AI over company documents reads mailboxes, contracts and HR folders, which means it processes personal data all day by design. That does not make it incompatible with GDPR. It makes the vendor's architecture a compliance document, and it gives your DPO a short list of questions that cut straight through the marketing. Here is that list, with the answers Naxis Assistant, our private knowledge engine, holds itself to.
Where is the data, and whose name is on it?
The clean answer is a single-tenant deployment: your company's instance, your database, your document store, shared with nobody, running on your own servers or in an EU data centre under the vendor's management. The client stays controller; the vendor processes only what it actually touches, under a signed Data Processing Agreement. If a vendor cannot say plainly where your documents rest and who can reach them, everything after that sentence is decoration.
What leaves the boundary when the AI answers?
The question to insist on: exactly what is transmitted per answer, is anything retained, and does anything train a model? The strongest configuration keeps even generation at home, a self-hosted deployment running a self-hosted, open-weight AI model, so nothing leaves at all. Where a managed AI service is used, the defensible answer is the question plus the permission-filtered excerpts only, zero retention after the answer returns, no training on client data, all of it in the contract.

Can the rights actually be exercised?
GDPR grants rights the software has to be able to perform, not merely promise:
- Access and portability (arts. 15 and 20): a person's data exportable as a machine-readable file, self-service.
- Erasure (art. 17): hard deletion that removes records from the store and the search index alike. A tombstone with a filename is not erasure; a file path can identify a person on its own.
- Records of processing (art. 30): a register of what is processed, why and under which measures. The honest version is generated from the deployment's live configuration, so the paperwork cannot drift from the system it describes.
- Accountability: an audit record that can prove it has not been edited, covering questions, answers, permission changes and erasures.
Ask to see each one performed, not described. In a Naxis deployment each of these is a working mechanism, not a promise: export and erasure are self-service, and the Article 30 record is generated from the configuration that actually runs.
What about the EU AI Act?
An internal knowledge engine is not an Annex III high-risk system, but deployers do carry transparency and AI-literacy duties. The product should discharge them by construction: every conversational surface declares that an AI is answering, answers stay grounded in the company's own record with citations, the system decides nothing about people and executes nothing, and high-risk uses are excluded contractually, so the system your counsel reviewed is the system your teams get.
Certifications
Ask for ISO 27001 and SOC 2, and expect a straight answer about status. Ours is public: the ISO 27001 track and the SOC 2 track each show exactly where the work stands, the underlying controls are reviewable today.
The GDPR mapping, article by article Read the security record
The DPA template, the architecture overview and a sample of the generated Article 30 manifest are readable on the compliance pages, and signed copies are an account request away. Bring your DPO; the review is the product working as intended.
