Cedreon in Europe
Last updated: 11 August 2026
Cedreon is a screened interface to AI models, built for professionals who handle other people's confidential information. This page sets out the European position.
The GDPR framework
When you use Cedreon on your clients' matters you are the controller and Cedreon is the processor. That relationship runs under the Cedreon Data Processing Agreement, which is incorporated by reference into the Terms of Service and is therefore in force from the moment you accept them. No separate signature is required, and signing a formal copy does not change when it started applying.
The DPA covers the Article 28 requirements: documented instructions, confidentiality of authorised personnel, security measures, sub-processor authorisation with notice and objection, assistance with data-subject requests and breach notification, deletion or return at the end of the service, and audit.
The Privacy Policy describes what Cedreon processes as a controller in its own right: account, billing and website data. It is an information notice. It is not a consent, and we do not treat acceptance of the Terms as consent to anything in it.
Sub-processors
The current list, what each one does and where it processes, is at /subprocessors. Changes are published before they take effect and notified to the account contact, with 30 days to object on data-protection grounds.
Technical and organisational measures
The measures are set out at /security, written from the running system rather than from a template. The ones specific to this product:
- Recognised sensitive values are replaced with reversible placeholders before any request reaches a model provider. The provider receives the placeholder; the mapping is encrypted and restored only for the authorised reader.
- Search queries sent to a connected Drive are masked destructively: nothing reversible leaves. A web-search query is sent as you typed it; the control there is that the feature is off until you switch it on per conversation, and the switch says so.
- Every exchange is written to an append-only, hash-chained record. It does not store the plaintext of prompts or model responses, only integrity and operational metadata.
- Erasure destroys the encrypted mapping, which makes the original values unrecoverable, while the integrity record survives with nothing personal in it.
Detection is layered and best-effort. It is a supplementary measure, not anonymisation, and not a warranty that every sensitive value is recognised.
Which processing is verifiably in the EU
We are precise about this rather than reassuring, because the difference is what a data protection officer will ask about.
- The application and your stored data are processed in the European Union.
- In-process components send nothing outward: the recognition model, document extraction, the document search index and PDF generation all run on our own infrastructure.
- Every model row is pinned to a named European processor with provider fallback disabled. An unavailable processor produces a failure rather than a silent re-route to another region.
- The gateway itself will not route outside Europe. Requests go to its European endpoint, which serves only providers cleared for EU processing and refuses anything else before a provider is contacted. Who serves each row is named on the subprocessors page.
Processing in Europe does not mean the model was BUILT in Europe. An organisation that needs both can switch itself to EU vendors only, which restricts the model set to European-built rows and withholds web search, because the search provider's processing region is not one we pin.
Professional confidentiality in Europe
Many of the professionals Cedreon serves are bound by confidentiality obligations that go beyond data protection: lawyers, tax advisers, auditors, doctors. Cedreon publishes a professional-confidentiality agreement framework for organisations in that position, using the same execution workflow and the same technical enforcement as the Swiss agreement.
One thing we will not do is pretend there is a single European equivalent of Switzerland's Article 321. Professional secrecy in Europe is national law, and its scope, its criminal consequences and its treatment of service providers differ from one member state to another. The agreement therefore states Cedreon's undertakings in terms that do not depend on one national regime, and leaves the identification of the applicable national obligation to the organisation signing it.
This agreement is not yet offered for signature. Its national legal scope, its text and its approved processor set each need to be cleared first. The engineering is in place; the activation is not, and we would rather say that than display a button.
What activating a profile does
When such an agreement is fully executed, the organisation enters a compliance profile that applies to every member:
- only models and providers explicitly approved for that profile may be used, in the picker, in automatic routing and in any direct request;
- external tools whose processors are not approved are switched off for the organisation, server-side;
- where several restrictions apply, only routes approved under all of them may be used;
- a request with no approved route is refused with an explanation, never quietly served by an unapproved provider.
Each profile has its own approved set. A route approved under one is not thereby approved under another.
Talk to us
Write to [email protected].