Trust and data sovereignty

Norwegian jurisdiction. Reviewable evidence.

YPAI is a Norwegian company with no US corporate entity, operating EEA infrastructure. Data residency, subprocessors and international-transfer controls are defined per project. SCCs are available for any customer-directed transfer outside the EEA.

  • Norwegian AS
  • EEA residency by default
  • Norwegian corporate structure
  • SCCs available

Seven artefacts a procurement review can read.

Produced on request and scoped to the engagement. Each one answers a question your reviewers will ask.

Evidence package 7 artefacts · one evidence package
  1. Per-recording provenance 01
  2. Consent records 02
  3. Demographic metadata 03
  4. QA artefacts 04
  5. Dataset versioning 05
  6. Sub-processor transparency 06
  7. Sampling methodology 07

artefact 02 of 07

Consent records

One consent per contributor, per purpose, with the timestamp and the wording they agreed to.

Requested via Request a sample evidence package

artefact 05 of 07

Dataset versioning

A hash per version and a change log between versions, so a delivered set can be matched to the one you tested.

Requested via Request a sample evidence package

artefact 06 of 07

Sub-processor transparency

The register of infrastructure and service providers behind the engagement, available on formal request.

Requested via Request a sample evidence package

Six regulations, one control and one artefact each.

The regulation your review names, the control YPAI operates for it and the artefact that proves the control ran.

GDPR Article 7 Lawful basis: consent
YPAI control Consent per contributor and purpose, with a withdrawal workflow
Evidence artefact Consent records generated per data subject
GDPR Article 12 to 23 Data subject rights
YPAI control A data-subject-rights workflow that writes its own audit trail
Evidence artefact Exportable DSR audit log
GDPR Article 28 Data processor terms
YPAI control Article 28 DPA terms in every engagement contract
Evidence artefact Fully executed DPA artefact
EU AI Act Article 10 Data governance for high-risk AI
YPAI control Provenance per recording and documented sampling against bias
Evidence artefact Provenance logs and sampling methodology documentation
MiFID II Financial services voice and recording
YPAI control Five-year recording retention built into the architecture
Evidence artefact System provenance and cryptographic retention metadata
HIPAA Limited to consent language and contract review
YPAI control Healthcare consent wording and a contract review scoped to the project
Evidence artefact Per-contributor signed consent paired with documented data-handling terms

Single jurisdiction. By design.

Legal entity
Norwegian AS
Data residency
EEA infrastructure
Corporate structure
Norwegian ownership

YPAI is a Norwegian company with no US corporate entity. Data residency, subprocessors and international-transfer controls are defined per project. SCCs are available for any customer-directed transfer outside the EEA.

What YPAI signs and what YPAI operates.

Two lists. The commitments YPAI signs in every engagement, and the controls YPAI operates whether or not a contract asks for them. Both are standing artefacts, so a security team can assess fit from standard documents before a call.

What YPAI signs 3

GDPR Article 28 DPA
The Data Processing Agreement comes with every engagement, ready for countersignature.
30-day erasure SLA
Hard deletion within 30 days of contract end, written into the master service agreement.
SCCs available
Standard Contractual Clauses for customer-directed transfers outside the EEA.

What YPAI operates 7

Per-contributor consent records
Each record is timestamped and bound to the processing purpose, in an immutable audit trail.
DSR workflow
Access, rectification and erasure requests run through one workflow that logs each step.
GDPR Article 32 security mapping
Each engineering control is mapped to the Article 32 requirement it satisfies.
72-hour breach notification
GDPR Article 33 window, with the audit trail entry timestamped from the moment of awareness.
EEA processing by default
Norwegian AS operating EEA infrastructure by default, under Norwegian jurisdiction.
EU AI Act Article 10 alignment
Controls mapped to EU AI Act Article 10 data governance requirements.
7-artefact evidence package
The seven artefacts above, produced for the engagement on formal request.

Frequently asked

What procurement asks before signing.

Where does YPAI store customer data?

In the European Economic Area by default, on Norwegian and EEA infrastructure providers. A transfer you direct outside the EEA runs under Standard Contractual Clauses.

What is the data erasure SLA?

Hard deletion within 30 days of contract end, written into the master service agreement, with the audit trail preserved. Erasure requests from data subjects run through the DSR workflow, which logs each step.

How are healthcare-specific legal and data-handling requirements handled?

Healthcare-specific legal roles, data flows, residency, and contract terms are assessed before scope acceptance and confirmed in signed project documentation.

What is your sub-processor list?

Documented and available on formal request as part of the procurement workflow. The sub-processor register is one of the seven artefacts in the evidence package.

Can you sign our DPA, or do we use yours?

Either. YPAI's DPA covers the GDPR Article 28 terms and comes ready for countersignature. Your DPA is accepted with redlining where the engagement scope allows it.

What is your breach notification window?

In line with GDPR Article 33: 72 hours from awareness, with the audit trail entry timestamped from the same moment.

What compliance evidence does YPAI provide for security review?

A documented evidence package with every engagement: GDPR Article 28 DPA ready for countersignature, per-contributor consent records, DSR workflow documentation, a 30-day erasure SLA in the master service agreement, SCCs for customer-directed transfers outside the EEA, and EU AI Act Article 10 alignment. The commitments and controls panel above lists each artefact. The platform walkthrough shows how a session produces this record, from specification through verified delivery.

Get the artefacts your procurement committee will ask for.

A named YPAI engineer replies inside one EU business day with the sovereignty assessment, the draft DPA and the evidence package scoped to your workload.