Client data in private accounts
Staff paste extracts from client files into free chatbots. Where that data ends up and how long it is kept, nobody knows.
For Dutch small and mid-sized companies
Your staff work with AI on your own documents, within the rights of their department. You keep the keys, the log and the AI register the AI Act asks of you in your own hands.
Data in EuropeRights per departmentStart with an AI audit
The return was deferred by a year in March, in consultation with the client. The agreement is in the meeting notes of 14 March.
Source, Jansen BV fileThat is not down to unwillingness. It happens by itself, someone tries a free chatbot, it works, and six months later there is client data sitting in private accounts.
Staff paste extracts from client files into free chatbots. Where that data ends up and how long it is kept, nobody knows.
One person pays for ChatGPT on their own credit card, another uses nothing at all. Whoever leaves takes their account and all their conversations with them.
If a client or an auditor asks what you do with AI, nobody has the answer written down. Since 2 August 2026 the AI Act expects that of you.
Your staff get a better AI environment than the one they had on their own. You get the grip you were missing. Nobody has to keep records.
Staff log in to one environment and work there with the models from OpenAI and Anthropic. No separate accounts, no private keys, no credit cards.
Connect document collections per department, by upload or straight from Google Drive and SharePoint. The AI answers from your own files, and the models do not train on your data.
Tax sees tax files, payroll sees salary data. Anyone who may not reach something cannot reach it through the AI either.
The model providers' keys sit centrally in the environment and never end up on a laptop. If someone leaves, you switch off one account.
Every use gets a log entry. The register shows which applications run, with which models and sources, and under whose responsibility. Export as PDF or CSV, for a client or an auditor.
That is the difference with the American providers of this kind of tooling. Everything we see of you stays within the EU.
The environment and the database sit in a data centre within the EU. Your documents, the rights per department, the record of use and the register do not leave Europe.
The question itself goes to the model of the provider you choose. Choose a European region at OpenAI or Anthropic and that step stays in Europe too. Choose an American one and the register shows you which departments and sources that concerns.
By default we record per conversation only that it took place, the moment, the department, the model and the sources used. Content is recorded only if you switch that on. Retention is 90 days by default and you set it yourself. Your documents stay in the environment as long as you want and can be deleted per collection.
Annual accounts, tax files and payroll, separated per department.
Policies and client files as a source for advice and back office, each within their own rights.
Process notes and referrals without anything ending up in a free chatbot.
Not the version with high-risk systems and fines running into tens of millions, but what applies when your company has ten to fifty people. It comes down to two questions, what happens with AI in your company, and who can reach which data through AI.
In the audit we map which AI tools are being used in your office right now, including the ones you did not know about. You get an overview of what is running, where client data goes and what the AI Act makes of that. The result is a report you can use straight away as the first content of your AI register, whether you continue with Noxtrack afterwards or not.
In half an hour we map what already happens with AI in your office and what the environment would look like for you. Rather email first? hello@noxtrack.com
Question not listed? Email hello@noxtrack.com.