HomePrivacy and GDPR

Resource / Privacy

Clarify privacy before the AI project - not after.

Most AI projects stall not on technology but on unanswered privacy questions. This page is not legal advice, but a practical checklist of what you and the vendor must clarify before anything is built.

Last updated: September 17, 2026

Who is the controller?

First clarify who decides purposes and means - usually you as customer. The vendor normally processes data on your behalf, which calls for a data processing agreement before personal data is shared. It should be signed before the pilot sees real data.

Minimise data from the start

Give the pilot as little data as still proves value: a scoped sample, anonymised examples, or synthetic data where it suffices. The less personal data the pilot sees, the simpler agreements and risk become.

Sensitive data needs its own setup

Health, religion, politics, biometrics, and children's data carry special rules. If the workflow holds such data, say so in the first message - then we set up anonymisation, access control, and logging before anything else.

How Aprex clarifies this with you

Before building, we map data sources, roles, approvals, and risk together with you. Sources stay visible, humans approve where errors matter, and automatic content is labelled. If the case is too risky for AI, we say so - even when it costs us the assignment.

Privacy checklist

Clarify this before the vendor sees real data.

Responsibility

Who is controller, and who is processor?

Data

Which personal data is needed - and what can be anonymised?

Access

Who sees the data at the vendor, and how is it logged?

Storage

Where is data stored, for how long, and how is it deleted?

Approval

Where must humans approve before AI acts?

Pilot method

See how a safe 2-6 week AI pilot is scoped.

Privacy FAQ

Can we use anonymised data in the pilot?

Often, yes. A scoped or anonymised sample suffices in many pilots. Tell us what you have and we will propose a setup proving value with minimal personal data.

Do we need a DPA before the pilot?

Yes, if the vendor will process personal data on your behalf. It should be signed before real data is shared - raise it in the first meeting.

What if the case is too risky?

Then we say so and propose alternatives - narrower scope, more human control, or not doing it. A pilot should reduce risk, not move it.

Is this page legal advice?

No. This is practical guidance from a software team. When in doubt on interpretation, use a DPO or lawyer.

Open about limits

We gladly build AI where privacy can be handled properly - and advise against it where it cannot. Ask us what you are unsure about; rather one honest no than a pilot that dies in legal review.

Unsure about privacy in your case?

Describe the workflow and which data is involved. We answer honestly whether it can be solved safely.

Contact Aprex