Offer AI to your clients — on a backend that survives every compliance review
Why AI projects are the business of the moment for service providers
Your clients want AI — and don't dare. Between the GDPR, US cloud concerns and shadow AI in the team (staff have long been using private chatbot accounts), there is a project lying idle at your existing clients that you, as their trusted IT partner, are best placed to unlock: the official, compliant AI setup. Rollout, policy, integration, operations — recurring service instead of a one-off project. The only question is which backend you standardise on. You make that decision once — and then defend it in every compliance review your clients run.
The DPA chain: who is what here?
The legal structure, set up cleanly: your client is the controller, you are the processor, PrivatAI becomes your sub-processor (Art. 28 (2), (4) GDPR). For that we provide the building blocks publicly and verifiably: a DPA under Art. 28 GDPR including documented sub-processors (Hetzner/DE, Scaleway/FR — core processing entirely within the EU) and technical and organisational measures. Your data protection officer — and your client's — can read everything before anyone signs a contract. That is precisely the difference between "the provider says GDPR-compliant" and "we can prove it".
The special case few backends cover: clients who are professionals bound by secrecy (law firms, tax advisors, medical practices — § 203 StGB). A standard DPA is not enough here; the confidentiality chain has to reach the service provider. PrivatAI brings the undertaking on professional secrecy (including the instruction required by § 203 (4) StGB) as a ready-made annex — and, for elevated requirements, an Enterprise setup with a § 203 commitment across the entire processing chain and German inference hosting. If your client base sits in the regulated mid-market, that is your argument against any US backend.
OpenAI-compatible: migration by swapping the endpoint
Your existing client solutions — chatbots, RAG setups, internal tools, agents — most likely speak the OpenAI interface. Moving to PrivatAI is therefore not a rebuild but a configuration step: swap the endpoint and API key, test, done. You keep your codebase, your frameworks, your workflows — and gain a backend where inputs and outputs are discarded after processing: no content logs, no training on client data, no body of data that becomes your client's problem (and therefore yours) in an incident.
What you can actually offer with it
- "Official AI tool" as a managed service: roll out the PrivatAI chat at the client, add an AI policy, training, operations — the answer to shadow AI, as a recurring service.
- Client-specific solutions via the API: document summarisation, email assistance, internal knowledge tools, automations — on a backend that survives the compliance review.
- AI features inside your own products: if you build software for your industry, PrivatAI becomes the AI layer inside it — GDPR compliance turns into a feature of your product.
- Advisory with substance: introducing AI in the regulated mid-market is half a data protection question. With a demonstrably compliant backend you sell answers instead of caveats.
PrivatAI as a backend, compared
| Criterion | PrivatAI | US API ("EU region") | White-label chatbot platforms |
|---|---|---|---|
| Content storage | None — processed and discarded | Usually 30-day retention | Platform-dependent |
| DPA chain for service providers | Yes, publicly verifiable | Yes, but US parent company (CLOUD Act) | Sometimes |
| § 203 chain for secrecy-bound clients | Yes (Annex 4; Enterprise: whole chain) | No | No |
| Building blocks | API and ready-made chat | API only | Ready-made bot only |
| Flexibility for your own solutions | Full (OpenAI-compatible API) | Full | Limited (toolkit) |
| Provider | German company | US corporation | Mixed |
PrivatAI (privatai.com) — AI chat & API from Germany. No content logs, no training on your data, GDPR-compliant.