Is the development of an AI solution safe for our company’s data?

The most common concern we hear is not the price. It is the question of where the data goes.

The data remains yours.

All intellectual property created during the project, and all the data we process, belongs to you. This is set out in the contract, not just on trust.

Processing takes place where it makes sense.

Kjer to zahteva narava podatkov, tečeta obdelava in model znotraj tvoje infrastrukture ali v EU regiji ponudnika. Kje točno, določimo v fazi analize, ni enotnega odgovora za vse projekte.

No training on your data without consent.

We do not use your data to train models that would be used elsewhere. For commercial models, we apply terms and conditions that exclude training on input data.

Access based on the principle of least privilege.

Only those team members who need to access production data are granted access. Access is revoked upon completion of the project.

What the GDPR requires

If a solution processes personal data, we enter into a Data Processing Agreement (DPA) which sets out what data we process, for what purpose, where and for how long. For higher-risk projects, we carry out a Data Protection Impact Assessment (DPIA).

In practical terms, this means three elements that we incorporate into the solution:

  • Traceability

A record of which data was used in which decision

  • The right to erasure

The solution must be able to remove an individual’s data, including from derived structures

  • Minimisation

Only what is strictly necessary for the task goes into the model

What the EU Artificial Intelligence Act entails

For most Slovenian companies, the following applies: an AI solution that you use internally for process automation is most likely not ‘high-risk’ and does not entail onerous obligations. However, it is important to know where you stand.
Current status of deadlines:
Obligation Effective from
Prohibited practices + requirement for AI literacy among employees in effect from 2. 2. 2025
Obligations for general-purpose AI models (GPAI) in effect from 2. 8. 2025
Labelling of synthetic content in a machine-readable format 2. 12. 2026
High-risk systems as defined in Annex III (e.g. recruitment, lending) 2. 12. 2027 (postponed from August 2026)
High-risk systems as defined in Annex I (medical devices, machinery) 2. 8. 2028
What this means for you today: the requirement for employees to be AI-literate is already in effect. If your company uses AI tools, you must ensure that the people using them understand what they are doing. This cannot be put off.
For every project, we carry out a risk classification where we determine which category the solution falls into, and what this means for the documentation. If it turns out that the solution falls into the high-risk category, we’ll let you know at the start, not at the end.

The content on this page is for information purposes only and does not constitute legal advice. For legal advice, guidance on compliance or your obligations in your specific case, please consult a relevant expert.