Logo leezy.ai

AI agents with clear data boundaries

Understand where application data is stored, when model providers process a request, and which controls are available. For stricter requirements, leezy also supports dedicated, customer-cloud, and on-premise deployments.

Illustration of protected data flows between company systems and a leezy AI agent
EU
Primary application data storage
No training
Customer content is not used to train public models
Encrypted
In transit and at rest
Private
Dedicated and customer-managed options

Data flow

Know where data goes, before you deploy

A leezy agent retrieves approved context, prepares the relevant prompt, sends it to the configured model, and returns the answer to the user.

  1. 01

    Approved sources

    The agent retrieves only the knowledge and connected-system context needed for the request.

  2. 02

    Application storage

    Knowledge, configuration, and conversation records are stored in the primary application environment in the EU.

  3. 03

    Model inference

    The relevant prompt is sent to the configured model provider or to your private model endpoint.

  4. 04

    Grounded answer

    The response returns through leezy, with the conversation and operational record handled according to the selected setup.

Primary application data is stored in the EU. Depending on the selected model and deployment, inference may be processed by a provider outside the EEA or the United Kingdom under appropriate transfer safeguards.

Deployment options

Match the operating model to your risk profile

Start with managed infrastructure or define a more isolated setup with our enterprise team.

Managed cloud

Use leezy's managed service with primary application data stored in the EU. Configured model providers remain a separate part of the processing chain.

Dedicated environment

Agree an isolated single-tenant setup with dedicated capacity, storage, domain, and retention requirements.

Your cloud or on-premise

Deploy in your AWS, Azure, or GCP account, or on your own servers, with model routing and integrations designed around your controls.

Security controls

Practical safeguards for day-to-day operations

Technical controls support your security process, while configuration and organizational responsibilities remain explicit.

Encryption

Data is encrypted in transit with TLS and at rest through the infrastructure providers used by the selected deployment.

Role-based access

Define who can manage agents, knowledge, conversations, and workspace settings within your organization.

Auditable changes

Track relevant actions and configuration changes so teams can review who changed what and when.

Retention controls

Set retention and deletion requirements according to the product plan and agreed deployment configuration.

Responsibilities & safeguards

A clear role for every party

Data protection depends on the full processing context. These are the standard roles and safeguards described in leezy's privacy information.

Customer as controller
Your organization decides why and how personal data is processed through the agent and configures the use case accordingly.
hypescale as processor
hypescale GmbH operates leezy and processes customer data under the agreed data processing terms.
Documented subprocessors
Infrastructure and model providers are documented so your legal and security teams can review the processing chain.
Transfer safeguards
Where a provider processes data outside the EEA or the United Kingdom, contractual safeguards such as Standard Contractual Clauses apply where required.

Questions security teams usually ask

Is leezy GDPR-compliant?

GDPR compliance depends on your purpose, configuration, legal basis, and organizational measures. leezy provides EU primary storage, documented processing terms, security controls, and deployment options that help customers build an appropriate setup; the customer remains responsible as controller.

Where is customer data stored?

Primary application data is stored in the EU. Model inference is a separate processing step and its location depends on the provider and deployment you select.

Is our content used to train public AI models?

No. Customer prompts, completions, and uploaded content are not used to train public third-party models. A model provider may retain prompts and completions for up to 30 days for abuse monitoring, depending on the configured service.

Can data be processed outside Europe?

Yes, model inference may involve a provider outside the EEA or the United Kingdom. Where required, the processing is covered by transfer safeguards such as Standard Contractual Clauses. Private model routing can reduce or avoid this dependency.

How is data encrypted?

Data is encrypted in transit using TLS and at rest through the cloud infrastructure used by the selected deployment. The exact controls can differ between managed, dedicated, and customer-operated setups.

Can leezy run in our own environment?

Yes. Enterprise deployments can be designed for your AWS, Azure, or GCP account, or for on-premise infrastructure. Model routing, integrations, operations, and support are defined with your team.

Can we define retention and deletion rules?

Retention requirements can be aligned with the selected product plan and deployment. Dedicated and customer-managed environments support more specific operational rules, which are agreed during solution design.

Is a data processing agreement available?

Yes. hypescale GmbH provides data processing terms for customers and documents the relevant service providers in the processing chain.

Turn your requirements into a deployable architecture

Bring your security questionnaire, data residency rules, and target workflows. We will map the right deployment and model path with you.