Responsibility
Who is controller, and who is processor?
Most AI projects stall not on technology but on unanswered privacy questions. This page is not legal advice, but a practical checklist of what you and the vendor must clarify before anything is built.
Last updated: September 18, 2026
First clarify who decides purposes and means - usually you as customer. The vendor normally processes data on your behalf, which calls for a data processing agreement before personal data is shared. It should be signed before the pilot sees real data.
Give the pilot as little data as still proves value: a scoped sample, anonymised examples, or synthetic data where it suffices. The less personal data the pilot sees, the simpler agreements and risk become.
Health, religion, politics, biometrics, and children's data carry special rules. If the workflow holds such data, say so in the first message - then we set up anonymisation, access control, and logging before anything else.
Before building, we map data sources, roles, approvals, and risk together with you. Sources stay visible, humans approve where errors matter, and automatic content is labelled. If the case is too risky for AI, we say so - even when it costs us the assignment.
Clarify this before the vendor sees real data.
Who is controller, and who is processor?
Which personal data is needed - and what can be anonymised?
Who sees the data at the vendor, and how is it logged?
Where is data stored, for how long, and how is it deleted?
Where must humans approve before AI acts?
See how a safe 2-6 week AI pilot is scoped.
Read more →We gladly build AI where privacy can be handled properly - and advise against it where it cannot. Ask us what you are unsure about; rather one honest no than a pilot that dies in legal review.
Describe the workflow and which data is involved. We answer honestly whether it can be solved safely.
Contact Aprex →