Geodd’s GDPR-Ready Approach | Geodd
Geodd’s GDPR-Ready Approach to AI Inference
Back to Updates
Uncategorised

Geodd’s GDPR-Ready Approach to AI Inference

Bartosz Neuman
June 18, 2026

Geodd is a GDPR-ready AI inference provider focused on data minimization and secure processing. It does not store standard API prompts, outputs, request/response bodies, or customer datasets, and API data is not used for training or human review. Geodd retains only limited operational metadata and supports EU infrastructure, DPA terms, security controls, and GDPR rights requests.

For teams building AI products, privacy is no longer something to think about after launch. The way inference infrastructure handles data matters from the beginning, especially when products serve customers in the EU, EEA, or UK.

Geodd has been built with that reality in mind. Our GDPR-ready approach focuses on reducing unnecessary data exposure, giving customers clearer control over where inference runs, and supporting the legal and operational requirements expected from a production AI infrastructure provider.

At the center of this approach is data minimization.

For standard API inference, Geodd does not store API prompts, inputs, outputs, completions, request bodies, or response bodies. Uploaded files and fine-tuning data are not supported for this service, and customer datasets are not stored. API data is not used for training, and prompts or outputs are not reviewed by humans.

This matters because AI infrastructure often touches sensitive business context, product logic, customer messages, internal workflows, or user-generated content. Reducing what is stored reduces the long-term privacy and security risk for customers using the platform.

Geodd only keeps limited operational metadata needed to run the service, such as the model used, timestamp, token count, status code, and usage records. This supports billing, reliability, abuse prevention, debugging, and security without storing the actual prompt or completion content.

Security is also part of the foundation. Geodd uses safeguards such as encryption at rest, TLS protection in transit, API key hash storage, role-based access controls, MFA for admin access, firewalls, access logging, vulnerability management, incident response processes, and staff confidentiality obligations. Access is limited based on job role and operational need.

For customers with EU requirements, Geodd supports inference through EU data center infrastructure. Customers may also choose non-EU infrastructure where appropriate, in which case requests are routed outside the EU/UK under the applicable contractual and transfer safeguards.

Geodd also maintains the legal and operational documents customers expect when assessing a processor. This includes a Data Processing Agreement framework, defined retention periods, subprocessor review practices, breach notification processes, and support for GDPR and UK GDPR rights requests.

Geodd’s role is also clearly separated. We act as an independent controller for our own business data, such as account, billing, support, security, and administrative records. When customers submit personal data through the API for inference, Geodd generally acts as a processor and handles that data under the customer’s instructions.

For AI teams, this creates a more practical path to production. Instead of treating GDPR as a separate legal layer, Geodd’s infrastructure approach starts with minimizing what is stored, limiting access, protecting operational systems, and giving customers clearer choices around infrastructure and data handling.

GDPR readiness is not only about documents. It is about how the service is designed, what data is retained, who can access it, where processing happens, and how customers are supported when privacy questions come up.

That is the standard Geodd is building toward: production AI inference that is efficient, predictable, and designed to reduce unnecessary customer data exposure.