
AGICY is designed to function as a Sovereign Data Processor, with planned 100% data localization, end-to-end encryption, and alignment with the European General Data Protection Regulation — design status for a pre-construction programme.
Under Article 28 of the GDPR, data controllers must only use processors providing sufficient guarantees to implement appropriate technical and organizational measures. AGICY is designing trusted infrastructure for GDPR-aligned sovereign European AI compute with EU data-residency targets — this is compliance design status, not a claim of held certification or absolute present-tense compliance.
This document establishes the planned legal, technical, and organisational framework under which AGICY would process personal data on behalf of its enterprise clients. It should be read in conjunction with the AGICY Master Services Agreement (MSA) and Data Processing Agreement (DPA).
Unlike hyperscalers routing data across trans-Atlantic cables — risking extraterritorial data access under the US CLOUD Act — AGICY's design target is 100% data residency and localization within the Republic of Cyprus. No EU citizen data processed on AGICY hardware is intended to leave the jurisdiction of the European Union.
"AGICY utilizes secure enclaves and homomorphic encryption paradigms, ensuring that even systems administrators cannot access the underlying dataset or model weights of our enterprise clients."
AGICY is pioneering "Machine Unlearning" protocols for large language models. Should a data subject enforce their Right to be Forgotten, AGICY plans to provide the compute infrastructure required to excise specific data points from localized RAG (Retrieval-Augmented Generation) vector databases and fine-tuned weights without requiring a full model retraining from scratch.
Post-erasure, AGICY plans automated membership inference attacks against the modified model to cryptographically verify that the target data points are no longer recoverable from the model's parameters. A signed attestation report is intended for the data controller within 72 hours.
AGICY's planned standard DPA includes the following binding commitments:
AGICY does not plan to engage third-party sub-processors for core inference or training workloads. All compute is intended on AGICY-owned hardware, maintained by AGICY-employed engineers. Where ancillary sub-processors are engaged (e.g. payment processing), they are disclosed in Annex B of the DPA and subject to equivalent contractual safeguards.
In the event of a personal data breach, AGICY intends to notify the data controller without undue delay and in any case within 24 hours of becoming aware of the breach — a design target faster than the GDPR's 72-hour requirement. The notification includes:
"AGICY commits to a 24-hour breach notification window as a design target — three times faster than the GDPR minimum. A planned Security Operations Centre is designed for 24/7/365 coverage with automated anomaly detection across processing nodes."
AGICY does not intend to transfer personal data outside the European Economic Area. In the event a client requests processing involving data flows to non-EU jurisdictions, AGICY will refuse the instruction and escalate to the DPO, consistent with its obligations under Article 28(3)(a).
PDF Format · SHA-256 Verified · 1.4 MB
Pre-book Sovereign Compute compliant with all EU regulations.
Calculate SRA Allocation