Your staff are probably using ChatGPT already. On personal accounts, because it is faster, and with quotes, emails, or customer data, because that is what the work consists of. Very few companies can say where that data ends up.
Service
Locations in Ulm/Neu-Ulm and Brandenburg/Berlin; built for companies beyond those regions.
A ban only makes AI invisible
Prohibit AI without offering an approved route and you get shadow AI: personal accounts, no logs, no data processing agreement. The time savings are real, so people keep going. Just somewhere nobody is looking.
Every data class gets its place
We classify your data by protection need and decide, per class, where it may be processed: in a local model on your own network, with a provider offering EU hosting and a data processing agreement, or in a standard tool with clear input rules. The approved environment has to be more convenient than the personal account, or nobody will use it.
What we actually deliver
- An inventory of the AI tools already in use
- Data classes, data flows, and technical measures, documented for your data protection officer
- An approved AI environment: local, EU cloud, or hybrid
- An AI usage policy that fits on one page
- AI literacy training under Art. 4 of the AI Act, with records
Afterwards, AI is permitted instead of tolerated
- Everyone knows which tool is approved for which data.
- Customer data and trade secrets stay in environments you control.
- When a customer, an auditor, or a supervisory authority asks, the documentation is ready.
- The time savings stay, without the grey area.
Langdock alternative
AI Hub: an approved AI environment, ready to use
If you do not want to start from scratch, AI Hub gives you chat, a knowledge base, AI agents, workflows, transcription, and website chatbots in one interface. Data and models run only in EU data centres, one data processing agreement covers every tool, and your content is never used for training. The models behind it are interchangeable.
Common questions about AI and data protection
- Can companies use ChatGPT in compliance with GDPR?
- Yes, if the setup is right. That means a business or API account with a data processing agreement, inputs that are not used for training, and clear rules on which data may be entered. Personal accounts on the free version are not suitable for customer personal data. The same applies to Microsoft Copilot, Claude, or Gemini. If you want a European alternative, there are European models such as Mistral and platforms with EU hosting.
- Is there a GDPR-compliant alternative to Langdock or ChatGPT Enterprise?
- Yes, for example AI Hub, our platform with chat, a knowledge base, AI agents, workflows, transcription, and website chatbots. Data and models run only in EU data centres, one data processing agreement covers every tool, and content is never used for model training. Which platform fits depends on your data classes, existing IT, and budget. We work that out in the AI privacy check.
- When is local AI better than a cloud solution?
- Local AI pays off when data must not leave the building, for example professional secrecy at law firms, medical practices, and tax advisers, engineering data, or contracts with strict confidentiality clauses. For many other tasks, a cloud model with EU hosting gives better answers at lower cost. A hybrid setup is often the most sensible: sensitive data stays local, the rest runs in the cloud.
- What does the EU AI Act require from companies that only use AI?
- Since 2 February 2025, companies that deploy AI must ensure sufficient AI literacy among their staff (Art. 4). Since 2 August 2026, the transparency obligations of Art. 50 apply, for example telling people they are talking to an AI and labelling deepfakes. Obligations for high-risk systems were postponed to December 2027 and August 2028. For most SMEs, training, documentation, and transparency therefore come first.
- What is shadow AI and why is it a risk?
- Shadow AI means employees use AI tools with company data without the company knowing or approving it. There is no data processing agreement, no logging, and no deletion policy, and after a data breach nobody can trace what went where. A ban alone rarely helps. An approved alternative that is faster in daily work does.
- Does 1tm replace a data protection officer or legal advice?
- No. We provide the technical and organisational groundwork: data flows, technical measures, policy, training records, and the AI environment itself. The legal assessment of individual cases stays with your data protection officer or law firm, and this documentation makes their review much faster.
