Security & GDPR
Compliance enforced in the architecture.
The GDPR requires demonstrable measures. AVGfilter replaces the behavioural rule 'no personal data into AI' with a technical safeguard inside the processing itself.
Live
See the privacy filter work live
Enter a text containing personal data and see exactly what the AI does and does not see.
Privacy filter, live
Personal data is tokenized before a model sees the text, and restored again once the answer returns.
- Received
- Tokenized
- AI processing
- Restored
- Completed
Input
text from the employeeDetected personal data
Run the filter to see which data gets replaced.
Tokenized version
sent to the modelNo tokenization performed yet.
What the model receives
literal payloadNothing sent yet.
Personal data never leaves the environment; the model only ever sees tokens.
Answer restored
readable for the employeeThe answer is made readable again after processing.
Principles
Principles of the processing
Data minimisation
Only the fields required for the question are sent along. Functional data such as building type or floor area yes, identifying data no.
No personal data in prompts
All input passes the tokenization layer. Documents and intake via email or WhatsApp are tokenized too, before any AI call takes place.
No content in logging
Per AI call we record which categories of personal data were detected and how many, not the content. That makes the processing demonstrable without creating a second copy of the data.
Hosted inside the EU
The filter service runs in the EU (North Europe). The token mapping never leaves the EU.
Retention
Token mappings remain valid for a maximum of thirty days so conversations can be reloaded, and are deleted as soon as a conversation is cleaned up.
No model training on your data
Your input is not used for training. Because the model only receives tokens, there is no personal data available to train on.
Detection
What gets masked
- Person names
- Email addresses
- Phone numbers (+31 / 06)
- National ID (with checksum)
- IBAN account numbers
- Addresses and postcodes
- Company registration numbers
- Locations
Downloads
Documents for your compliance file
For orientation — always have final versions reviewed by your counsel or data protection officer.
Sample data processing agreement
Model document with the processing arrangements for the filter service: nature of the processing, data categories, security measures and sub-processors.
PDF · English
DPIA checklist for AI tools
A practical checklist to prepare a data protection impact assessment for AI usage, from processing description to residual risk.
PDF · English
FAQ