Security & your data
For a Mittelstand company, one question comes before every use case: what happens to our data? Here is how we work, plainly, and the same way on every engagement.
Your data stays yours
We work on your systems, or on a setup you control. Your data does not become ours, and whatever we build runs inside your business and stays yours when we leave. No lock-in, no dependency on us to keep it running.
Where your data is processed
We process data inside the EU/EEA wherever possible. Where a provider processes data outside it, the transfer is safeguarded by the EU Standard Contractual Clauses. Per project, we tell you exactly which systems touch your data and where they run, before anything starts.
Which AI we use
We are vendor-neutral and pick the best-in-class model for each job, chosen for its security and data terms as much as its quality. Every tool is configured so your business data is not used to train third-party models, and where a tool processes data on our behalf, it does so under a data-processing agreement and only for your project. You always know which provider sits behind each part of the build.
Who can access what
Access is kept to the few people who need it for your project, on the principle of least privilege: only what the work requires, nothing more. Credentials stay in your control, and our access is removed when the engagement ends.
A human always signs off
Nothing an AI produces leaves your house without a person deciding it should. The AI proposes; your people decide. Automation removes the routine, never the judgment.
Deletion and hand-back
When a project ends, or whenever you ask, we return or delete the data we held on your behalf and revoke our access. What we built stays with you; what was ours to hold does not linger. We agree the specifics with you in writing at the start.
Documented, so you can run it without us
We hand over what we build with the documentation to operate it: how it works, where it runs, who has access, and how to change it. No black box, no reliance on us to keep the lights on.
GDPR and Swiss law
We process personal data in line with the EU General Data Protection Regulation (GDPR) and, for Swiss clients, the Swiss Data Protection Act (revDSG), under a data-processing agreement. See our Privacy Policy for the detail.
Who is responsible
You work directly with a founder, who is your point of contact for anything about your data. Ask us who handles what, and we will tell you by name. contact.adaimpact@gmail.com
Questions about your specific setup?
Every business is different. Tell us your constraints and we will walk you through exactly how your data would be handled, before anything starts. Talk to us →