Lawfulness & transparency
Processing on a clear legal basis – and openly documented, so it is always clear what happens with which data.
Digital workers · Data protection
Digital workers work with data. That is why data protection comes first in every MR.KNOW solution: data-minimising, transparent, hosted in the EU and with a person in control.
Principles
We build on the principles of Art. 5 GDPR (mirrored in the UK GDPR) – from data minimisation to accountability.
Processing on a clear legal basis – and openly documented, so it is always clear what happens with which data.
Data is used only for the specified, explicit purpose of the task – and never beyond it.
As little personal data as possible – only what the digital worker genuinely needs for the job.
Processes that keep data current and correct; corrections are possible at any time.
Clear retention periods. Data is not kept for longer than the purpose or the law requires.
Encryption, access control and logging protect data against unauthorised access.
We process only what the task requires – purpose-bound, secure and traceable. Your content does not train any public AI models.
GDPR & EU AI Act
Two frameworks, one approach: we meet the GDPR (incl. UK GDPR) and the EU AI Act together.
The EU AI Act regulates AI use based on risk and complements the GDPR. We meet both in a single approach. Here are the AI Act requirements at a glance.
The regulation classifies AI systems by risk. Digital workers are categorised by their purpose – with additional safeguards where the risk is higher.
People can tell that they are interacting with an AI. AI use and its results are documented and traceable.
Human-in-the-loop: no solely automated decisions with significant effects on individuals. A person reviews and decides.
We avoid applications banned under the regulation, such as social scoring or manipulative systems.
Technical documentation, logging and clear responsibilities form the basis for conformity and audits.
Before go-live we support informing employees and their representatives about the use of AI.
Content that your digital workers process is not fed into AI-model training without being asked. Such use only ever happens if you give your explicit and revocable consent.
Data-subject rights
Data subjects can exercise their rights at any time. We support you in putting them into practice.
Which data we process (Art. 15 GDPR).
Correct inaccurate data (Art. 16 GDPR).
The „right to be forgotten“ (Art. 17 GDPR).
Limit processing (Art. 18 GDPR).
Take your data with you (Art. 20 GDPR).
Object to processing (Art. 21 GDPR).
Security
A selection of the measures we use to ensure the security of processing (Art. 32 GDPR).
The most common questions from IT, data protection and the business.
No – not without your explicit, revocable consent. By default your content is processed solely for the task you commissioned.
In the EU by default, and in the UK or your own region on request. If you prefer, we run the solution on-premise in your own infrastructure.
No. There are no solely automated decisions with legal or similarly significant effects on individuals (Art. 22 GDPR). A person stays in control (human-in-the-loop).
Yes. Where we act as a processor, we provide a DPA in line with Art. 28 GDPR (and UK GDPR), including the technical and organisational measures (TOMs).
We rely on transparency, human oversight and documentation. Before go-live we support informing employees and their representatives about the use of AI.
Yes. Data is encrypted in transit and at rest; the specific technical and organisational measures (TOMs) are part of the data processing agreement.
Yes. On request your data is deleted in line with the data subject rights under the GDPR; with on-premise operation you retain full data sovereignty anyway.
This page describes our general approach to data protection for AI-powered digital workers. It is not legal advice – the applicable privacy notice and contractual agreements (e.g. the Data Processing Agreement) prevail.