Cedreon

Cedreon in Europe

Last updated: 11 August 2026

Cedreon is a screened interface to AI models, built for professionals who handle other people's confidential information. This page sets out the European position.

The GDPR framework

When you use Cedreon on your clients' matters you are the controller and Cedreon is the processor. That relationship runs under the Cedreon Data Processing Agreement, which is incorporated by reference into the Terms of Service and is therefore in force from the moment you accept them. No separate signature is required, and signing a formal copy does not change when it started applying.

The DPA covers the Article 28 requirements: documented instructions, confidentiality of authorised personnel, security measures, sub-processor authorisation with notice and objection, assistance with data-subject requests and breach notification, deletion or return at the end of the service, and audit.

The Privacy Policy describes what Cedreon processes as a controller in its own right: account, billing and website data. It is an information notice. It is not a consent, and we do not treat acceptance of the Terms as consent to anything in it.

Sub-processors

The current list, what each one does and where it processes, is at /subprocessors. Changes are published before they take effect and notified to the account contact, with 30 days to object on data-protection grounds.

Technical and organisational measures

The measures are set out at /security, written from the running system rather than from a template. The ones specific to this product:

Detection is layered and best-effort. It is a supplementary measure, not anonymisation, and not a warranty that every sensitive value is recognised.

Which processing is verifiably in the EU

We are precise about this rather than reassuring, because the difference is what a data protection officer will ask about.

Processing in Europe does not mean the model was BUILT in Europe. An organisation that needs both can switch itself to EU vendors only, which restricts the model set to European-built rows and withholds web search, because the search provider's processing region is not one we pin.

Professional confidentiality in Europe

Many of the professionals Cedreon serves are bound by confidentiality obligations that go beyond data protection: lawyers, tax advisers, auditors, doctors. Cedreon publishes a professional-confidentiality agreement framework for organisations in that position, using the same execution workflow and the same technical enforcement as the Swiss agreement.

One thing we will not do is pretend there is a single European equivalent of Switzerland's Article 321. Professional secrecy in Europe is national law, and its scope, its criminal consequences and its treatment of service providers differ from one member state to another. The agreement therefore states Cedreon's undertakings in terms that do not depend on one national regime, and leaves the identification of the applicable national obligation to the organisation signing it.

This agreement is not yet offered for signature. Its national legal scope, its text and its approved processor set each need to be cleared first. The engineering is in place; the activation is not, and we would rather say that than display a button.

What activating a profile does

When such an agreement is fully executed, the organisation enters a compliance profile that applies to every member:

Each profile has its own approved set. A route approved under one is not thereby approved under another.

Talk to us

Write to [email protected].