Skip to content

AI & data protection

How we handle your data in AI projects.

Plain answers to the questions every AI project starts with: where does the data go, who can see it, and is it used to train models?

On this website: the live AI demos

The demos and the sigmacode Assistant are showcase projects built on Claude by Anthropic.

Processed through the Anthropic API

What you type or upload in a demo is sent from our server to the Anthropic API to generate the answer. It is not sent to any other AI provider.

Not stored by us

We don't save demo inputs or answers in a database or in our logs. To prevent abuse we keep rate-limit counters keyed to your IP address; they expire after at most 24 hours.

Anthropic's commercial terms

Anthropic processes API data under its commercial terms. By default it does not use API inputs and outputs to train its models. It retains them for a limited period, and content flagged in a trust & safety review may be kept longer.

Nothing reaches us without your click

The Assistant can draft a project brief, but it is only sent to us after you add your details, tick the consent box and click Send. The contact details you enter in that card are not sent to Anthropic.

Please don't enter confidential information or other people's personal data into the demos — use the sample files or made-up data.

In client projects

When we build AI features on your data, these principles apply by default and are written into the proposal and the data processing agreement.

  1. 01

    Provider and region chosen per project

    We choose the model provider and region with you, based on your data, compliance requirements and budget: a hosted model API under business terms, a cloud platform with EU data residency, or an open-weight model self-hosted on your infrastructure or in an EU data centre when data must not leave it. We can also work on your own provider account, so the contract and the data stay with you.

  2. 02

    No training on your data

    Your data is not used to train or improve models for anyone else. We only use providers and settings that exclude training on API data. Fine-tuning happens only if you ask for it, on a model that belongs to you.

  3. 03

    Data minimisation

    Only the data the use case needs goes into prompts, indexes and logs. Prototypes run on a representative sample, pseudonymised where possible.

  4. 04

    PII redaction

    Where feasible, personal data such as names, email addresses and phone numbers is detected and masked before it reaches the model or the logs.

  5. 05

    Access control

    Document permissions carry through to retrieval, so the assistant only answers from sources the user may see. Admin and cloud access is protected with MFA and least privilege.

  6. 06

    Careful logging

    Logs are needed to debug and evaluate, but they are personal data too. We agree with you what is logged, redact it and set a retention period.

  7. 07

    Evaluation before go-live

    Every AI feature ships with an evaluation set — answer quality, citation accuracy, refusals and prompt-injection tests — that is re-run on every change.

  8. 08

    Contract and documentation

    A data processing agreement under Art. 28 GDPR, a sub-processor list completed per project and, for transfers outside the EU/EEA, Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.

Common questions

Will our data be used to train AI models?

No. We use providers and settings under which API data is not used for training, and we never use your data to train models for other clients. If you want a fine-tuned model, it is trained for you only and remains yours.

Can the data stay in the EU?

In most projects, yes — through the provider's EU data residency, an EU cloud region or a self-hosted open-weight model. Which option fits is decided during scoping and documented in the sub-processor annex of the DPA.

Can we use our own AI provider account?

Yes. The provider contract, billing, retention settings and data then stay under your control; we work with access that you grant and can revoke at any time.

What should we prepare?

A list of data sources, who may see what, and whether personal or special-category data is involved. Our checklist for scoping RAG and AI assistant projects covers the details.

This page describes how we work; it is not legal advice. Binding terms are set out in the proposal, the data processing agreement and our terms.

Have a project in mind?

Tell us what you're building. You get an honest assessment, a clear scope and a fixed-price or milestone proposal, usually within a few working days.

Prefer to write first? Write to us