Security & data protection
Security and GDPR — private AI that keeps client data in the country
An accounting firm handles its clients’ financial secrets — invoices, bank statements, business data. That is why Kontír AI is built as private AI: it runs on private EU hardware, uses no external AI API, and financial data never leaves the country.
Why is private AI the only defensible way?
Public AI tools work by shipping whatever you upload — a document, a statement, a question — to servers run by foreign cloud providers. For personal use that is a matter of convenience; for an accounting firm it is not. As a data processor, the firm is responsible for its clients’ business and financial secrets — putting them into a system it cannot inspect is a confidentiality problem and a GDPR problem at the same time. Kontír AI answers that dilemma in the simplest possible way: the data never sets off.
A public AI tool
-
Every uploaded document lands on a foreign cloud provider’s servers — from there, the data’s path can no longer be traced.
-
A client’s financial secrets end up in a third-party system the firm has no way to inspect.
-
As a data processor, the firm is liable for its clients’ data — the risk is a confidentiality problem and a GDPR problem at once.
Kontír AI — private AI
-
Runs on private EU hardware — financial data never leaves the country.
-
Data extraction is done by our own AI model — no external AI API, nothing forwarded to an AI provider.
-
DPA, audit trail, data export: the entire processing path is documented and verifiable.
What the firm gets
Data protection you can see in the contract — and in the log.
GDPR compliance
The data path is documented from ingestion to posting suggestion — the system operates to GDPR requirements.
DPA — data processing agreement
A written agreement defines what may happen to the data — and what may not.
Audit trail of every operation
Every processing step is logged and traceable: what happened, when, and to which document.
Data export at any time
The data remains the firm’s own: a complete export is available at any time.
EU hardware
Kontír AI runs on private EU infrastructure — not in a public cloud, not abroad.
No external AI API
Extraction and suggestions come from our own AI model — not a single document reaches an external AI provider.
For the strictest requirements
Enterprise: the data never even leaves the building.
In the Kontír AI Enterprise edition, the entire system — AI models included — runs on the firm’s own server. Full data sovereignty for the most data-sensitive firms: client financial data physically stays on the premises.
An honest word about responsibility.
The AI suggests — it does not post. Every item lands in an approval queue: nothing is booked until the accountant has reviewed and approved the suggestion. Control and professional responsibility stay exactly where clients and the law expect them: with the firm. Kontír AI replaces the manual work, not the accountant.
Bring your firm’s data-protection questions.
At the demo we will show you, point by point, how and where Kontír AI processes your documents — and what never leaves the system.
Related: Private AI vs. cloud AI · Privacy policy