Safety and privacy
At AI voor Impact we take safety and privacy very seriously. Our AI assistants are designed to comply with current laws and regulations, including the EU AI Act and the GDPR, and are built with several layers of technical security.
Our approach
Our chatbots consist of two components: the frontend and the backend.
Frontend
The chat interface that runs on the website where it is placed. The interface is loaded with a code snippet and runs in an isolated Shadow DOM environment. This keeps the chatbot fully separate from the rest of the website: no style or script conflicts and no access to sensitive elements of the page.
Backend
The software of the chatbot itself, hosted on Google Cloud Platform in Europe (region west-4). To generate answers we use AI models that work together with checked sources of knowledge, for the most accurate answers. Which model is used is up to the client, and it is easy to switch.
Laws and regulations
The use of artificial intelligence within the European Union is regulated by the AI Act (Regulation (EU) 2024/1689). This framework is designed to make use of the opportunities of AI while protecting people's health, safety and fundamental rights, by classifying AI systems according to their level of risk.
AI systems are divided into several risk categories:
Our AI assistants fall within the limited risk category because they are mainly informative and educational. They give answers based on checked sources of information and are open about being AI. This means that the assistants take no decisions that have direct medical or legal consequences or that affect fundamental rights.
Our measures
To make sure that our chatbots work in line with the AI Act and the GDPR, we take the following measures:
Transparency
The chatbot tells users that they are communicating with an AI system, in line with Article 50 of the AI Act. The chat menu has a link to the privacy statement, which explains what happens to the chat messages.
Data protection
The chatbot processes personal data in line with the GDPR (EU 2016/679). We safeguard the confidentiality and security of users' data. The chatbot does not ask for personal details and does not link user interactions to login systems. If a user does share personal data, it is removed automatically from the stored messages using Google Cloud Sensitive Data Protection (DLP).
Data processing agreement
Under the GDPR, a data processing agreement is required when an organisation has personal data processed by another party. Chat messages count as personal data when the user shares information about themselves. We sign a data processing agreement with every client.
Automatic deletion of data
Conversations are deleted automatically after a configurable retention period (365 days by default). This is done by a built-in TTL (time-to-live) mechanism at database level, with a daily clean-up process as an extra safeguard. There is also a GDPR deletion endpoint for immediate deletion on request (the right to be forgotten).
Technical security
Our platform is built with several layers of technical security, from the infrastructure to the application.
Encrypted transport (HTTPS/TLS)
All communication between the chat interface and our servers goes over encrypted HTTPS connections. We apply a strict HSTS policy (HTTP Strict Transport Security) that prevents unencrypted connections.
Isolated service architecture
Each component of our platform runs as a separate service with its own service account and minimal permissions (the principle of least privilege). Tools and sources of knowledge can only be reached internally and are not accessible from the public internet.
Security headers
All services send security headers, including Content Security Policy (CSP), X-Content-Type-Options and Referrer-Policy. These headers protect against common web vulnerabilities such as cross-site scripting (XSS) and clickjacking.
Prompt injection prevention
User input is checked automatically and neutralised for known injection patterns. We also monitor the output of the AI model for unwanted patterns, such as leaking system instructions or echoing malicious input.
Rate limiting
The platform protects against overload and misuse by limiting the number of requests per user. This prevents a single user from overloading or misusing the system at the expense of other users.
Ownership validation
Each conversation is linked to a specific assistant. With every request, the platform checks that the conversation belongs to the right assistant, which prevents access to conversations across assistants.
Secrets management
Sensitive configuration such as API keys and authentication secrets is stored in Google Cloud Secret Manager and is never visible in code or configuration files.
PII redaction
Personal data (such as names, email addresses, phone numbers, Dutch citizen service numbers (BSN) and IBAN numbers) that users enter by mistake is detected automatically and removed before storage, using Google Cloud Sensitive Data Protection (DLP).
Monitoring and logging
All services produce structured logs with tracing (OpenTelemetry). Security events such as injection attempts and unauthorised access attempts are logged for analysis and follow-up.
Infrastructure
Google Cloud Platform
Our platform runs entirely on Google Cloud Platform in the European region (europe-west4, the Netherlands). All storage and infrastructure is within the EU. To generate answers we use the OpenAI API, for which a data processing agreement (DPA) is in place. Under the OpenAI API policy, data is not used to train models. We use managed services such as Cloud Run, Firestore and Cloud Storage, which meet Google's highest security standards.
Our own infrastructure
We host all chatbots on our own cloud infrastructure, managed as Infrastructure as Code (Terraform). This gives us full control over the configuration, security and compliance of our services.
Checked knowledge base
The knowledge base behind each assistant is well structured, verified and updated regularly. Answers are generated from these checked sources, not from random sources on the internet.
Continuous monitoring
User interactions are checked systematically. Through a management dashboard we monitor conversations and feedback to keep improving the quality and safety of the assistants.
Questions or more information?
If you have questions about specific aspects of our technical infrastructure or compliance measures, please get in touch.
Get in touch