TRUST & SECURITY

Built so your client data cannot leave.

PrivateNode is designed for firms whose regulator, insurer, and clients all expect a straight answer to one question: where does our data go? Here is the whole answer, in one place.

A single-tenant node, not a shared platform

Each firm gets its own dedicated server. Your documents, your vector index, your conversation history, and your audit trail live on that one machine and nowhere else. There is no shared database, no data commingling between clients, and no multi-tenant application layer to misconfigure.

EU/UK data residency

Your node runs in European data centres (Hetzner, Germany and Finland), and AI inference runs with EU-based providers. No US company sits in the processing chain, so there is no CLOUD Act exposure to explain away in your risk assessment. Data stays in UK-adequate jurisdictions end to end.

A control plane that only sees metadata

We operate the fleet centrally, but the central systems carry operational metadata only: model names, token counts, latency, cost, and anonymised usage signals. The content of your questions and answers never leaves your node. Even we cannot read your queries. That is an architectural property, not a policy promise.

An audit trail your regulator can inspect

Every node keeps a full audit log on the server itself: who asked what, when, which sources were consulted, and what was answered. If the SRA, FCA, or ICO asks how AI is used in your practice, the evidence is on your own machine, under your control, ready to export.

Zero retention with AI providers, in the contract

Model inference is ephemeral. The EU inference providers we use commit contractually to zero data retention: prompts are processed and discarded, and are not used for model training. We choose providers on this term, and it is written into our agreements rather than assumed from a privacy policy.

GDPR Article 28, as standard

You remain the data controller; PrivateNode acts as your processor under a full Data Processing Agreement covering GDPR Article 28: documented instructions, confidentiality, security measures, sub-processor transparency, and deletion on exit. The DPA is included with every plan, along with compliance documentation for your own risk assessment.

Certified infrastructure, honestly attributed

Our hosting provider, Hetzner, holds ISO 27001 certification for the data centres your node runs in. That certification belongs to the infrastructure layer, and we say so plainly: PrivateNode builds on certified hosting rather than claiming the certificate as its own.

Single-tenant node

EU/UK residency

Metadata-only control plane

On-server audit trail

Contractual zero retention

GDPR Art. 28 DPA

QUESTIONS FOR YOUR RISK ASSESSMENT?

We will walk your COLP, DPO, or compliance lead through the architecture and provide the documentation pack.

Book a 20-minute demo

See also our Privacy Policy and Terms of Service.