Compliance

How we handle data and obligations

Everything below is a statement you can hold us to. Where an obligation is only partly met, it says so.

Legal entity

Entity
AM Solutions AB
Org.nr
559584-8044
Registered
Göteborg, Sverige
Tax
Godkänd för F-skatt

Where data is processed

Application data, stored content and generated assets are processed and stored in the EU. Model inference is the exception noted below; where a provider processes outside the EU, transfers rely on Standard Contractual Clauses.

CategoryLocationTransfer basis
Application hosting and computeEU
Databases and vector storageEU
Object storage for generated assetsEU
CDN and edgeEU
Model inference and embeddingsNon-EU (SCC)Standard Contractual Clauses where a provider processes outside the EU

Subprocessors

We act as processor for client data; the client is the controller. Under Article 28(2) GDPR you are entitled to know who processes data on our behalf and to object to a change.

  • The current named subprocessor list is provided under our DPA, on request.
  • We notify clients before adding or replacing a subprocessor.
  • Each subprocessor is bound by terms no less protective than our own.

GDPR

  • Data processing agreement available on request, with Article 28 terms.
  • Data subject requests forwarded to the controller without undue delay, with assistance in responding.
  • Data retained only for the term of the engagement; returned or deleted on termination at the client's choice.
  • Transfers outside the EU rely on Standard Contractual Clauses.

EU AI Act

Article 50(2) of Regulation (EU) 2024/1689 requires providers of systems generating synthetic media to mark outputs in a machine-readable format. It has applied since 2 August 2026.

  • Generated media is marked with IPTC DigitalSourceType and C2PA Content Credentials.
  • We do not build systems classified as high risk under Annex III.
  • Implementation, and its limits, are documented at Article 50 provenance.

Security

  • Secrets held outside application code and outside version control, injected at run time.
  • Encryption in transit and at rest across hosting, storage and databases.
  • Least-privilege access; credentials rotated on personnel or vendor change.
  • Security incidents affecting client data notified without undue delay and within 72 hours.

AI-specific commitments

  • Client data is not used to train models.
  • Zero-retention processing is used wherever a model provider offers it.
  • Generative systems are evaluated before deployment, not only at build time.
  • Published output passes human review; nothing publishes unattended without it.
  • Synthetic media we produce is marked as artificially generated.

Accessibility

Pages are built to WCAG 2.1 AA and EN 301 549, with automated accessibility and performance checks gating every deploy.

Insurance

Professional liability insurance (ansvarsförsäkring) in force.

Requesting documents

DPA, subprocessor list and security details: [email protected].

This page describes our own posture. It is not legal advice, and it does not replace the terms of a signed agreement.