Is Pilea GDPR compliant?
Yes, Pilea is fully GDPR compliant. All customer data is privately stored and processed exclusively within the European Union, ensuring complete adherence to EU data protection regulations.
Where is Pilea data stored?
Pilea stores all customer data on secure servers located in the European Union. The platform uses:
- Primary servers: EU-based infrastructure for all data storage
- Integration gateway: Located within the EU for secure third-party connections
- LLM processing: OpenAI through Azure on Swedish servers
- Transcription services: French servers for audio processing
What security measures does Pilea implement?
Authentication & Access Control
- Two-factor authentication (2FA) available for all user logins
- Secure user access controls and permissions management
Data Processing & Storage
- EU-exclusive processing: No data ever leaves European borders
- GDPR-compliant third parties: All integrated services meet EU privacy standards
- Secure integration gateway: All third-party connections routed through EU-based gateway service (Unified.to)
Privacy Protection Features
- PII redaction: Coming soon for additional privacy protection
- Data Processing Agreement (DPA): Available on request for enterprise customers
- No US data transfer: Zero customer data transferred to United States servers
Which third-party services does Pilea use?
Pilea carefully selects EU-compliant partners:
- Integration gateway: Unified.to (EU-based)
- Transcription service: Gladia (EU-based)
- LLM processing: OpenAI ChatGPT 4o via Azure (EU servers)
All third-party services are GDPR-compliant and process data exclusively within the European Union.
Does Pilea train AI models with customer data?
No. Pilea does not use customer data to train AI models or transfer any information to US-based systems. Your feedback data remains private and is used solely for your organization's insights and analysis.
How does Pilea ensure long-term data security?
Pilea's privacy-first approach includes:
- Continuous GDPR compliance monitoring
- Regular security audits and updates
- Transparent data processing practices
- Clear data retention and deletion policies
- Enterprise-grade encryption for data in transit and at rest
Where can I read more?