EU Compliance

Designed for
the GDPR.

Most AI tools promise compliance. lynox keeps data on your infrastructure — so there's less to promise in the first place.

Choose where
the AI runs.

Anthropic Direct US
USA

Default. Fast, full model access. Data transits US servers.

AWS Bedrock EU-safe
Frankfurt (eu-central-1)

Claude in the EU. No transatlantic transfer. AWS EU entity as processor.

Google Vertex AI EU-safe
Belgium (europe-west1)

Claude via GCP. EU data residency. Google EU entity as processor.

Mistral EU-safe
Paris, France

French company. Own models, native tool calling. No US parent, no CLOUD Act.

Scaleway EU-safe
Paris, France

18+ open-source models. French cloud provider. Very affordable.

Nebius EU-safe
Finland / Netherlands

60+ models, EU infrastructure. 99.9% SLA.

Local Model EU-safe
Your hardware

Run LLaMA, Qwen, or Mistral locally. Zero data leaves your network.

Article by article.
Covered.

Art. 5 — Data minimization

lynox only sends conversation context to the AI provider. No bulk data export, no background sync.

Art. 17 — Right to erasure

Delete the SQLite file. Or delete specific entities via the Knowledge Graph UI. Immediate, complete, verifiable.

Art. 20 — Data portability

Your data is SQLite files. Copy them. Read them with any SQLite tool. No export request, no 30-day wait.

Art. 25 — Privacy by design

Self-hosted architecture. No telemetry. Encrypted vault. Permission-based tool access. Not a policy — a design decision.

Art. 28 — Processor agreements

Your AI provider is the only processor. You sign their DPA directly. Self-hosted lynox is software on your server — no DPA with us needed.

Art. 44–49 — International transfers

Use Bedrock Frankfurt or Vertex Belgium. Your data stays in the EU. No SCCs needed, no transfer impact assessment.

No US jurisdiction
over your data.

The CLOUD Act lets US authorities request data from US companies — regardless of where the data is stored. This affects every US-headquartered SaaS you use.

With lynox + AWS Bedrock Frankfurt: your server is in the EU, your AI runs in the EU, and your AI provider's EU entity processes the data. This minimizes US jurisdiction exposure, though AWS Inc. (US parent) remains in the corporate chain.

This is not legal advice. Consult your DPO or legal team for your specific compliance requirements.

Give this page
to your legal team.

Then set up lynox with Bedrock Frankfurt. The architecture speaks for itself.

Get started →