GDPR Compliance
Last updated: 19 July 2026
Privacy is not an add-on to AIBOX — it is the reason the product exists. This page summarises how Team Landi approaches the General Data Protection Regulation (EU) 2016/679, both for this website and for client engagements.
1. Data stays on your premises
AIBOX solutions are designed to run locally, at your premises or in infrastructure you control. Your documents, databases, and conversations processed by AIBOX do not need to leave your organisation — which dramatically simplifies your own GDPR position when adopting AI.
2. Our roles
For this website and our marketing, Team Landi acts as a data controller — see our Privacy Policy for details.
When we implement or support solutions that touch your personal data, we act as a processor under a written data processing agreement (DPA) defining scope, instructions, confidentiality, sub-processors, and deletion on termination.
3. Principles we apply
Data minimisation: we design solutions to process only the data a workflow actually needs.
Purpose limitation and transparency: what a system does with data is documented and agreed before deployment.
Storage limitation: retention periods are defined per project, with deletion or anonymisation at the end of them.
4. International transfers
Where a tool we use transfers data outside the EEA (for example our website form provider), we rely on adequacy decisions or Standard Contractual Clauses. Client-side AIBOX deployments avoid such transfers by design.
5. Incidents
If a personal data breach affecting data we process ever occurs, we assess and notify affected controllers without undue delay in line with Art. 33 GDPR, and support the notification obligations that may follow.
6. Contact
For GDPR questions, data processing agreements, or exercising your rights, contact hello@teamlandi.com.
Questions? Write to us at hello@teamlandi.com
