Security & compliance

Trust is part
of the architecture.

EU hosting, GDPR, AI declared under the EU AI Act, no training on your data, and a team that always stays in control. For every vertical, without exception.

Our commitments

Eight principles, non-negotiable.

They apply to Novo Estate, to TableAgent and to every custom project.

01

EU hosting

Data hosted in the European Union. Transfers outside the EU are covered by standard contractual clauses.

02

GDPR

Collection limited to what is needed, data subject rights respected, deletion on request.

03

No training

Your conversations are used to answer your customers. They never train a model.

04

Declared AI

In line with the EU AI Act, our products always introduce themselves as AI assistants.

05

Human in the loop

As soon as a request falls outside the agreed scope, the team takes over with the full context.

06

Encryption

In transit and at rest, strong authentication, least-privilege access.

07

Isolation

Data is separated by client and, within a group, by entity or venue.

08

Minimisation

We only collect what the task requires. Deletion on request.

Human in the loop

The AI never decides in your place.

An unusual request, a sensitive situation, an out-of-scope question: the team takes over.

  1. 01You decide what the AI handles
  2. 02It hands over to the team as soon as a request falls outside the agreed scope
  3. 03Every handed-over request arrives with its full context
  4. 04Your team can take over any conversation
  5. 05Your business rules apply to every answer
  6. 06Every action is visible in your software

FAQ

Your CIO’s questions.

Where is our data hosted?+

In the European Union. The few transfers outside the EU are covered by the European Commission’s standard contractual clauses.

Is our data used to train models?+

No. Your conversations and data are only used to answer your customers and carry out the agreed tasks.

Do our customers know they’re talking to an AI?+

Yes. Our products introduce themselves as AI assistants, as the EU AI Act requires. They never pretend to be a team member.

Can we take over a conversation?+

At any time. Your team can take over any conversation, and the AI hands over on its own as soon as a request falls outside the agreed scope.

How do we delete data?+

On simple request, in line with the GDPR. Data subject rights are respected.

Who has access to the data?+

Only the people who need it to run the service, with strong authentication and least-privilege access.

Contact

Let’s talk it through with your CIO.

Twenty minutes with you, and your CIO or legal counsel if you wish. We answer every question.