Adaptrix is fully committed to compliance with the General Data Protection Regulation (GDPR). We have implemented comprehensive technical and organizational measures to protect personal data and ensure the rights of data subjects are respected.
Adaptrix has completed a comprehensive self-assessment demonstrating compliance with GDPR requirements. Our implementation includes automated data subject request handling, encryption at rest and in transit, and comprehensive audit logging.
View Self-Certification DocumentThe GDPR provides you with specific rights regarding your personal data. Below are your rights and how we help you exercise them.
You have the right to obtain confirmation as to whether your personal data is being processed and access to that data.
You have the right to have inaccurate personal data corrected and incomplete data completed.
You have the right to have your personal data deleted when it is no longer necessary or you withdraw consent.
You have the right to restrict processing in certain circumstances, such as when accuracy is contested.
You have the right to receive your personal data in a structured, commonly used, machine-readable format.
You have the right to object to processing based on legitimate interests, including profiling and direct marketing.
To exercise any of your rights under GDPR, you can submit a request using the methods below. We will verify your identity and respond within the statutory timeframe.
For online requests, please use our secure form. We will verify your identity and respond within the statutory timeframe.
We only process personal data with a valid legal basis under Article 6 GDPR.
We collect only the data necessary for the purposes specified.
Encryption, access controls, and audit logging are built into our platform.
We notify affected parties and supervisory authorities within 72 hours of a breach.
We conduct DPIAs for high-risk processing activities.
Primary data processing occurs in Frankfurt, Germany within the EU.
Provable, not just promised
Adaptrix runs self-hosted open models on its own sovereign EU infrastructure in Frankfurt, Germany. Your data is never sent to a third-party AI provider to be answered — the AI comes to the data, not the other way around.
EU data residency. Processing on Adaptrix-operated infrastructure in the EU keeps transfers simple: no third-party AI sub-processor outside the EU sits in the answer path.
Accountability (Art. 5(2)) needs evidence, not assurances. Every question, source read, answer and viewer is written to an immutable, hash-linked audit trail — each block carries the previous block’s hash, so any tampering breaks the chain and is detectable.
How the hash-linked audit trail is built — illustrative hashes.
For any questions regarding data protection or to submit a request:
legal@adaptrix.aiAdaptrix
Palma, Illes Balears, Spain