people.

All posts →