Legal
Back to home

Data policy

Data Policy Oniroco

Introduction

This document provides a clear overview of the data and privacy guidelines for customers using Oniroco, a chat and AI orchestration service that connects to large language models (LLMs) via multiple providers and gateways under Oniroco’s own vendor contracts and technical configuration.

It covers GDPR compliance, the distinction between GDPR and data residency, how data is used and stored, which model paths Oniroco operates, retention practices, and the security protocols that Oniroco observes.

GDPR compliance vs data residency

These are related but not the same:

| Concept | Meaning | |--------|---------| | GDPR compliance | Lawful processing, purpose limitation, minimisation, security, subprocessors, DPAs, data-subject rights, international transfer safeguards (e.g. SCCs), etc. | | EU data residency | Whether prompts, completions or stored data physically remain in data centres in the EU/EEA |

All LLM endpoints and platform paths that Oniroco uses in production are operated under GDPR-aligned arrangements (appropriate contracts, DPAs where required, no training on customer API traffic, security and subprocessors under control).

Not every path guarantees EU-only residency. Some paths keep processing and/or short-lived logs outside the EU while remaining GDPR-compliant through transfer mechanisms and vendor terms. Other paths (e.g. Azure OpenAI in EU regions, OpenRouter enterprise EU in-region routing, self-hosted in the EU) additionally offer stronger residency guarantees.

Oniroco will state clearly, per deployment, which paths apply and whether they include EU residency—without equating “non-EU region” with “not GDPR compliant.”

How Oniroco runs model access

Oniroco speaks directly to provider APIs and gateways under Oniroco’s contracts and account configuration. Customers use Oniroco; they do not each have to negotiate separate foundation-model contracts for the standard platform paths (unless a dedicated/self-hosted or special enterprise setup is agreed).

Production paths Oniroco operates include:

| Path | Role in Oniroco’s stack | |------|---------------------------| | OpenAI API | Direct API under Oniroco’s commercial terms | | Anthropic API | Direct commercial API under Oniroco’s commercial terms | | Azure OpenAI Service | Enterprise path with optional EU data residency | | OpenRouter | Gateway to a list of trusted vendors, configured by Oniroco (including OpenRouter EU endpoint / enterprise EU in-region routing where enabled: https://eu.openrouter.ai) | | Self-hosted models | Dedicated GPU for the customer when that deployment model is agreed |

Oniroco selects and hardens these paths (trusted vendors, no-train terms, ZDR where available, EU OpenRouter where applicable). Optional customer preferences may exist for which approved path is used for a given workspace; that is still within Oniroco’s contracted and configured set—not an open “bring your own unvetted vendor” model.

Commitments that apply across these paths

  • No use of customer API traffic to train foundation models — no compromises on this point for production traffic on Oniroco’s supported paths.
  • Retention at the model layer is zero or short and purpose-limited (security, abuse/fraud monitoring, or the vendor’s standard commercial backend window where ZDR is not in force)—not secondary commercial reuse.
  • GDPR-aligned contracts and processing terms with the vendors and gateways we use.
  • Credentials and secrets for tools never go to the LLM (e.g. database passwords, API keys,... stay in Oniroco’s runtime).

Relevant references

(Non-exhaustive; live pages prevail. These support Oniroco’s vendor diligence; customer processing is under Oniroco’s DPA / agreement with the customer.)

Azure / Microsoft

OpenAI

Anthropic

(Oniroco uses the commercial API under contract)

OpenRouter

(including EU endpoint configuration used by Oniroco)

Use and storage of data (Oniroco platform)

Platform hosting

Oniroco application data is hosted in the European Union:

  • Data centres: Belgium and the Netherlands (e.g. Google Cloud in Belgium and DigitalOcean in the Netherlands), for redundancy, availability and GDPR alignment
  • Backups: Stored in the EU, retained for up to one year (or as agreed in the customer contract)

LLM processing

Inference traffic is sent only over Oniroco-configured paths (including Anthropic API and OpenRouter EU among others). What leaves the EU for model inference depends on the path in use for that workload:

  • Paths with EU residency (e.g. Azure OpenAI EU, OpenRouter EU in-region, EU self-hosted): processing kept in the EU as designed for that path
  • Paths without full EU residency: still GDPR-compliant under Oniroco’s contracts and transfer safeguards; residency is simply not the same guarantee as compliance

What is sent to an LLM

  • Sent: Only what the model needs to do its job (e.g. relevant chat context, tool results / raw data required for reasoning).
  • Not sent: Tool and system credentials (e.g. passwords, private API keys).

Data minimisation and anonymisation

Legacy entity-extraction alone is a weak sole control (high error rate ⇒ residual personal data). Oniroco therefore combines:

  • Sending only task-necessary data to the model
  • Keeping secrets out of prompts
  • No training on API traffic
  • Zero or short, purpose-limited provider retention under our contracts (including ZDR and trusted OpenRouter vendors where applicable)

Retention at the LLM layer

| Topic | Oniroco position | |--------|-------------------| | Training | Never on customer production API traffic on supported paths | | Provider-side retention | 0 where ZDR / equivalent applies; otherwise short, limited windows (security/abuse and/or vendor standard commercial backend—e.g. order of days up to the vendor’s documented commercial default such as Anthropic’s standard 30-day API backend window when ZDR is not active). Not for model training or unrelated secondary use | | OpenRouter | Oniroco configures trusted vendors, no-train / ZDR-oriented routing and EU endpoint where applicable; OpenRouter itself does not train models and does not keep prompt/response bodies unless logging is enabled (Oniroco does not run customer production on casual opt-in logging) | | Anthropic | Commercial API under Oniroco contract; ZDR where included in that contract; otherwise vendor commercial retention rules as published / contracted | | Platform DB (Oniroco) | Separate from LLM ephemeral processing; EU-hosted; subject to product features and deletion procedure below |

Ongoing backups

Ongoing backups protect platform data integrity and availability. Backups remain in the EU for up to one year (or as contractually agreed). They are distinct from short-lived LLM-provider processing.

Procedure for deleting data

  • Soft delete by default on the Oniroco platform (marked deleted, excluded from normal use).
  • Hard delete on explicit request, removing data from active systems subject to legal hold, backup rotation and compliance duties.

Requests: support@oniroco.eu.

Provider-side deletion follows the contracts Oniroco holds with each vendor/gateway; Oniroco handles that operationally for standard platform paths.

Personal data and consent

Personal data is processed under the customer’s instructions and applicable law. Features that intentionally store personal data (e.g. Human Handover) require the appropriate legal basis / consent as configured with the customer.

Free-text that users type into chat may contain personal data; it is handled under the storage and LLM-routing rules above.

No data sharing between customers

No data is shared between customers in any way. Unless specifically agreed by the customer it can be shared on a case by case basis. Default without consent is always: no sharing.

No fine-tuning on customer data by default

Oniroco does not fine-tune foundation models on customer conversations or tool payloads unless a separate explicit agreement says so. Production traffic stays on no-training API terms. Operational data lives in Oniroco’s EU databases, not with model providers beyond the retention profile of the active path.

Control of the chain (e.g. vs Microsoft Foundry)

Managed studio stacks often hide routing, logging and subprocessors. Oniroco keeps control of each link—gateway, prompt contents, tool credentials, storage and our vendor contracts—so production controls (GDPR terms, no training, retention, and residency where promised) can be enforced deliberately.

Data Protection Officer (DPO)

Brecht Valcke is Oniroco’s DPO. Contact: support@oniroco.eu (routed to the DPO).

Summary for common due-diligence questions

| Question | Answer | |----------|--------| | Who contracts the LLM vendors? | Oniroco, under our agreements and configuration (e.g. Anthropic API, OpenRouter EU, OpenAI, Azure, self-hosted). | | Must every customer pick and contract vendors themselves? | No for standard platform paths. Workloads run on Oniroco’s approved, contracted stack. | | Are all endpoints GDPR compliant? | Yes. All production endpoints Oniroco uses are run under GDPR-aligned arrangements. | | Does GDPR require an EU datacentre for the LLM? | No. GDPR compliance ≠ EU residency. Residency is an extra guarantee on some paths only. | | Is lack of EU residency “not GDPR compliant”? | No. Non-EU processing can still be GDPR-compliant (contracts, SCCs/transfer tools, purpose limitation, security, no training, etc.). | | What goes to the LLM? | Only what is needed for the task. Not tool credentials. | | Training on our data? | Never on supported production paths. | | How long at the LLM provider? | 0 under ZDR/equivalent where applicable; otherwise short purpose-limited windows per vendor contract (not for training). | | Where is the Oniroco app data? | EU (BE/NL), with EU backups. |

Conclusion

Oniroco is a production-grade AI layer operated on Oniroco’s multi-vendor stack (including Anthropic API and OpenRouter EU, alongside OpenAI, Azure OpenAI and optional self-hosted GPUs): EU platform hosting, GDPR-compliant endpoints throughout, optional stronger EU residency on specific paths, no training on API data, and zero or short provider-side retention under our contracts.

For deployment-specific path lists, residency maps or subprocessors: support@oniroco.eu.