Conversational Platform

AI Chatbots with integrated compliance features

Technical, organizational and contractual features designed to support GDPR, EU AI Act, DORA and accessibility requirements.

LoyJoy provides technical, organizational and contractual features designed to support lawful customer-dialogue implementations. The final assessment depends on the specific use case.

EU Data Sovereignty

AI models on our own hardware in our German data center

For our chat agents, we run the AI model Gemma 4 on our own hardware in our data center in Münster, not in a rented cloud. This removes external AI subprocessors from chat inference: no chat data is sent to external US-based model providers during this processing step. Based on the feedback we receive, customers rate Gemma 4 as comparable with current large language models from well-known providers for accuracy, speed and reliability. Other current models remain available by choice.

Server rack with active network and status LEDs in LoyJoy's data center in Münster.

Why Compliance is Crucial Now

Regulatory requirements are increasing. LoyJoy helps you stay one step ahead.

Stricter Regulations

The EU AI Act and DORA increase requirements for transparency and resilience. LoyJoy provides features designed to support relevant requirements in the specific use case.

Reputation Protection

Violations don't just cost money – they cost trust. With LoyJoy you support your compliance posture and protect your brand.

Growing Customer Expectations

Accessible and privacy-friendly experiences are expected. LoyJoy provides features geared toward WCAG 2.1 AA and privacy by design; content and configuration must also be considered.

Legal Frameworks & How LoyJoy Supports Them

From GDPR to the EU AI Act and DORA, LoyJoy provides features and evidence geared toward relevant requirements.

GDPR.
EU-only hosting in securely encrypted data centers. Privacy-by-design with data minimization, pseudonymization, and consent-aware tracking.
EU AI Act.
Features designed to support transparency obligations include labels on AI-generated messages and Explainable AI. High-risk applications are excluded under the Acceptable Use Policy.
DORA.
End-to-end audit logs for all chat events. Automated API incident notification via email.
Accessibility (BfSG / WCAG 2.1 AA).
Screen reader compatible web component, keyboard navigation, high color contrast, and automated accessibility tests with every release.
Certified infrastructure & external testing.
Hosted on ISO 27001 and PCI DSS certified infrastructure (Google Cloud EMEA). LoyJoy's own information security management follows the BSI IT-Grundschutz-Kompendium and ISO/IEC 27001:2022, with certification as a stated objective. Annual external penetration test by an accredited provider, OWASP Web Security Testing Guide methodology, certificate available on request.
Technical & organizational measures.
TLS 1.3 in transit, AES-128 at rest. RBAC and optional MFA requirement. Data retention policy with automatic deletion period.

Privacy by Design & Operational Security

Transparency, control, and data protection are not extras – they are built into the LoyJoy platform.

Explainable AI view.
Source highlighting for every generated answer – traceable for customers and auditors.
Pseudonymised processing.
Processing via abstract identifiers. Retention configurable per tenant from 7 to 720 days, enforced by irreversible deletion.
Model-switch log.
Every LLM change is documented – full traceability for compliance teams.
Data residency.
All customer data stored exclusively in EU regions. LoyJoy does not have access to your data without your explicit permission.
Customer audit portal.
24/7 access to reports and log exports for your compliance evidence.
External audits.
Annually by independent auditors, last report July 2026.

Ready to give LoyJoy a Try?

Request Your Free Personalized Demo Now!