Trust: what you need to approve EuroWork
Where the data is stored, what the contract says, what we don鈥檛 have, and a ready-made template for a data protection impact assessment that you can fill in and attach.
This page isn鈥檛 written for the person who will use EuroWork. It鈥檚 written for the person who needs to approve someone else using it: the data protection officer, the IT manager, the procurement officer, or the person who gets the question dropped in their lap on a Friday and needs an answer by Monday.
We鈥檝e tried to answer all those things in one place, including what we don鈥檛 have.
Where the data actually is stored
The database and the application both run in Frankfurt, in the same data centre region. AI processing happens by default with Mistral AI in Europe, with zero data retention: your questions and answers aren鈥檛 saved by the AI provider and aren鈥檛 used to train their models.
ChatGPT and Claude are available as options and involve processing in the US. They鈥檙e only used when an individual user actively selects them for a single message, and your administrator can turn the option off completely. Before such a message is sent, it goes through a sensitivity check, and anything that looks like personal data or confidential information is always routed to the EU model instead.
All of this is also stated in the policy document, which is the legally binding text. This page is the summary.
How one organisation never sees another鈥檚 data
The isolation is built into the database, not the code on top. Every query to the database carries the organisation鈥檚 identity, and without that identity, no rows are returned at all. If a bug in the application forgets a condition, the result is that nothing shows up, not that the wrong thing does. That鈥檚 called fail-closed, and it鈥檚 the only kind of protection you can rely on in the long run.
Content is never logged in the decision log. It records which model responded, when, how much it cost, and why the model was chosen. Not what anyone asked.
The contract
The data processing agreement is part of the service agreement, with your organisation as the data controller and EuroWork AB as the processor for the content your employees enter. You can get the contract text before you register, just let us know.
The sub-processors, meaning the providers we in turn use for operations and AI processing, are named in the policy document. If we change any of them, we鈥檒l let you know in advance.
What we don鈥檛 have
We鈥檙e not ISO 27001 certified. We don鈥檛 have an external penetration test to show you, or a status page with an uptime history. Those things are coming, but we won鈥檛 pretend they already exist.
We鈥檇 rather you find this out on our own page than during a procurement process.
Accessibility
The service is built to meet WCAG 2.2 AA. Contrast levels, keyboard navigation, and screen reader support have been reviewed, but we鈥檙e not claiming every surface is perfect. If you run into something that doesn鈥檛 work, let us know, and we鈥檒l fix it. That鈥檚 also the only honest way to work with accessibility: a service is never finished, it just gets gradually less bad.
If something goes wrong
If we discover a personal data breach, we鈥檒l contact you without undue delay, with what we know at the time and what we鈥檙e doing about it. You鈥檒l get what you need for your own report to the supervisory authority, including timestamps and which categories of data were affected.
Taking your material with you
Documents can be downloaded as Word, Excel, or PowerPoint directly in the service. If you want everything exported at once, for example because you鈥檙e choosing to leave, we鈥檒l arrange that. We don鈥檛 see making a cancellation difficult as a negotiating position.
The AI Act
Everything the service generates is labelled. Images carry the marking inside the file itself, so it stays with the image when it鈥檚 downloaded and shared. AI responses are marked in the interface. That meets Article 50 on transparency, and the reports in the service can be used as part of your own documentation.
Ready-made template for a data protection impact assessment
If a public sector organisation is introducing AI, a data protection impact assessment is usually required, and writing one from scratch takes an afternoon no one has. Here鈥檚 a template where we鈥檝e answered everything that鈥檚 about us. What鈥檚 left is what鈥檚 about you, and only you can answer that.
1. Description of the processing. EuroWork is used by employees to ask questions, summarise and create documents, transcribe meetings, translate files, and run recurring tasks. The data processed includes account details and the work content employees enter themselves.
2. Purpose and legal basis. Fill in your purpose. The legal basis is typically public interest or exercise of official authority for public sector organisations, legitimate interest for private ones.
3. Categories of data subjects. Employees who use the service, and the individuals who appear in the material employees choose to enter. Specify who these are in your organisation.
4. Necessity and proportionality. The service doesn鈥檛 collect more than what the employee writes or uploads themselves. The connection to Microsoft 365 is personal and voluntary: each user connects their own account, the connection is read-only (calendar, email headers, individual emails and files at the user鈥檚 explicit request), data is fetched at the time of the query without ongoing synchronisation, each access is logged, and the user can disconnect their account at any time.
5. Where the processing takes place. Storage within the EU and EEA: database and application in Frankfurt, in the same data centre region. AI processing with a European provider with zero data retention. Third-country transfers only occur if a user actively chooses an external model, an option that can be disabled for the entire organisation.
6. Risks and safeguards. Row-level isolation per organisation that fails closed, automatic sensitivity checks that can raise but never lower the protection level, information classification per query, an audit log of actions, human approval before an AI draft becomes a final document, and a monthly cost cap.
7. Residual risk. The main residual risk is that an employee enters more sensitive material than the purpose requires. Countermeasures: information classification, the sensitivity check, and the built-in course covering this specifically. Assess the level based on your organisation.
8. Consultation with the data protection officer. Fill in the date and any comments.
If you鈥檇 like this template as a Word document, just let us know and we鈥檒l send it.
Ask us instead of guessing
If you can鈥檛 find the answer here, write to us. You鈥檒l get a reply from a human, and if the answer is that we don鈥檛 have what you need, we鈥檒l say so.