Hosting and data storage
For many organizations this is the first question for their privacy officer or information security officer: where does this run, and what happens to the data? Here are the facts.
Where does vragen.ai run?
vragen.ai runs entirely on Dutch servers. The infrastructure is hosted and managed by TrueFullstaq, a Dutch hosting provider. All data therefore stays in the Netherlands: your knowledge base, the configuration and the questions asked.
You can read why we chose this in the article Vragen.ai as a sovereign AI platform.
Which language model does vragen.ai use?
That's up to you. There are two routes:
-
Local models. These run on our own Dutch servers at TrueFullstaq. All processing then stays within our own infrastructure; nothing goes to external AI providers.
-
External models. Models from the large labs, accessed via their APIs and with agreements about how data is used: OpenAI, Anthropic, Mistral or a model through Microsoft Azure. These external models are also hosted within the EU; your data never leaves the EU. On Azure you can now pick the Dutch region as well, alongside France and Sweden. The model connection is not tied to a single provider, so we can in principle also connect one your organization has already approved. Which parties your choice puts in the chain, and what it means for your processing register, is set out in DPIA and processing register.
The model choice is in every plan, Starter included. Starting small does not tie you to a fixed language model.
Personal data in asked questions
If a visitor accidentally types a name, address or other personal data into the widget, vragen.ai anonymizes it automatically. The question appears in your inbox with a marker such as [name removed], and after one hour the original data is permanently deleted. That hour exists so an ongoing conversation can still be finished with the visitor themselves.
This anonymization is on by default; you do not have to do anything for it. You will find the setting under Settings, General.
What it is and what it is not: automated recognition of personal data in free text, and that does not catch everything with certainty. Whatever it misses stays in the conversation and disappears with your retention period. The risk stays small because nothing on screen asks for personal data, there is no account, and the widget's own functional cookies contain no personal data to attach anything to.
More about this in the article Anonymizing data.
Questions about your situation?
More about security, the tests and the certifications of SWIS can be found on the security page. For custom arrangements, such as a data processing agreement or input for a DPIA, get in touch with us; we'll arrange that together with you.