Back

Data protection and AI usage policy

Updated 2 August 2026

This document describes how EuroWork processes data, where processing takes place and which protections are built into the service. EuroWork is operated by Skräddarsydd AB, Norrgatan 16, 432 41 Varberg, Sweden.

Roles and responsibility

Your organisation is the data controller for the content employees enter into the service (questions, documents, source material). Skräddarsydd AB processes this content as a data processor, solely to deliver the service.

For account and billing data (name, email address, organisation details) Skräddarsydd AB is the data controller.

What data is processed

Account data: name, email address, job title, department, country, language preference and an optional profile picture. Within the service the profile picture is visible only to others in your organisation. The single exception is the forum, which is shared across all organisations: if you post there without choosing to be anonymous, your name, profile picture, organisation name and country are shown to other participants. See the forum section below.

Work content: conversations, uploaded documents, project sources, assistant material and saved documents. Content is row-level isolated per organisation in the database, one organisation can never read another's data.

Operations and cost log: every AI call is logged with model choice, timestamp, token volume and cost. Prompt and response content is not part of the decision log.

Where data is processed

All storage is within the EU and EEA: the database runs in Frankfurt (Germany) and the application in Stockholm (Sweden).

By default, AI processing takes place with Mistral AI in Europe with zero data retention: no prompts or answers are stored by the AI provider, and nothing is used to train their models.

The external models ChatGPT (OpenAI) and Claude (Anthropic) are available as an option. They are only used when a user actively selects them for an individual message, and involve processing in the United States. Every such message first passes the sensitivity gatekeeper: personal data, confidential matters and trade secrets are never sent to external models and always go to the EU model instead. Your administrator can switch the option off for the whole organisation, and enabling or disabling it is audit logged.

Applicable law and cross border transfers

Organisations in the EU are covered by the GDPR. Organisations in Norway, Iceland and Liechtenstein are covered by the GDPR through the EEA Agreement. In both cases all processing takes place within the EU and EEA by default, so no third country transfer arises. Only if a user actively selects an external model for an individual message (an option your administrator can switch off) does a transfer to the United States occur, based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework and after automatic sensitivity screening.

Organisations in the United Kingdom are covered by the UK GDPR together with the Data Protection Act 2018, not the EU GDPR. Storage within the EU and EEA is permitted because the UK recognises the EEA as adequate, and the European Commission renewed its adequacy decision for the UK on 19 December 2025, valid until 27 December 2031.

Organisations in Switzerland are covered by the revised Federal Act on Data Protection (revFADP), supervised by the FDPIC. The GDPR only reaches a Swiss organisation once it addresses the EU market. Storage within the EU and EEA is permitted because Switzerland recognises the EEA as adequate.

The EU AI Act applies to organisations in the EU. It is EEA relevant but not yet incorporated into the EEA Agreement, and neither the United Kingdom nor Switzerland has an equivalent horizontal AI law. The reports and documentation in the service are available on every market and are useful as supporting material whichever framework applies to you.

The forum

The forum is shared by all organisations in the service and is therefore the only place where data leaves your organisation. Here Skräddarsydd AB is the data controller rather than a processor, because we determine the purpose of the shared discussion ourselves.

If you post under your own name, your name, profile picture, organisation name and country are shown to everyone with access to the forum. If you choose to post anonymously, none of this is shown: the link to your account remains in the database so that you can edit your own post, but it is never shown to other readers, nor to your employer.

Posts are automatically translated into the languages readers use, and automatically reviewed before publication. Both steps run on an EU model with zero data retention and are paid for by EuroWork. Do not write personal data or confidential information in a forum post, whether or not you are anonymous.

Your organisation's owner decides whether employees have access to the forum. It is on by default and can be switched off for the whole organisation.

The sensitivity gatekeeper

Before anything is sent to an AI model, the prompt, attached documents and context sources are screened automatically in two layers: deterministic patterns (personal identity numbers, email addresses, phone numbers, IBAN and more) plus a contextual assessment on an EU model.

If sensitive data is detected, the conversation's protection class is raised automatically, the user is informed, and the event is logged. The protection is built fail closed: if the screening cannot decide, the content is treated as sensitive.

Information classes and web search

All content is handled in information classes: public, internal, confidential or prohibited. The class governs which data flows are allowed.

Web search can never be used for confidential content, a platform rule that cannot be switched off. Your organisation can tighten the rules further, never loosen them.

Retention and deletion

Your administrator controls the retention policy: conversations are deleted automatically after a chosen number of days of inactivity per information class. Deletion is recorded in the audit log.

The organisation can export all conversation content (JSON) at any time and request full deletion.

Cookies

The service uses only necessary cookies: a session cookie for signing in and a language cookie that is set only when you actively choose a language yourself. There are no analytics, tracking or third-party cookies, which is why no consent banner is shown.

Country and language for new visitors are derived from the browser's language setting and the network's country of origin on each page view, without storing anything.

Subprocessors

Vercel Inc. (application hosting, EU region Stockholm), Neon Inc. (database, EU region Frankfurt), Mistral AI SAS (AI models, France, zero data retention) and Resend (transactional email such as invitations and password resets).

OpenAI (United States) and Anthropic PBC (United States), solely for messages where the user actively selected an external model (an option your administrator can switch off) and the automatic sensitivity screen has cleared the content.

Security

Each organisation's data is isolated in two layers: every database query states the organisation explicitly, and the database additionally has per organisation row level policies (Row-Level Security). All traffic is encrypted. Administrator events, policy changes and exports are recorded in an audit log that the organisation's administrator and data protection officer can review.

Single sign-on (SSO/OIDC) and automatic provisioning (SCIM 2.0) are supported, deactivated accounts are shut out immediately.

AI marking under the AI Act

What the service creates is marked as machine-made. Every image gets two markings: an invisible one, built into the image itself, and a note in the file metadata saying it is AI-created, by which service and when. Documents exported to Word and PDF carry the same note in the file properties. The marking says nothing about what the content is about, who ordered it or which organisation it belongs to.

The marking must not be removed. You may not, and may not allow anyone else to, deliberately delete or rewrite the marking the service has placed in a file. Exceptions apply where a change is necessary to keep the information accurate after downstream processing, and for security audits and research. We do not sell tools for circumventing markings either, and we do not strip markings that someone else placed in material you feed in.

Visible marking is your responsibility. If you publish a deep fake, meaning image, audio or video resembling a real person or event that could be taken for genuine, it has to be visible to whoever sees it. The same goes for AI-written text published to inform the public on matters of public interest, unless a person has reviewed the substance and taken editorial responsibility. Internal material, emails and anything that stays inside the organisation is not covered.

Your rights and contact

Data subjects exercise their rights (access, rectification, erasure and more) primarily via their organisation, which is the data controller for work content.

Questions about this policy or Skräddarsydd AB's own processing: contact Skräddarsydd AB, Norrgatan 16, 432 41 Varberg, Sweden.