GDPR-compliant AI product management
Specky is an AI-native PM workspace built EU-first: all workspace data is hosted exclusively in Frankfurt, every GDPR right (Art. 15–20) is self-serviceable from settings, a standard Art. 28 DPA is available on request, and your data never trains a model. Below is the checklist EU teams should run against anyAI tool — with Specky's answers filled in.
EU data residency
All workspace data stored exclusively in Frankfurt, Germany. Never leaves the EU.
Never trains on your data
Contractual no-training, no-storage position for AI inference — not a vague “improve our services” clause.
Rights are self-service
Export, erasure, portability, and consent — Art. 15–20 handled from Settings, no email required.
DPA + SOC 2 alignment
Art. 28 DPA on request, SCCs supported, controls mapped to SOC 2 (Type II certification in progress).
The EU checklist for AI PM tools — with our answers
“It's GDPR-compliant” on a marketing page isn't enough. These are the checks EU teams should run against any AI tool before signing — including this one.
| Check | What “good” looks like | Specky's answer |
|---|---|---|
| Data residency | Personal data stored and processed in the EEA | All workspace data stored exclusively on Supabase infrastructure in Frankfurt, Germany. Residency certificates available for enterprise customers. |
| Data sovereignty | Honest disclosure of who has jurisdictional control — an EU region of a US provider is residency, not sovereignty | Specky is an EU (Austria) company. Database infrastructure runs on Supabase's Frankfurt region; Supabase is US-headquartered — we disclose that rather than blur residency into sovereignty. |
| Sub-processors | Named, jurisdiction disclosed, changes notified in advance | Full list published on the security page: Supabase (EU, Frankfurt), Vercel (US), Google Generative AI (US), PostHog (EU or US, opt-in), Stripe (US). No sub-processor can access your workspace content data. |
| Trains on your data? | An explicit “your data never trains our models” — not “we may use data to improve our services” | Your data never trains a model. Prompt data is not stored by Google and is not used for training under our business agreement. |
| GDPR rights (Art. 15–20) | Self-serviceable, not email-and-wait | Access, erasure (30-day grace period), portability (JSON export), and consent management — all self-service from workspace Settings → Privacy & Data. |
| DPA (Art. 28) | Standard DPA available immediately; SCCs supported for transfers | Standard GDPR Art. 28 DPA available on request; custom DPAs and additional SCCs supported for enterprise. Email security@specky.space. |
| EU AI Act (Annex III) | Vendor states its conformity posture in writing | Specky's AI features draft documents and organise product signals — they don't score, rank, or decide anything about natural persons (the hiring/credit/biometrics use cases Annex III covers). Written posture statement available on request. |
| Breach notification | 72-hour customer notification commitment (Art. 33/34) | Affected customers notified within 72 hours of confirming a breach, including nature of the incident, data affected, and remediation steps. |
Every claim above is documented in full on the security page and privacy policy.
The AI-specific questions, answered plainly
Where does AI inference happen?AI inference (Google Gemini) is processed in the US. Prompt data is not stored by Google and is not used for training under our business agreement. Customers requiring EU-only AI processing can have inference routed through an EU-based model — contact us to discuss.
Residency vs. sovereignty — the distinction most vendors blur. Residency is where the bytes sit; sovereignty is who has jurisdictional control. Specky is an EU (Austria) company and workspace data sits in Frankfurt — but our database provider, Supabase, is US-headquartered. We'd rather disclose that plainly than sell residency as sovereignty. Ask any vendor the same question.
What about the EU AI Act?Specky's AI features draft documents, synthesise signals, and generate tickets — they operate on artefacts, not on scoring or decisions about people (the hiring/credit/biometrics territory Annex III covers). A written conformity posture statement is available on request.
GDPR & EU compliance — frequently asked questions
Is there a GDPR-compliant AI product management tool?
Yes. Specky is an AI-native product management workspace built EU-first: all workspace data is stored exclusively in Frankfurt, Germany, every GDPR data-subject right (Art. 15–20) is self-serviceable from settings, a standard Art. 28 DPA is available on request, and your data never trains a model.
Where does Specky store my data?
All workspace data is stored exclusively in the EU, on Supabase infrastructure in Frankfurt, Germany. Your workspace data never leaves the EU. AI inference (Google Gemini) is processed in the US under a no-storage, no-training business agreement — and for customers requiring EU-only AI processing, inference can be routed through an EU-based model on request.
Does Specky train AI models on my data?
No. Your data never trains a model. Prompt data sent for AI inference is not stored by the provider and is not used for training under our business agreement — an explicit contractual position, not a “we may use data to improve our services” clause.
Does Specky sign DPAs?
Yes. A standard Data Processing Agreement (GDPR Art. 28 compliant) is available immediately on request, and enterprise customers can arrange custom DPAs with additional standard contractual clauses (SCCs) for international transfers.
How do I exercise my GDPR rights in Specky?
Self-service, from workspace Settings → Privacy & Data: right of access (data export), right to erasure (account deletion with a 30-day grace period), right to data portability (JSON export), and per-purpose consent management. You don't need to email anyone.
Is Specky in scope for the EU AI Act's high-risk categories?
Specky's AI features draft documents, synthesise product signals, and generate tickets — they operate on artefacts, not on decisions about people. Annex III's high-risk categories cover use cases like hiring, credit scoring, and biometrics. A written statement of Specky's conformity posture is available on request via security@specky.space.
This page is general information, not legal advice. Verify compliance requirements against primary regulation (GDPR, EU AI Act) and your own DPO or legal counsel.
Compliance as a non-issue, not a project
Start a 14-day trial — EU-hosted from the first byte, DPA on request, and your data never trains a model. Or send this page to your DPO and let them run the checklist.