Back

Data protection and AI usage policy

Updated 15 August 2026

This document describes how EuroWork processes data, where processing takes place and which protections are built into the service. EuroWork is operated by EuroWork AB (559474-3709), Box 260, 831 23 Östersund, Sweden.

Roles and responsibility

Your organisation is the data controller for the content employees enter into the service (questions, documents, source material). EuroWork AB processes this content as a data processor, solely to deliver the service.

For account and billing data (name, email address, organisation details) EuroWork AB is the data controller.

What data is processed

Account data: name, email address, job title, department, country, language preference and an optional profile picture. Within the service the profile picture is visible only to others in your organisation. The single exception is the forum, which is shared across all organisations: if you post there without choosing to be anonymous, your name, profile picture, organisation name and country are shown to other participants. See the forum section below.

Work content: conversations, uploaded documents, project sources, assistant material and saved documents. Content is row-level isolated per organisation in the database, one organisation can never read another's data.

Operations and cost log: every AI call is logged with model choice, timestamp, token volume and cost. Prompt and response content is not part of the decision log.

Meeting audio uploaded for transcription is stored temporarily in private file storage in Frankfurt and deleted once the minutes are ready. Documents uploaded for translation are handled the same way.

If your organisation uploads a PowerPoint template, the colours and fonts are extracted and stored, never the file itself. An uploaded logo, however, is stored as an image in the database, since it is drawn into your presentations.

Where data is processed

All storage is within the EU and EEA: both the database and the application run in Frankfurt (Germany), in the same data centre region, so your data does not travel between countries on every page view.

By default, AI processing takes place with Mistral AI in Europe with zero data retention: no prompts or answers are stored by the AI provider, and nothing is used to train their models.

The external models ChatGPT (OpenAI) and Claude (Anthropic) are available as an option. They are only used when a user actively selects them for an individual message, and involve processing in the United States. Every such message first passes the sensitivity gatekeeper: personal data, confidential matters and trade secrets are never sent to external models and always go to the EU model instead. Your administrator can switch the option off for the whole organisation, and enabling or disabling it is audit logged.

The Microsoft 365 connection

Each user can connect their own Microsoft 365 account to the service. The connection is voluntary, personal and read only: the service can read calendar events, inbox subjects and preview text, the content of a single email when the user explicitly points to it, and the content of files on SharePoint and OneDrive that the user already has access to. Nothing is written, sent or deleted in the Microsoft environment.

Material is fetched at the moment of the question, when the user asks something that needs it, and then becomes part of the conversation with the same isolation and retention as all other work content. There is no continuous synchronisation. Access tokens are encrypted at rest (AES-256-GCM), every read is recorded in the audit log with its purpose, and the user can disconnect at any time, which deletes the tokens.

Microsoft's own processing of your email and files takes place under your agreement with Microsoft, not under this one. The connection only reads from it, at the user's request.

Applicable law and cross border transfers

Organisations in the EU are covered by the GDPR. Organisations in Norway, Iceland and Liechtenstein are covered by the GDPR through the EEA Agreement. In both cases all processing takes place within the EU and EEA by default, so no third country transfer arises. Only if a user actively selects an external model for an individual message (an option your administrator can switch off) does a transfer to the United States occur, based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework and after automatic sensitivity screening.

Organisations in the United Kingdom are covered by the UK GDPR together with the Data Protection Act 2018, not the EU GDPR. Storage within the EU and EEA is permitted because the UK recognises the EEA as adequate, and the European Commission renewed its adequacy decision for the UK on 19 December 2025, valid until 27 December 2031.

Organisations in Switzerland are covered by the revised Federal Act on Data Protection (revFADP), supervised by the FDPIC. The GDPR only reaches a Swiss organisation once it addresses the EU market. Storage within the EU and EEA is permitted because Switzerland recognises the EEA as adequate.

The EU AI Act applies to organisations in the EU. It is EEA relevant but not yet incorporated into the EEA Agreement, and neither the United Kingdom nor Switzerland has an equivalent horizontal AI law. The reports and documentation in the service are available on every market and are useful as supporting material whichever framework applies to you.

The forum

The forum is shared by all organisations in the service and is therefore the only place where data leaves your organisation. Here EuroWork AB is the data controller rather than a processor, because we determine the purpose of the shared discussion ourselves.

If you post under your own name, your name, profile picture, organisation name and country are shown to everyone with access to the forum. If you choose to post anonymously, none of this is shown: the link to your account remains in the database so that you can edit your own post, but it is never shown to other readers, nor to your employer.

Posts are automatically translated into the languages readers use, and automatically reviewed before publication. Both steps run on an EU model with zero data retention and are paid for by EuroWork. Do not write personal data or confidential information in a forum post, whether or not you are anonymous.

Your organisation's owner decides whether employees have access to the forum. It is on by default and can be switched off for the whole organisation.

The sensitivity gatekeeper

Before anything is sent to an AI model, the prompt, attached documents and context sources are screened automatically in two layers: deterministic patterns (personal identity numbers, email addresses, phone numbers, IBAN and more) plus a contextual assessment on an EU model.

If sensitive data is detected, the conversation's protection class is raised automatically, the user is informed, and the event is logged. The protection is built fail closed: if the screening cannot decide, the content is treated as sensitive.

Information classes and web search

All content is handled in information classes: public, internal, confidential or prohibited. The class governs which data flows are allowed.

Web search can never be used for confidential content, a platform rule that cannot be switched off. Your organisation can tighten the rules further, never loosen them.

Retention and deletion

Your administrator controls the retention policy: conversations are deleted automatically after a chosen number of days of inactivity per information class. Deletion is recorded in the audit log.

The organisation can export all conversation content (JSON) at any time and request full deletion.

Cookies

The service uses only necessary cookies: a session cookie for signing in and a language cookie that is set only when you actively choose a language yourself. There are no analytics, tracking or third-party cookies, which is why no consent banner is shown.

Country and language for new visitors are derived from the browser's language setting and the network's country of origin at each page view.

Visitor statistics on the public website are cookie free: we count page views per day, page, country and referring site as plain numbers. To count unique visitors per day, a one way hash of network address and browser is stored with a salt that rotates daily, and the hashes are deleted after two days. No visitor can be followed across days, and nothing is shared with third parties.

If you write a proposal in the Not the one who decides? form, EuroWork AB stores what you filled in and the finished draft for follow up, and the email addresses when the email is sent. EuroWork AB is the data controller for this data.

Subprocessors

Vercel Inc. (application hosting and temporary file storage, EU region Frankfurt), Neon Inc. (database, EU region Frankfurt), Mistral AI SAS (AI models, France, zero data retention), Black Forest Labs GmbH (image generation, Germany, EU hosting) and Sweego SAS (transactional email such as invitations and password resets; a French company hosted with OVHcloud and Scaleway within the EU).

OpenAI (United States) and Anthropic PBC (United States), solely for messages where the user actively selected an external model (an option your administrator can switch off) and the automatic sensitivity screen has cleared the content.

Security

Each organisation's data is isolated in two layers: every database query states the organisation explicitly, and the database additionally has per organisation row level policies (Row-Level Security). All traffic is encrypted. Administrator events, policy changes and exports are recorded in an audit log that the organisation's administrator and data protection officer can review.

Single sign-on (SSO/OIDC) and automatic provisioning (SCIM 2.0) are supported, deactivated accounts are shut out immediately.

AI marking under the AI Act

What the service creates is marked as machine-made. Every image gets two markings: an invisible one, built into the image itself, and a note in the file metadata saying it is AI-created, by which service and when. Documents exported to Word and PDF carry the same note in the file properties. The marking says nothing about what the content is about, who ordered it or which organisation it belongs to.

The marking must not be removed. You may not, and may not allow anyone else to, deliberately delete or rewrite the marking the service has placed in a file. Exceptions apply where a change is necessary to keep the information accurate after downstream processing, and for security audits and research. We do not sell tools for circumventing markings either, and we do not strip markings that someone else placed in material you feed in.

Visible marking is your responsibility. If you publish a deep fake, meaning image, audio or video resembling a real person or event that could be taken for genuine, it has to be visible to whoever sees it. The same goes for AI-written text published to inform the public on matters of public interest, unless a person has reviewed the substance and taken editorial responsibility. Internal material, emails and anything that stays inside the organisation is not covered.

Your rights and contact

Data subjects exercise their rights (access, rectification, erasure and more) primarily via their organisation, which is the data controller for work content.

Questions about this policy or EuroWork AB's own processing: contact EuroWork AB (559474-3709), Box 260, 831 23 Östersund, Sweden.