Who it's for
AI and SaaS companies handling personal data — particularly those training on user data, making automated decisions, or selling to enterprise customers with data-protection requirements.
FAQ
We already have a privacy policy — isn't that enough?
A policy is one piece. The harder questions are your lawful basis for using personal data in training and inference, and how you handle automated decisions — which is where most AI products are exposed.
How does GDPR interact with the EU AI Act?
They overlap but aren't the same. The AI Act governs the system; GDPR governs the personal data it uses. AI products usually need both — we make sure they're consistent.