Data governance
Where the data sits, who may see it, how long it is kept, and what the EU AI Act says about the thing you are building. Settled before the first line of code, not after the security questionnaire arrives.
What this is
The question that stops an AI project is almost never technical. It is a customer's security questionnaire, a works council asking where the data goes, a lawyer asking which risk tier this falls into, or a board member asking what happens if the thing is wrong about somebody. These questions arrive late, and they arrive all at once.
This is the work of answering them before they are asked. Where each piece of data comes from and where it ends up, what lawful basis it moves on, who may see what, how long anything is kept, and what the EU AI Act requires of the specific system you are building. It is not a policy document nobody reads. It is a set of decisions, written down, that software can be built against.
EU hosting by default and a GDPR processing agreement signed before we touch anything. The AI Act risk tier is worked out before design starts, because the tier changes what has to be built.
What it does
Five questions, answered once, in a form your legal team can sign and your engineers can implement.
01
Maps the data the system touches
Every source, every field that is personal, and every place a copy ends up, including the copies nobody meant to create.
02
Settles the lawful basis and the paperwork
Processing agreement, sub-processors, transfers, and the record you are required to keep. Written for a legal team to sign rather than a template to fill in later.
03
Classifies the system under the EU AI Act
Which tier, what that requires in practice, and what it would take to stay out of a heavier tier where that is a real option.
04
Defines who may see what
An access model that matches how the company actually works, and a plan for the day somebody changes role or leaves.
05
Sets retention, deletion and logging
How long things are kept, how a deletion request is honoured end to end, and what is logged so an audit can be answered with evidence instead of assurances.
What you walk away with
Documents that answer the questions before they are asked, and rules that live in the software rather than in a folder.
A data map and a register
What the system touches, where it lives, who processes it, and on what basis.
The signed paperwork
A processing agreement, the sub-processor list and the transfer position, ready for your legal team.
A written AI Act classification
The tier, the reasoning behind it, and the obligations that follow, in language a non-lawyer can act on.
An access matrix and a retention schedule
Who sees what, for how long, and what the system does automatically when the answer changes.
How it runs
One system at a time
We govern the thing being built, not the whole company. A company wide programme takes a year and protects nothing in the meantime.
Follow the data
Sources, copies, backups, logs and third parties. The copies nobody remembers are the ones that cause the incident.
Decide and write it down
Every decision gets an owner and a date. An open question is fine; an undocumented assumption is not.
Build it into the system
Access rules, retention and logging become configuration and code, not a promise in a document.
Who this suits
Regulated industries
Finance, health and anything where your customer's auditor eventually becomes your auditor.
Companies answering security questionnaires
Enterprise customers ask. The answers should exist before a deal depends on them.
Anyone about to sign an AI vendor
Where the data goes, what it trains, and what happens when you leave. Worth an hour before signature.
What it costs in time
Calendar time for one system. Shorter if the system is not live yet, which is also the cheapest moment to do this.
Map and questions
We follow the data through the system and come back with the questions only you can answer.
Decisions and classification
Lawful basis, the AI Act tier, access and retention, written down with an owner against each one.
Built in
The rules become configuration and code, and the paperwork goes to your legal team.
Send us the questionnaire you are stuck on
Or the clause your customer added at the last minute. Thirty minutes is usually enough to say what needs answering and in what order.
Book a call