artefact 01 of 07
Per-recording provenance
Where each recording came from and who handled it, recorded per file.
Requested via Request a sample evidence package
Trust and data sovereignty
YPAI is a Norwegian company with no US corporate entity, operating EEA infrastructure. Data residency, subprocessors and international-transfer controls are defined per project. SCCs are available for any customer-directed transfer outside the EEA.
Produced on request and scoped to the engagement. Each one answers a question your reviewers will ask.
artefact 01 of 07
Where each recording came from and who handled it, recorded per file.
Requested via Request a sample evidence package
artefact 02 of 07
One consent per contributor, per purpose, with the timestamp and the wording they agreed to.
Requested via Request a sample evidence package
artefact 03 of 07
The dialect, region and speaker balance of the dataset, reported as aggregates.
Requested via Request a sample evidence package
artefact 04 of 07
The quality gates the dataset passed, with the logs and metrics behind each one.
Requested via Request a sample evidence package
artefact 05 of 07
A hash per version and a change log between versions, so a delivered set can be matched to the one you tested.
Requested via Request a sample evidence package
artefact 06 of 07
The register of infrastructure and service providers behind the engagement, available on formal request.
Requested via Request a sample evidence package
artefact 07 of 07
How the data was selected and stratified, written so a reviewer can repeat the draw.
Requested via Request a sample evidence package
The regulation your review names, the control YPAI operates for it and the artefact that proves the control ran.
YPAI is a Norwegian company with no US corporate entity. Data residency, subprocessors and international-transfer controls are defined per project. SCCs are available for any customer-directed transfer outside the EEA.
Two lists. The commitments YPAI signs in every engagement, and the controls YPAI operates whether or not a contract asks for them. Both are standing artefacts, so a security team can assess fit from standard documents before a call.
Frequently asked
In the European Economic Area by default, on Norwegian and EEA infrastructure providers. A transfer you direct outside the EEA runs under Standard Contractual Clauses.
Hard deletion within 30 days of contract end, written into the master service agreement, with the audit trail preserved. Erasure requests from data subjects run through the DSR workflow, which logs each step.
Healthcare-specific legal roles, data flows, residency, and contract terms are assessed before scope acceptance and confirmed in signed project documentation.
Documented and available on formal request as part of the procurement workflow. The sub-processor register is one of the seven artefacts in the evidence package.
Either. YPAI's DPA covers the GDPR Article 28 terms and comes ready for countersignature. Your DPA is accepted with redlining where the engagement scope allows it.
In line with GDPR Article 33: 72 hours from awareness, with the audit trail entry timestamped from the same moment.
A documented evidence package with every engagement: GDPR Article 28 DPA ready for countersignature, per-contributor consent records, DSR workflow documentation, a 30-day erasure SLA in the master service agreement, SCCs for customer-directed transfers outside the EEA, and EU AI Act Article 10 alignment. The commitments and controls panel above lists each artefact. The platform walkthrough shows how a session produces this record, from specification through verified delivery.
A named YPAI engineer replies inside one EU business day with the sovereignty assessment, the draft DPA and the evidence package scoped to your workload.
Analytics and Google Ads cookies are set only if you accept. They show us which campaigns bring visitors here. Change your choice any time under Cookie settings. Analytics and ad cookies are set only if you accept. Cookie policy