Compliance & confidentiality
AEPUR is built for environments where traceability and confidentiality are non-negotiable. You choose, flow by flow, where your data is processed: without AI, with models running on your own infrastructure, or with an external AI provider named in the contract. The chosen mode is settled during scoping, written into the contract, and every integration into your ERP goes through human validation.
Where your data is processed
Part of our work involves no artificial intelligence at all; another part requires a language model. Depending on the nature of the flow and your own requirements, three modes are available. They coexist: a sensitive flow can stay on local processing while another one uses an external model.
- Without AI. Table synchronisation, structured files, checks and calculations: everything is deterministic. No data leaves your infrastructure, and the result is reproducible exactly.
- Local AI. The models run on your infrastructure or on sovereign hosting, with no outbound calls. This is the right mode for documents you do not want leaving your premises under any circumstances.
- External AI. For difficult documents, a language model hosted by a third-party provider currently reaches an accuracy that local models do not. In that case: the provider is named in the contract, listed as a sub-processor in the data processing agreement, contractually bound not to retain your data or use it to train its models, and the processing location is disclosed to you.
- The choice is yours, and it is reversible. For each flow we document the mode used and its cost. Moving a flow from external to local processing, or the other way round, is a configuration change, not a rebuild.
GDPR
AEPUR acts as a processor under the GDPR: the customer remains the controller. Our role is to carry out processing on their behalf, within the contractually defined scope.
- Access scope defined during scoping. Depending on the flows retained: read access to a dedicated mailbox, to a file repository, and/or to tables in your business system. Every access is listed, read-only by default and limited to what is strictly necessary. Never a blanket access to your email or your database.
- Minimisation. Only the fields needed by the flow are retained. Raw documents and attachments are purged after validated extraction (indicative retention of about 30 days, adjustable to your own retention policy).
- Sub-processors. The hosting provider and, where applicable, the AI model provider are named in the data processing agreement, together with the processing location. No sub-processor is added without prior notice to you.
- Security. Named accounts, least-privilege access, full logging of every extraction, correction and validation, encryption of data in transit.
- Assistance. We support the customer in handling data-subject rights (access, rectification, erasure) and, where relevant, for a data protection impact assessment (DPIA).
- Notification. Any personal data breach is reported to the customer without undue delay.
- Data processing agreement (DPA). A processor agreement template is provided as part of each contract, and discussed during the scoping phase.
AI Act
AEPUR has carried out a classification analysis of its system under Regulation (EU) 2024/1689 on artificial intelligence.
Conclusion: the system is classified as minimal risk. It does not fall into any high-risk category (no automated decisions about natural persons, no HR, credit, biometric or justice processing) and does not involve prohibited practices.
- Systematic human validation. Before any integration into the customer's ERP, an operator validates. The system takes no autonomous decision: it prepares the data.
- Transparency. If a conversational component is added later, it will explicitly announce itself as an AI system.
- Ongoing documentation. For each deployment, we document the models used, their version, their licence and, where they are hosted by a third party, the provider and the processing location. This classification is reviewed as the European regulatory timeline evolves.
Our product commitments
Voluntary measures, beyond the regulatory minimum.
No automatic ERP writes
Only the customer's team pushes validated data. Nothing is written to your systems without validation.
Full traceability
Every extraction, correction and validation is logged and auditable.
You choose the mode
Without AI, local AI or external AI: settled flow by flow during scoping, written into the contract, reversible.
No memory between documents
Each document is processed in isolation. In external mode, the provider is contractually bound not to retain your data or use it to train its models.
Training included
Customer teams are briefed on using the system during the pilot deployment.
An AI Act classification document and a GDPR processor agreement template (DPA) are provided to each customer during contractual scoping.
This page is for information only and does not replace the service agreement and its annexes, which alone govern the relationship between the parties.