Trust and data sovereignty

Norwegian jurisdiction. Reviewable evidence.

YPAI is a Norwegian entity operating European infrastructure. It is not a US-domiciled provider under the CLOUD Act, by corporate structure. SCCs support transfers outside the EEA.

  • Norwegian AS
  • EEA residency by default
  • No US corporate entity
  • SCCs available

Audit artifacts YPAI delivers per project.

Seven artifacts produced on request, validated by procurement teams across regulated mid-market and enterprise buyers.

Evidence package 7 artifacts · one evidence package
  1. Per-recording provenance 01
  2. Consent records 02
  3. Demographic metadata 03
  4. QA artifacts 04
  5. Dataset versioning 05
  6. Sub-processor transparency 06
  7. Sampling methodology 07

artifact 01 of 07

Per-recording provenance

Documentation of data lineage detailing the origin and chain of custody for individual project recordings.

Requested via Request a sample evidence package

artifact 02 of 07

Consent records

Contributor agreements validating specific permissions scoped by individual and intended processing purpose.

Requested via Request a sample evidence package

artifact 03 of 07

Demographic metadata

Aggregated distribution reports validating the balance of dialect and regional representations across the dataset.

Requested via Request a sample evidence package

artifact 04 of 07

QA artifacts

Validation logs and metric reports detailing the quality assurance gates passed during dataset compilation.

Requested via Request a sample evidence package

artifact 05 of 07

Dataset versioning

Immutable cryptographic hashes and change logs tracking modifications across dataset iterations.

Requested via Request a sample evidence package

artifact 06 of 07

Sub-processor transparency

A documented register of third-party infrastructure and service providers, available upon formal request.

Requested via Request a sample evidence package

artifact 07 of 07

Sampling methodology

Technical documentation defining the statistical approach used to select and stratify data for model training.

Requested via Request a sample evidence package

Where YPAI maps to the regulations procurement reviews.

Six regulations, with the YPAI control mechanism and the evidence artifact that proves it.

GDPR Article 7 Lawful basis: consent
YPAI control Per-contributor consent paired with automated withdrawal workflow
Evidence artifact Consent records generated per data subject
GDPR Article 12 to 23 Data subject rights
YPAI control Dedicated DSR workflow featuring automated audit trails
Evidence artifact Exportable DSR audit log
GDPR Article 28 Data processor terms
YPAI control Standardized DPA terms embedded in contracts
Evidence artifact Fully executed DPA artifact
EU AI Act Article 10 Data governance for high-risk AI
YPAI control Systemic provenance tracking and bias mitigation documentation
Evidence artifact Provenance logs and sampling methodology documentation
MiFID II Financial services voice and recording
YPAI control Architecture supporting five-year recording archive capabilities
Evidence artifact System provenance and cryptographic retention metadata
HIPAA Healthcare consent language scope only
YPAI control Healthcare-specific consent language and project-scoped contractual review
Evidence artifact Per-contributor signed consent paired with documented data-handling terms

Rows appear only where YPAI holds a control and an evidence artifact.

Single jurisdiction. By design.

Legal Entity
Norwegian AS
Data Residency
EEA Infrastructure
Jurisdictional Perimeter
No US Entity

YPAI is a Norwegian entity operating European infrastructure. It is not a US-domiciled provider under the CLOUD Act, by corporate structure, not by contract. SCCs are available for any customer-directed transfer outside the EEA.

What YPAI signs and what YPAI operates.

YPAI procurement value is anchored in structural EEA jurisdiction and GDPR-native engineering. The contractual commitments and operational controls below are standing artifacts, so security teams can assess architectural fit without commissioning custom documentation.

What YPAI signs 3
GDPR Article 28 DPA
Standardized Data Processing Agreement included with every engagement, ready for countersignature.
30-day erasure SLA
Hard deletion guarantees written into the master service agreement.
SCCs available
Standard Contractual Clauses for customer-directed transfers outside the EEA.
What YPAI operates 7
Per-contributor consent records
Immutable cryptographic audit trails for all data inputs.
DSR workflow
Automated pipelines for Data Subject Rights requests.
GDPR Article 32 security mapping
Engineering parameters mapped directly to GDPR Article 32 security requirements.
72-hour breach notification
GDPR Article 33 window, with the audit trail entry timestamped from the moment of awareness.
EEA-resident processing
Norwegian AS operating EEA infrastructure by default, with no US CLOUD Act exposure.
EU AI Act Article 10 alignment
Proactive mapping to European AI data governance mandates.
7-artifact evidence package
Documented proof of data provenance and isolation, available upon formal request.

Frequently asked

What procurement reviewers ask before signing.

Where does YPAI store customer data?

In the European Economic Area (EEA) by default. Norwegian and EEA infrastructure providers only. Customer-directed transfers outside the EEA are supported via Standard Contractual Clauses (SCCs).

What is the data erasure SLA?

30 days from a verified erasure request, with audit trail preserved. Hard deletion is written into the master service agreement.

How are healthcare-specific legal and data-handling requirements handled?

Healthcare-specific legal roles, data flows, residency, and contract terms are assessed before scope acceptance and confirmed in signed project documentation.

What is your sub-processor list?

Documented and available upon formal request as part of the procurement workflow. Sub-processor transparency is one of the 7 audit artifacts shipped per project.

Can you sign our DPA, or do we use yours?

YPAI ships a standardized DPA covering GDPR Article 28 terms. Customer DPAs are accepted with redlining where the engagement scope makes it operationally feasible.

What is your breach notification window?

In line with GDPR Article 33: 72 hours from awareness, with the audit trail entry timestamped from the same moment.

What compliance evidence does YPAI provide for security review?

A documented evidence package with every engagement: GDPR Article 28 DPA ready for countersignature, per-contributor consent records, DSR workflow documentation, a 30-day erasure SLA in the master service agreement, SCCs for customer-directed transfers outside the EEA, and EU AI Act Article 10 alignment. The Commitments and Controls panel above lists each artifact.

Get the artifacts your procurement committee will ask for.

A named YPAI engineer replies within one EU business day with the sovereignty assessment, draft DPA, and the evidence package scoped to your workload.