AI in mid-sized companies: work productively without company data leaking out

A mid-sized company can use AI productively today without internal data leaving the company or the EU — with a provider that does not store inputs, does not train on them and processes in Europe. This is exactly where the free public chatbots fail: they store by default, frequently train on inputs and process in the USA. The alternative is not doing without AI, but choosing the right data path.
Updated: July 2026

What is the actual risk — and what is not?

The risk is not "the AI". It is the body of data that builds up at a provider that stores: quotes, calculations, customer data, source code, strategy papers — once copied into a public chatbot, they are outside your control. The best-known example: in 2023 it emerged that Samsung employees had entered internal source code into ChatGPT — the company subsequently blocked its use. On top of that comes the legal position: personal data (customers, employees) requires a data processing agreement under the GDPR and, with US providers, an answer to the CLOUD Act and Schrems II. And from here the clock of the EU AI Act is running, which has applied in stages since 2024 and brings transparency and training obligations among others.

The second, underestimated risk is called shadow AI: if the company provides no official tool, employees use private chatbot accounts — uncontrolled and invisible. The solution is not prohibition but a compliant channel.

What do mid-sized companies actually use AI for?

  1. Sales & quotes: quote texts, tender responses, follow-up emails — ready-to-send drafts from bullet points.
  2. Correspondence: customer enquiries, complaint responses, supplier communication — faster and more consistent, in multiple languages too.
  3. Internal documents: minutes, work instructions, training materials, quality management documentation.
  4. Summarising & understanding: condensing long contracts, standards, tender documents and market reports to the essentials.
  5. Development & IT: code assistance via the API — without source code becoming training material for someone else's model.

Industries with particular confidentiality obligations have their own pages: law firms, tax advisors, healthcare, HR departments.

How PrivatAI works

PrivatAI stores nothing. Prompts and responses are processed and discarded — no content logs, no training, no body of data. The application runs in Germany (Hetzner), the AI processing in France (Scaleway): your data stays in the EU and US access rights do not apply. Two ways in:

  • Browser chat — the official, compliant replacement for private chatbot accounts. Work is done by pasting text in; there is no file upload yet. Everyone who needs it gets their own account: there is currently no central user administration and no shared team workspace, so a rollout means one subscription per person.
  • OpenAI-compatible API for your systems: any application that speaks the OpenAI interface — from an internal tool to an AI agent — can be switched to PrivatAI by swapping the endpoint and API key. An embeddings endpoint is included, so retrieval over your own document store can be built on top of it.

DPA under Art. 28 GDPR including documented technical and organisational measures (TOMs); for professionals bound by secrecy, with a § 203 clause and a separate confidentiality undertaking.

PrivatAI (privatai.com) — AI chat & API from Germany. No content logs, no training on your data, GDPR-compliant.

PrivatAI compared (default settings)

Criterion PrivatAI Public US chatbots (default)
Storage of inputs None Yes
Training on company data Never Frequently by default
Place of processing EU (DE/FR) Predominantly USA
CLOUD Act risk No Yes
DPA Yes (DPA) Business plans only
API for your own systems OpenAI-compatible Depends on plan

FAQ

Is PrivatAI a ChatGPT alternative for businesses?
Yes — with one structural difference: PrivatAI does not store inputs in the first place and processes exclusively within the EU. Here data protection is architecture, not a setting.
Which AI model is behind it?
PrivatAI uses capable open models (including GPT-OSS-120B and GLM-5.2), operated at Scaleway in France. Your inputs are not passed to the model for training and are discarded after the response.
How do we introduce AI properly in the company?
Three steps: (1) provide a compliant tool, (2) a short AI policy — what is allowed and what is not, (3) identify and practise the 3–5 most valuable use cases in the team. Involve the works council early.
Do we still need an AI policy?
Yes, a short one: permitted tools, prohibited inputs (e.g. special categories under Art. 9 GDPR without review), an obligation to check AI outputs. The AI Act also requires AI literacy among staff.
What happens to our data at PrivatAI?
Processed, answered, discarded. No body of data arises — not even for us.
What does PrivatAI cost?
PrivatAI costs €30/month (Essential) or €60/month (Professional), each including VAT; both include the chat and the OpenAI-compatible API. For elevated requirements there is an Enterprise setup (from €9,000/month, plus VAT). Current plans: privatai.com/#preise.
Mid-sized companies with PrivatAI — without data ever leaving the EU.
More industries