Data sovereignty & compliance

Your data. Your server. Your control.

Data protection under the GDPR, document storage under GoBD.

Nothing is passed on to unauthorized third parties. AI accounts configured so your data is not released for model training.

For trade businesses and companies with an ERP system, sensitive business data, customer addresses, invoices and cost calculations are the most valuable asset. That is why we set up your assistants on your own server, sign a data processing agreement (DPA, AVV in German) under Art. 28 GDPR with you in advance and make sure no document is sent without your approval. The server runs in your name with a provider in the EU or Switzerland (EU adequacy decision), under that provider's own DPA; you can change the provider without asking us.

Small server in a lockable office cabinet, key in the lock

How we protect your data

Technical and organizational measures at a glance

Dedicated server in the EU or Switzerland

Every company gets its own server in its own name, in a German data center, elsewhere in the EU or in Switzerland, or on-premise in its own infrastructure. Certifications (for example ISO 27001) are issued to the data center operator, who shows them on request; METLAGO holds no certification of its own. Contract with METLAGO under German law.

DPA under Art. 28 GDPR

Before the pilot starts, we sign a DPA with you. It sets out the technical and organizational measures (TOMs). The server provider and the AI provider have their own DPAs, which you sign as the company; we list them in the annex.

No training on your company data

The AI accounts run in your name. We set them up so that the use of your data for model training is switched off, and record the setting in the DPA annex.

Note: with consumer subscriptions of the AI provider, training has been on by default since 2025; switching it off is part of our setup and is checked at handover.

Human-in-the-loop approval

The system prepares decisions, emails, invoices and journal entries, but never carries out binding external actions on its own. You or your staff always keep the final approval.

Full audit trail

Prepared for tax advisors and auditors

  • Complete logging of all system actions.
  • Traceability: every receipt shows its source, when it was read and which checks were made.
  • Roles and permissions: staff see only the job sites and receipts they are authorized to access.
  • Document storage under GoBD: the original is stored unaltered, every change is logged, and everything can be exported for your tax advisor and for tax audits.

Messenger as the inbox: what Telegram means

Telegram is the inbox, not the storage

  • Photos and voice notes pass through Telegram's servers; Telegram does not sign a DPA and does not disclose where its servers are. The bot picks up every message immediately, stores it on your server and deletes it from the chat.
  • If you do not want that, use the web app or email forwarding as the inbox; the rest of the system stays the same.
  • In its first message the bot states that an AI system is answering (Art. 50 EU AI Act).