01 / Principles

GDPR & EU data sovereignty.

Every prompt, every completion, every embedding — processed and stored exclusively on European soil.

EU-only residency

Servers physically in Trento, Italy.

All inference workloads run on servers physically located at our colocation facility in Trento, Italy. Data at rest and in transit never leaves the European Union. No cross-border data transfers to the US, China, or any third country.

Article 28

Standard DPA on request

Our agreement defines controller vs. processor roles, data categories, processing purposes, sub-processor obligations, breach notification timelines, and data deletion procedures.

No US sub-processors

No AWS. No Azure. No GCP.

Our entire stack runs on our own hardware in a colocation facility. No US company touches your data. No CLOUD Act exposure. No Schrems II concerns.

EU AI Act

Built for GPAI obligations from day one.

As a provider of general-purpose AI models (GPAI), our obligations include transparency documentation, energy efficiency reporting, and downstream compliance guidance for deployers in high-risk contexts. We are building our compliance framework to align with the EU AI Act as it enters force.

02 / Data flow

Where your data travels.

Comparison of provider jurisdictions, sub-processors, and regulatory exposure.

Provider Primary Jurisdiction Data Centers Sub-Processors GDPR SCC Required AI Act Readiness
Nypples Industries Italy (EU) Trento, Italy None (self-operated) No In Progress
DeepSeek API China China Undisclosed Required Not Applicable
OpenAI API US US, EU (limited) Microsoft Azure Required Partial
Anthropic API US US, EU (limited) GCP, AWS Required Partial
Together AI US US Multiple US providers Required Limited
Google Gemini API US Global (US primary) Google Cloud Required Partial
03 / Your rights

Your data rights.

Enforceable commitments, not marketing copy.

  • Right to Access: Request a copy of all data processed through your account within 30 days.
  • Right to Deletion: We permanently delete all your prompts, completions, and embeddings upon request. No retention beyond what you specify.
  • Right to Portability: Export all your data in machine-readable JSON format. No proprietary lock-in.
  • No Training on Your Data: We never use customer prompts or completions to train, fine-tune, or improve any model. Your data is your data.
  • Encryption at Rest and in Transit: AES-256 for storage, TLS 1.3 for all API communications.
  • Access Logging: Full audit trail of who accessed what, when, and from where. Retained for 90 days, exportable on request.
The difference: Most AI APIs treat GDPR compliance as an afterthought — a checkbox. At Nypples, European data sovereignty is the entire reason we exist. We built our infrastructure specifically for organizations that cannot or will not send data outside the EU. If your legal team has ever flagged a SaaS tool because of Schrems II, Nypples is the answer.