GDPR / DPA pack
Controller and processor roles, sub-processors, transfer safeguards, and a data processing agreement for business customers.
Owning the AI system still requires clear documentation: processing roles, technical measures, deletion evidence, update boundaries, model provenance, and a published security contact.
Eight defined areas replace broad trust claims with reviewable records, operational templates and published contact routes.
Controller and processor roles, sub-processors, transfer safeguards, and a data processing agreement for business customers.
Technical and organisational measures covering access, encryption, logging, backups, provisioning, and incident response.
Defined retention periods for order records, support material, logs, and optional Pre-Load files.
Written confirmation when customer files are removed from provisioning storage after an agreed Pre-Load.
Model family, source, licence, workload, runtime, format, update channel, and available verification references.
Separate stable, balanced, and fast-track channels for security, compatibility, and model updates.
A machine-readable disclosure contact at /.well-known/security.txt linked to the current security policy.
A published route for reporting, triage, remediation, customer impact assessment, and disclosure handling.
For configured systems, the customer-facing trust package can include a concise record of what model stack was selected and why it is appropriate for the device.
Versioned, plain-language summaries for an initial technical, security, and privacy review.
This page describes the trust package selbsai maintains for customers. Customer-specific DPA and TOM documents are provided during business onboarding where required.