Home
Hardware
Configurator
Services
OEM Guides About us Warranty Contact Versión en español →
Private AI · GDPR · Confidentiality

AI with confidential data: how to use it without it leaving your company

AI saves hours on contracts, reports and case files. The catch is that, with a cloud AI, every document you give it leaves your company. We look at what that means under the GDPR and what the alternative is.

ACD&CO technical team26 September 20264 min read

What happens to a document when you give it to a cloud AI

When you paste a contract into an AI chat or upload a report, the text travels to the provider’s servers, is processed there and, depending on the plan and settings, may stay in the history for a while. The business plans of the big providers usually commit to not training their models on your data and offer a data-processing agreement, but that does not change the essential point: the document has left your company and a third party is processing it.

For a lot of information that is not a problem. For some it is: personal data of clients or patients, trade secrets, bids, payroll, drawings or any document your contract or profession obliges you to safeguard.

What the GDPR requires when you use AI with personal data

The GDPR does not ban AI, but it requires the same as for any other processing of personal data. Among other things:

  • A legal basis for processing the data, used only for the purpose it was collected for.
  • Data minimisation: using only the data needed for the task.
  • If a provider processes the data on your behalf, a data-processing agreement (Article 28).
  • If the data leaves the European Economic Area, safeguards for that international transfer (Chapter V).
  • If the processing may pose a high risk to people, a data protection impact assessment (Article 35).

None of this is impossible with a cloud AI, but each provider adds a contract, a review and another link in the chain. For your specific case, it is best checked by your data protection officer or adviser.

With an AI that runs inside your network, documents are not disclosed to any AI provider: the processing still happens on your own systems.

Professional secrecy: when GDPR compliance is not enough

Lawyers, advisers, doctors, psychologists, auditors or engineering firms working with client information also have confidentiality duties of their own, from their profession or their contracts. Many companies and firms have adopted a simple rule: client documentation is not uploaded to external tools. Private AI lets you use AI without breaking that rule.

What private AI is and how it works

It is a machine, inside your network, that runs open language models —such as gpt-oss, Llama, Mistral or Qwen— and a search engine over your documents. When someone asks a question, the system finds the relevant passages in your files, gives them to the model to read and the model answers, citing where each fact comes from. Everything happens on your machine: neither the documents nor the questions leave the company.

It can work without an internet connection, each person logs in with their own account and sees only the document collections assigned to them, and there is no cost per use or per token.

What you gain and what you don’t

You gain control: your data stays in, the model does not change unless you want it to and the cost is fixed. What you do not get is the largest models on the market: for very general questions or very complex reasoning, top-tier cloud AI is still ahead.

For searching, summarising and drafting from your own documents, which is where a company saves the most hours, today’s open models work very well.

How to have it in your company

ACD&CO’s private AI for companies is a server inside your network, sized for teams of 5 to 60 people, with per-person permissions. You pay for the hardware, which you can buy or rent, and the set-up and configuration once: €770, with no monthly fees.

There is no maintenance fee, no per-user licence and no per-token cost. Its page has a calculator comparing the cost with cloud AI, in tokens and in time recovered.

Frequently asked questions

Does using ChatGPT with client data breach the GDPR?

Not necessarily: it depends on the legal basis, the contract with the provider, the settings and where the data is processed. What it does mean is that a third party processes that data, with everything that entails. With private AI the question does not arise, because the data never leaves your company.

Does private AI need the internet?

Not to work. It only needs a connection to download security updates, and you decide when it connects.

Is it as good as ChatGPT?

With your documents it works very well. For very general tasks, the largest cloud models still have the edge, and we tell you so before we start.

What would it cost in your case?

The private AI calculator compares the cost with the cloud, in tokens and in time recovered.

See private AI