For EU public sector organizations

Your governed AI workspace.

Built for public duties and GDPR obligations. Persistent workspace data stays in the European Union, with governed access, data minimization controls, and auditable activity.

The projects list in Feza: each department with its own shared space inside one workspace

A foundation for public sector AI. Four GDPR principles working together.

EU Data Residency

Persistent workspace data is stored in the European Union, with model routes governed by organization policy.

Data Minimization

Only the content required for an approved purpose is made available to the selected model and tools.

Governed Access

Identity, role, membership, and policy are evaluated before every request executes.

Accountability

Requests, sources, approvals, access scope, and generated outputs are recorded for review.

GDPR controls in practice. Enforced by the system, not the AI model.

Purpose First

Approved purposes and permissions are checked before the model replies.

Data by Design

Protection is enforced in the database and tools, not left to prompts.

Least Privilege

Access to one file does not grant broader department permissions.

Processor Boundaries

Connections and model routes follow documented instructions and approved scopes.

Isolated Cache

Cached data remains separated between users and authorized workspaces.

Private Discovery

Unauthorized files never appear in search, catalog, or recommendations.

GDPR by design

Technical and organizational measures. Across data, users, and models.

Read the security page

Controller Instructions

Roles, purposes, model routes, and retention rules are managed centrally and applied independently of model behavior.

Accountability Records

Every request is recorded with its access scope, source, approval state, route, and generated output.

Feza is designed to support GDPR-compliant processing. Compliance for a specific deployment also depends on the public body’s legal basis, instructions, data, contracts, and selected model routes.

Scope

Access has four levels. Individual to organization.

Personal

Private by default, yet remains within the organization.

Private

Project

Dedicated workspace. Sharing a department does not grant access to others.

By invitation

Team

A department's data stays with that department and never leaks out.

Team-only

Organization

The ultimate boundary for models, permissions, files, tools, and budgets.

Ceiling

Your partner in public sector AI. Deploy with governance from day one.

Our team supports GDPR-aware scoping, controlled pilots, documentation, and organization-wide rollout.

Implementation Team

Technical specialists support architecture, access, and deployment decisions.

Governance Channel

A shared channel for project, security, legal, and data-protection stakeholders.

Role-Based Training

Sessions for administrators, users, reviewers, and data-protection teams.

GDPR Workshop

Map purposes, data classes, roles, model routes, retention, and human review.

Workshop topics

  • Prompting
  • Agents
  • Workflows
  • Data minimization
  • DPIA inputs

FAQ

Persistent workspace data is stored in the European Union. Inference can run on an EU-hosted route or, where organization policy permits it, on an approved route beyond the European Union. Only the content required for the request is sent to the selected route.

No. Feza does not use customer content to train its own models. The data-use terms of external model providers are evaluated separately for each approved route.

Not unless access is explicitly granted. Identity, role, membership, and policy are evaluated before each request. Unauthorized content is not included in answers and does not appear in search, catalogs, or recommendations.

Yes. Requests, sources, approvals, access scope, model routes, and generated outputs are recorded so authorized teams can review how an outcome was produced.

No. Feza is designed to support GDPR-compliant processing through technical and organizational controls. The public body must still assess its legal basis, intended use, data, controller instructions, processors, contracts, retention rules, and selected model routes.