EU Data Protection and AI Compliance at a Glance
••
Change history (1 entry)
- 11/08/2026Initial publication.
Everything an information security, data protection or procurement review needs, on one page.
| Item | Detail |
|---|---|
| Entity | LoyJoy GmbH, Kapuzinerstr. 20, 48149 Münster, Germany. HRB 17049, Amtsgericht Münster. |
| Processing location | Personal data is processed exclusively in the EU, on Google Cloud EMEA infrastructure through Google Ireland. |
| AI inference, default path | Gemma 4 on hardware owned by LoyJoy in a data centre in Münster. No third-party model provider involved. Same for embeddings, summarisation, sentiment and topic analysis. |
| Optional model providers | Azure OpenAI in EU regions, Mistral (FR), Scaleway, Nebius, OpenAI. Used only on explicit customer instruction and inactive while the default path is in use. Annex 2 states each location and safeguard. |
| Phone Agent speech-to-speech | Runs in Azure OpenAI’s EU Data Zone. No third-country transfer occurs for this processing; a separate supplementary DPA covers the Phone Agent. |
| Bring your own key | With your own Azure OpenAI subscription, the model provider is your processor under your own contract, not a sub-processor of LoyJoy. |
| Legal basis | Data Processing Agreement under Art. 28(3) GDPR. Annex 1: technical and organisational measures under Art. 32. Annex 2: sub-processor list. |
| Audit right | On-site audits are possible with reasonable prior notice, during business hours, without disrupting operations. |
| Sub-processor changes | Four weeks’ advance notice, two weeks to object. |
| Training exclusion | Contractual, in the DPA: personal data “shall not be used for the training, development, fine-tuning, or other further development of AI or machine learning models.” Inputs are transmitted in real time to generate a response, and nothing else. LoyJoy performs no fine-tuning, so Google remains the GPAI provider of Gemma 4. |
| Retention and deletion | Configurable per tenant from 7 to 720 days, enforced by irreversible deletion. Phone transcripts and recordings 30 days by default. Audio streams are not persisted. Manual deletion and Art. 17 handling documented. |
| Encryption | TLS in transit without exception, AES at rest, key management held outside the cloud provider’s configuration. |
| Identity | Passkey (FIDO2) or magic link. Microsoft Entra ID SSO in all plans. OAuth for end users in chat from the Professional plan. |
| Authorisation and evidence | Around twenty roles, separated tenant data spaces, archived administrative audit logs with alerting. Programmatic access including MCP is governed by the same role model; tokens are revocable at any time. |
| Resilience and incidents | RTO 4 hours, RPO 24 hours, documented recovery plan with an on-call rota. Art. 33 breach process with a 72-hour deadline. |
| EU AI Act | Limited risk. LoyJoy is provider of the system, the customer is deployer. Art. 50 transparency in force since 2 August 2026 and implemented in chat and phone. Synthetic-audio disclosure implemented ahead of the 2 December 2026 deadline. |
| Certifications and testing | Hosted exclusively on ISO 27001 and PCI DSS certified infrastructure (Google Cloud EMEA). LoyJoy’s own information security management follows the BSI IT-Grundschutz-Kompendium and ISO/IEC 27001:2022, with certification as a stated objective. Annual external penetration test by an accredited provider, OWASP Web Security Testing Guide methodology, certificate available on request. Information security officer: Dr. Ulrich Wolffgang, CTO. |
| Accessibility and DORA | BFSG declaration of conformity, EN 301 549, WCAG 2.1 AA. DORA contract terms with audit rights and reporting from the Enterprise plan. |
No separate box on certification status is needed: the infrastructure is certified, and LoyJoy’s own ISMS follows the standards, with certification as a goal. Anyone who needs the distinction will find it in the “Certifications and testing” row above.
Documents
- DPA (Data Processing Agreement)
- DPA Annex 1: Technical and Organizational Measures
- DPA Annex 2: Sub-Processors
- IT & Data Security Measures of LoyJoy Platform
- Assistance with Data Protection Impact Assessment
- Brief Statement on the EU AI Act
- Supplementary DPA for the LoyJoy Phone Agent
- BFSG EU Declaration of Conformity
- Platform Service Description
- Terms and Conditions
Questions?
Questions from information security, data protection, procurement or AI governance are usually resolved faster in one shared call than in writing over several rounds. The CTO and information security officer join that call.
Contact: ulf.loetschert@loyjoy.com, +49 170 4444 121.