We build inside your cloud, under your controls. This page sets out where your data sits, who touches it, what we sign before we start, and where the models run.
In almost every engagement your data never leaves your environment. We work inside your cloud tenancy, against your systems, under your identity and access controls. What that means contractually depends on what we actually touch:
| Engagement shape | Our role | What we sign |
|---|---|---|
| Hands-on work in systems that hold personal data | Processor on your behalf under Art. 28 GDPR | AV-Vertrag (DPA) plus documented technical and organisational measures under Art. 32 |
| Work with anonymised, aggregated or synthetic data only | No personal data processed | NDA. We record how that determination was made, so it is auditable later |
| Advisory, architecture review, training - no system access | Neither controller nor processor | NDA |
Worth being precise about one point, because it is often misread: personal data staying on your infrastructure does not by itself put us outside Art. 28. Processing under Art. 4(2) includes access and consultation, not just storage. Where we can see personal data, we act as your processor and paper it properly - whose disks it sits on does not change that.
Access is granted by you, to named people, for the work at hand:
ProDataAI is founder-led. Kamlesh Kshirsagar is on every engagement, and that is the point of hiring a small firm: the person who scopes the work is the person who does it.
For specific pieces of work we bring in specialists from a network we have worked with before. That is how the model stays senior without carrying bench cost, and we are straightforward about it:
If a subprocessor list matters to your procurement or your own DPA obligations, we give you the details you need for it, and tell you before anything changes.
Signed before the first invoice, not after it. Note which direction each of these runs:
Most of the risk in an AI project is not the model, it is where the data goes to reach it. There are three options and we will tell you which one your case actually needs:
No client data is used to train models. Not by us, and we configure provider settings so it is not used by them either. Where a provider's default would do otherwise, we change it and show you the setting.
Data residency, access control and subprocessor discipline are the same evidence base the EU AI Act asks for. If you are working towards an AI inventory and risk classification, the controls on this page are already part of the answer.
Our practical guide covers what high-risk classification means, the December 2026 timeline after the Digital Omnibus, and the Betriebsrat dimension under §87 and §90 BetrVG that most guidance skips: EU AI Act - a practical implementation guide.
If your procurement or data protection team wants the contract position settled before anyone talks about scope, that is a good instinct. Send us your template and we will come back with the Art. 32 annex filled in. No call required first.
Start with the paperwork