Automation that feels like teamwork.

Digital workers · Data protection

Data protection, built in.

Digital workers work with data. That is why data protection comes first in every MR.KNOW solution: data-minimising, transparent, hosted in the EU and with a person in control.

Principles

Data protection, done consistently

We build on the principles of Art. 5 GDPR (mirrored in the UK GDPR) – from data minimisation to accountability.

Lawfulness & transparency

Processing on a clear legal basis – and openly documented, so it is always clear what happens with which data.

Purpose limitation

Data is used only for the specified, explicit purpose of the task – and never beyond it.

Data minimisation

As little personal data as possible – only what the digital worker genuinely needs for the job.

Accuracy

Processes that keep data current and correct; corrections are possible at any time.

Storage limitation

Clear retention periods. Data is not kept for longer than the purpose or the law requires.

Integrity & confidentiality

Encryption, access control and logging protect data against unauthorised access.

Your data stays your data.

We process only what the task requires – purpose-bound, secure and traceable. Your content does not train any public AI models.

GDPR & EU AI Act

Data protection meets AI regulation

Two frameworks, one approach: we meet the GDPR (incl. UK GDPR) and the EU AI Act together.

GDPR: Data residency & processing

  • Data residency in the EU (UK or your region on request)
  • On-premise operation in your own infrastructure possible
  • Encryption in transit and at rest
  • Role and access concept (need-to-know)
  • Data Processing Agreement (DPA) available
  • Supports GDPR, UK GDPR / DPA 2018 and, where relevant, US state privacy laws (e.g. CCPA/CPRA)

GDPR: AI-specific safeguards

  • Your data does not train public AI models – only with your explicit consent
  • No solely automated decisions about individuals (Art. 22 GDPR)
  • Safeguards against false outputs („hallucinations“) and traceable results
  • No sharing with third parties for unrelated purposes

EU AI Act requirements

The EU AI Act regulates AI use based on risk and complements the GDPR. We meet both in a single approach. Here are the AI Act requirements at a glance.

Risk-based approach

The regulation classifies AI systems by risk. Digital workers are categorised by their purpose – with additional safeguards where the risk is higher.

Transparency obligations

People can tell that they are interacting with an AI. AI use and its results are documented and traceable.

Human oversight

Human-in-the-loop: no solely automated decisions with significant effects on individuals. A person reviews and decides.

No prohibited practices

We avoid applications banned under the regulation, such as social scoring or manipulative systems.

Governance & documentation

Technical documentation, logging and clear responsibilities form the basis for conformity and audits.

Informing the workforce

Before go-live we support informing employees and their representatives about the use of AI.

No training on your data. No ifs, no buts.

Content that your digital workers process is not fed into AI-model training without being asked. Such use only ever happens if you give your explicit and revocable consent.

Data-subject rights

Your rights under the GDPR

Data subjects can exercise their rights at any time. We support you in putting them into practice.

Access

Which data we process (Art. 15 GDPR).

Rectification

Correct inaccurate data (Art. 16 GDPR).

Erasure

The „right to be forgotten“ (Art. 17 GDPR).

Restriction

Limit processing (Art. 18 GDPR).

Data portability

Take your data with you (Art. 20 GDPR).

Objection

Object to processing (Art. 21 GDPR).

Security

Technical & organisational measures (TOMs)

A selection of the measures we use to ensure the security of processing (Art. 32 GDPR).

  • Encryption (in transit & at rest)
  • Access, authorisation and input controls
  • Pseudonymisation/anonymisation where possible
  • Logging & traceability (purpose-bound)
  • Regular backups & recoverability
  • Processes to test & evaluate effectiveness

AI data protection explained

The most common questions from IT, data protection and the business.

Is our data used to train AI models?

No – not without your explicit, revocable consent. By default your content is processed solely for the task you commissioned.

Where is the data stored?

In the EU by default, and in the UK or your own region on request. If you prefer, we run the solution on-premise in your own infrastructure.

Does the AI make automated decisions about people?

No. There are no solely automated decisions with legal or similarly significant effects on individuals (Art. 22 GDPR). A person stays in control (human-in-the-loop).

Is there a Data Processing Agreement (DPA)?

Yes. Where we act as a processor, we provide a DPA in line with Art. 28 GDPR (and UK GDPR), including the technical and organisational measures (TOMs).

How does this relate to the EU AI Act?

We rely on transparency, human oversight and documentation. Before go-live we support informing employees and their representatives about the use of AI.

Is the data encrypted?

Yes. Data is encrypted in transit and at rest; the specific technical and organisational measures (TOMs) are part of the data processing agreement.

Can I have my data deleted?

Yes. On request your data is deleted in line with the data subject rights under the GDPR; with on-premise operation you retain full data sovereignty anyway.