Compliance by design
Built for GDPR and the EU AI Act
INSTRAT360 helps executives build governed AI strategies, so compliance and information security are part of the product — not an afterthought. This page explains the controls we build in and the frameworks we design against.
Last updated: March 2026
An honest note on “compliance”
Full regulatory compliance cannot be guaranteed by software alone. It depends on the application, its deployment, the contracts in place, operating procedures and each specific customer use case. INSTRAT360 provides a compliance-ready foundation. Before any customer processes real executive or personal data, we require a formal Data Protection Officer, legal and security review for that deployment. We describe what we are built for — we do not assert blanket compliance on your behalf.
Trust at a glance
Key facts about how we operate.
- Controller
- INSTRAT Technology ApS (Denmark)
- Hosting
- AWS EU regions (EEA preference)
- AI training
- Customer data excluded by default
- Human control
- Approval required for consequential actions
- Frameworks
- GDPR · EU AI Act · NIS2 · Data Act
- Enterprise
- DPA & subprocessor register available
Data protection & GDPR
GDPR applies whether processing is performed by a person or by AI. INSTRAT360 is designed around the regulation's core obligations.
- Clear controller/processor roles, with a Data Processing Agreement available for enterprise customers.
- Data minimisation and purpose limitation — we process workspace data only to deliver the service.
- Explicit retention rules for chats, files, memory, generated outputs and audit records.
- Support for access, correction, export and deletion of personal data.
- Tenant isolation and least-privilege access across the platform.
- A subprocessor register with change notification for enterprise agreements.
- EEA processing preference, with valid transfer safeguards where data leaves the EEA.
- DPIA support for high-risk personal-data processing, and an incident process aligned to the 72-hour notification requirement.
AI governance & the EU AI Act
Every AI capability in INSTRAT360 is built to be transparent, accountable and human-supervised — designed for the EU AI Act's transparency obligations (Article 50) ahead of their application.
- AI interaction and AI-assisted outputs are clearly identified in the product.
- AI recommendations stay visually distinct from verified facts and deterministic calculations.
- The AI cannot approve its own work — consequential actions require explicit human approval.
- Users can stop, override and correct AI output at any point.
- Each capability records its intended purpose, provider, model version, data categories, sources and human owner.
- Prohibited uses are blocked, and high-risk personal decisions (e.g. employment or creditworthiness) are not enabled without a separate high-risk assessment.
Executive & financial controls
Because CEOs and CFOs work with sensitive business information, numeric integrity and traceability are part of the product.
- Financial calculations use deterministic functions — not model guesses.
- Forecasts, assumptions and data-as-of dates are shown alongside the numbers.
- Narrative, tables and charts draw from identical canonical values.
- Every recommendation retains its sources and calculation method.
- Read-only integration access is the default; external writes require explicit approval.
- Approved reports and decisions are reproducible, with an audit trail of who asked, what the AI proposed, what changed, who approved and what executed.
Security & resilience
Our security baseline is designed to be NIS2-aligned, with a financial-services overlay available where DORA applies.
- Strong authentication, multi-factor support and role-based access control.
- Complete tenant separation and encryption in transit and at rest.
- Secure secrets handling, dependency and vulnerability management.
- Audit logs protected from ordinary modification.
- Backup, restore and disaster-recovery practices.
- Incident detection and response, with penetration testing and supplier/model-provider risk review before production use with real data.
Customer control & portability
You stay in control of your data — supporting the EU Data Act's switching and portability expectations.
- See where data is stored and which providers, subprocessors and integrations are active.
- Control retention and memory, and disable a model, tool or automation.
- Export source files, artifacts, audit history and relevant metadata.
- Remove integrations and credentials, and delete a workspace with confirmation.
- Reproduce an approved decision or deliverable — no lock-in to inaccessible data.
Frameworks we design against
We track the EU regulatory landscape and design for these obligations ahead of their application dates.
Data protection & security contact
For DPAs, our subprocessor register, security documentation, or to exercise a data-subject right, contact ale@instrat360.com. Enterprise customers can also review data controls inside the app under Settings → Trust & Governance.