EU Data Protection and AI Compliance at a Glance
••
Change history (2 entries)
- 07/09/2026Clarified that risk classification depends on the use case, excluded high-risk applications, and separated the transparency notice under Art. 50(1) from machine-readable marking under Art. 50(2).
- 11/08/2026Initial publication.
Everything an information security, data protection or procurement review needs, on one page.
| Item | Detail |
|---|---|
| Entity | LoyJoy GmbH, Kapuzinerstr. 20, 48149 Münster, Germany. HRB 17049, Amtsgericht Münster. |
| Processing location | Personal data is processed exclusively in the EU, on Google Cloud EMEA infrastructure through Google Ireland. |
| AI inference, default path | Gemma 4 on hardware owned by LoyJoy in a data centre in Münster. No third-party model provider involved. Same for embeddings, summarisation, sentiment and topic analysis. |
| Optional model providers | Azure OpenAI in EU regions, Mistral (FR), Scaleway, Nebius, OpenAI. Used only on explicit customer instruction and inactive while the default path is in use. Annex 2 states each location and safeguard. |
| Phone Agent speech-to-speech | Runs in Azure OpenAI’s EU Data Zone. No third-country transfer occurs for this processing; a separate supplementary DPA covers the Phone Agent. |
| Bring your own key | With your own Azure OpenAI subscription, the model provider is your processor under your own contract, not a sub-processor of LoyJoy. |
| Legal basis | Data Processing Agreement under Art. 28(3) GDPR. Annex 1: technical and organisational measures under Art. 32. Annex 2: sub-processor list. |
| Audit right | On-site audits are possible with reasonable prior notice, during business hours, without disrupting operations. |
| Sub-processor changes | Four weeks’ advance notice, two weeks to object. |
| Training exclusion | Contractual, in the DPA: personal data “shall not be used for the training, development, fine-tuning, or other further development of AI or machine learning models.” Inputs are transmitted in real time to generate a response, and nothing else. LoyJoy performs no fine-tuning, so Google remains the GPAI provider of Gemma 4. |
| Retention and deletion | Configurable per tenant from 7 to 720 days, enforced by irreversible deletion. Phone transcripts and recordings 30 days by default. Audio streams are not persisted. Manual deletion and Art. 17 handling documented. |
| Encryption | TLS in transit without exception, AES at rest, key management held outside the cloud provider’s configuration. |
| Identity | Passkey (FIDO2) or magic link. Microsoft Entra ID SSO in all plans. OAuth for end users in chat from the Professional plan. |
| Authorisation and evidence | Around twenty roles, separated tenant data spaces, archived administrative audit logs with alerting. Programmatic access including MCP is governed by the same role model; tokens are revocable at any time. |
| Resilience and incidents | RTO 4 hours, RPO 24 hours, documented recovery plan with an on-call rota. Art. 33 breach process with a 72-hour deadline. |
| EU AI Act | Risk classification depends on the specific intended purpose and customer configuration. Pure information, communication and support functions are generally not classified as high-risk where the system does not make or materially influence decisions about individuals. LoyJoy is not intended for use as a high-risk AI system under Article 6 in conjunction with Annex I or III; such use is excluded under the Acceptable Use Policy. LoyJoy is the provider of the system, and the customer is generally the deployer of the specific use. User transparency under Art. 50(1) is implemented for chat and phone. The separate machine-readable marking of synthetic outputs under Art. 50(2) is under technical review; systems placed on the market before August 2, 2026 have an implementation deadline of December 2, 2026. |
| Certifications and testing | Hosted exclusively on ISO 27001 and PCI DSS certified infrastructure (Google Cloud EMEA). LoyJoy’s own information security management follows the BSI IT-Grundschutz-Kompendium and ISO/IEC 27001:2022, with certification as a stated objective. Annual external penetration test by an accredited provider, OWASP Web Security Testing Guide methodology, certificate available on request. Information security officer: Dr. Ulrich Wolffgang, CTO. |
| Accessibility and DORA | BFSG declaration of conformity, EN 301 549, WCAG 2.1 AA. DORA contract terms with audit rights and reporting from the Enterprise plan. |
No separate box on certification status is needed: the infrastructure is certified, and LoyJoy’s own ISMS follows the standards, with certification as a goal. Anyone who needs the distinction will find it in the “Certifications and testing” row above.
Documents
- DPA (Data Processing Agreement)
- DPA Annex 1: Technical and Organizational Measures
- DPA Annex 2: Sub-Processors
- IT & Data Security Measures of LoyJoy Platform
- Assistance with Data Protection Impact Assessment
- Brief Statement on the EU AI Act
- Acceptable Use Policy
- Supplementary DPA for the LoyJoy Phone Agent
- BFSG EU Declaration of Conformity
- Platform Service Description
- Terms and Conditions
Questions?
Questions from information security, data protection, procurement or AI governance are usually resolved faster in one shared call than in writing over several rounds. The CTO and information security officer join that call.
Contact: ulf.loetschert@loyjoy.com, +49 170 4444 121.