Skip to main content
Trust & Compliance

Audit-ready by architecture.

GDPR, EU AI Act, and enterprise security. Built into the architecture.

EU data residency

Data processing, storage, and AI runs in the EU. All infrastructure is in EU data centres.

GDPR by Design

Data minimization, access control, and tenant isolation are built into the architecture.

EU AI Act

Automatic logging, transparent decisions, and exportable reports. Already built in.

EU AI Act · Articles 12–14

Full AI Act compliance.

The EU AI Act requires documentation of AI usage, data access, and oversight. Nordvec handles this automatically.

Automatic event logging

[Article 12]

Every query, every response, every data source. Logged with precise timestamps, fully automatic.

Transparency for users

[Article 13]

Clear documentation of what the AI can do, what it can't, and how it reaches its answers.

Human oversight

[Article 14]

Role-based access ensures oversight stays with the right people with the right permissions.

Exportable documentation

[Articles 12–14]

Full compliance report in one click. Ready for regulators, auditors, or internal reviews with up to 10 years of history.

GDPR · Data Subject Rights

Full GDPR compliance.

Beyond data residency and encryption, Nordvec implements every data subject right as a self-service feature. No support tickets needed.

Right to erasure

[Article 17]

One-click account deletion that atomically removes all personal data, documents, embeddings, AI history, and storage blobs. Fully automated, no manual intervention.

Data portability

[Article 20]

Export all your data as structured JSON, including documents, conversations, AI interactions, and memories. Machine-readable and ready to move.

Right of access

[Article 15]

Self-service data export covers everything we process about you. No support ticket, no waiting period. Your data is yours to inspect at any time.

Privacy by design

[Article 25]

Data minimisation, tenant isolation, and purpose limitation built into the architecture. AI providers receive only the minimum context needed per query.

No automated decisions

[Article 22]

Nordvec's AI is advisory only. It never makes binding decisions about individuals. Every answer is presented for human review with full source citations.

Records of processing

[Article 30]

Immutable, partitioned audit logs record every data access, AI query, and administrative action. Tamper-proof and exportable for DPOs and regulators.

Storage limitation

[Article 5(1)(e)]

Deleted documents are automatically purged after 30 days. No manual cleanup needed. Retention periods are enforced at the database level.

Complete audit trail. Always ready.

Every interaction is logged in an append-only audit trail. Available for compliance reviews, internal audits, or regulatory requests.

  • All AI queries and generated responses
  • Data sources accessed per query
  • Role-based access. You see only your own activity.
  • Precise timestamps for every event
  • Export as PDF or CSV in one click
Recent Activity
Q3 Revenue Analysis2 min ago
3 sources accessed
Brand Guidelines Search1 hour ago
2 sources accessed
Remote Work PolicyYesterday
4 sources accessed

Compliance shouldn't be an afterthought.

Compliance and productivity. You shouldn't have to choose.

Request Access