GDPR & EU AI Act

GDPR-compliant AI – with the EU AI Act considered from day one

Habicht is an AI platform designed for GDPR compliance from the ground up: data minimisation, self-service data-subject rights, gap-free logging and operation in your own house or an EU data centre. Every use case is additionally classified automatically by EU-AI-Act risk class – including exportable documentation for auditors.

Goshawk portrait with a watchful gaze – standing for data protection with transparency and traceability. Image generated with AI.
Close-up of the watchful goshawk's eye – standing for transparency and traceability. Image generated with AI.

What “built in” actually means

  • Risk class automaticallyEvery app and AI endpoint is classified by EU-AI-Act risk – with traceable reasoning.
  • Audit evidence at the push of a buttonOne compliance documentation (PDF/Word) per version, designed for the AI Act, GDPR Art. 30, NIS2 and CRA.
  • Gap-free loggingEvery AI action traceable, retained for 7 years; every result carries a transparency marker.
  • Data-subject rights, self-serviceAccess, export and deletion under GDPR are integrated – not manual work.
Annex VII fields for technical documentation, an SBOM snapshot per release, transactional deletion cascades across all data stores, breach notification within 72h, and a supply chain designed for NIS2/CRA with signed container images. These functions are in implementation or designed for the respective requirements.
EU AI Act

The EU AI Act in three sentences

  1. The EU AI Act classifies AI applications by risk and attaches obligations to that – from transparency to technical documentation.
  2. For many obligations, full applicability starts in August 2026.
  3. Whoever deploys AI operationally must know the risk class and be able to demonstrate it.
Assess your risk class in 2 minutes

Contractual vs. built in

Data protection can be promised – or implemented in the application. We do the latter.

Only in the contract

Compliance is in the small print; implementation stays your job.

  • Compliance lives in the terms and the data-processing agreement – not in the product.
  • Data sits in a US cloud; third-party access is excluded contractually, not technically.
  • Evidence has to be gathered manually.
  • Deletion and access are a ticket process.
In the application

Risk class, audit log and evidence are produced automatically as you use it.

  • Data protection and risk classification are built into the platform.
  • Operation in your own house or an EU data centre – no data outflow to the US cloud.
  • Compliance documentation is produced automatically per version.
  • Data-subject rights – access, export, deletion – run as self-service.
Sovereignty & data protection

Sovereignty is part of data protection.

Your data stays in your own house or in an EU data centre – no training on your data, no silent outflow to the US cloud.

More on operations & sovereignty
FAQ

Frequent questions on GDPR & the EU AI Act

Habicht is designed for GDPR compliance from the ground up: data minimisation, self-service data-subject rights, gap-free logging and operation in your own house or an EU data centre – with no data outflow to the US cloud.
Every use case is automatically classified by risk class, and you receive an exportable compliance documentation for auditors.
No. There is no training on your data (zero retention) – your content stays your content.
Either fully in your own data centre (on-premise), hybrid, or as SaaS in an EU data centre – never in the US cloud.

See Habicht in your own environment.

A short demo, tailored to your use case – on-premise, hybrid or in the EU cloud.