Data processing and security¶
This document outlines how we handle the data you provide when using our AI product, ensuring transparency and giving you complete control over your information.
How We Process Your Data in Our AI Product¶
At Dropsolid, we are committed to the security and privacy of your data. This document outlines how we handle the data you provide when using our AI product, ensuring transparency and giving you complete control over your information.
Our Commitment to Security and Data Control¶
The security of your data is our highest priority. We provide the following guarantees to ensure your information remains safe, compliant, and under your control at all times.
- ISO 27001 Certified: Dropsolid NV with the organizational unit Dropsolid AI NV is an ISO 27001 certified company under registration number: 30050644 ISMS22. This means our Information Security Management System (ISMS) is independently audited and verified to meet the highest international standards for managing information security. All processes described in this document operate under this certified framework.
- Absolute Data Sovereignty: Your data will not leave the EEA or if it does it complies with GDPR through SCCs. We guarantee that all data storage and processing occurs within EU data centers, ensuring you retain data sovereignty.
- No Uncontrolled Environments: Your data is never sent to or processed in an environment outside of our direct control or that of our contractually-bound, enterprise-grade AI provider. You are always in control of where your data resides.
Data Storage and Optional Vector Database¶
- Optional Vector Database: For customers on our Proof of Concept (POC), Pro, and Enterprise plans, we offer the use of a secure, private PostgreSQL database as a vector store. This database is hosted on our managed servers within a Google Cloud Platform (GCP) data center located in the European Union (EU).
- Encryption at-rest: All data stored in our databases is encrypted at a disk level by default, adding a robust layer of security.
How Your Data Interacts with Our AI Service Provider¶
- Data in-transit: All communication between our systems and the AI service provider is secured using HTTPS (with TLS encryption) and is routed exclusively to the provider's data centers within the EU.
- Data processing: For all requests originating from the EU, the actual computational processing of your data by the AI models happens on servers located within the EU multi-region.
- No training on your data: Your prompts and the AI-generated responses are not stored or used by our AI service provider to train their models or for any other purpose. This prevents your data from ever becoming part of a shared model.
- Temporary Caching: To improve performance, our provider may temporarily cache inputs and outputs for up to 24 hours. This occurs within the secure EU environment and can be disabled upon request.
Usage Monitoring, Auditing, and Analytics¶
- What We Monitor: Our internal platform logs technical details (token counts, response times) and, for auditing purposes, your prompts and the corresponding AI-generated responses. This entire platform operates under our ISO 27001 certified controls and is hosted on our managed servers within a Google Cloud Platform (GCP) data center in the EU.
- Our Commitment: We use technical data for billing and enforcing usage limits. The stored prompts and responses are strictly for auditing purposes and are not processed, analyzed, or used by us for any other reason.
Core Data Governance Guarantees (FAQ)¶
Here are direct answers to key governance and compliance questions.
What data is involved?¶
- User Input and AI Output: The prompts you submit and the responses generated by the AI.
- Technical Usage Data: Metadata about your interactions (token counts, latency, etc.).
- Optional Data for Specific Services: Data you provide for a Vector Database (RAG) or for fine-tuning a custom model.
Where does this data go?¶
Your data is strictly confined to two secure environments, both within the European Union:
- Our Internal Systems (Dropsolid): Your prompts, responses, and usage data are stored for auditing and billing on our EU-based, ISO 27001-certified platform.
- Our AI Service Provider: Your prompts are sent for real-time processing to our AI provider's EU-based servers. This provider does not store your data or use it for training, contractually guaranteeing that your data does not leave this controlled processing environment.
How do you ensure GDPR compliance?¶
Our compliance is built on a foundation of technical and organizational measures:
- ISO 27001 Certification: Our certified security practices provide the framework for how we protect data, a key requirement of GDPR.
- Territoriality and Data Sovereignty: All data remains within the EEA for both storage and processing.
- Purpose Limitation: We use your data only for the explicit purposes of service delivery, billing, and auditing.
- Data Minimization: We only collect data that is strictly necessary for these purposes.
- Security (Integrity and Confidentiality): Data is secured with HTTPS (TLS) in transit and strong encryption at-rest, managed under our ISO 27001 controls.
- Rights of Data Subjects: You retain full ownership and control over your data.
- Data Processing Agreements (DPA): We operate under a strict DPA with our AI service provider, which contractually enforces all GDPR requirements.