Skip to content

Knowledge

Where your documents go while a model is being built

For the uploaded documents the customer is the controller and IonKon is the processor. Article 28(1) GDPR requires the controller to use only processors providing sufficient guarantees of appropriate technical and organisational measures; Article 28(3) requires a contract setting out subject matter, duration, nature, purpose, categories of data and categories of data subjects. The processor acts solely on documented instructions. At IonKon the order placed in the portal and the data processing agreement itself constitute those instructions. The European Data Protection Board sets out the distinction in its Guidelines 07/2020: a processor is a separate entity that processes on behalf of the controller without deciding on purposes and essential means.

As of 12 August 2026

Roles come before technology

Kept strictly separate from this are your account master data, that is company name, address, VAT identification number and e-mail address. For these IonKon is its own controller, on the legal basis of contract performance. The separation is not cosmetic. It determines who answers a subject access request, who reports a personal data breach and whose retention schedule applies.

Step 1: the upload never touches the web server

Documents travel as a ZIP archive through a short-lived presigned form directly into the object storage of STRATO GmbH (STRATO HiDrive, data centres in Germany). They do not pass through IonKon web servers, and the website database holding accounts, orders and payment status is fully separated from the processing side. Before acceptance the server validates the archive and rejects anything outside the agreed limits.

Storage is encrypted at application level with AES-256-GCM using an envelope scheme: a separate data key per artefact, with the context bound to the individual order, so keys cannot be reused across orders. The legal bases are Article 6(1)(b) GDPR and your consent obtained before processing begins under Article 6(1)(a) GDPR, which you may withdraw with effect for the future.

Step 2: an instance that belongs to this order alone

For each order a single GPU instance is created at DataCrunch Oy (cloud brand "Verda", Finland). All content-related steps run on it: text extraction, removal of personal data, generation of synthetic training examples, and the fine-tuning itself. No external AI provider gains access to your documents at any point. Once finished, instance and volumes are destroyed in every outcome, including failure and cancellation. Training data or models of different customers are never merged; storage paths and encryption contexts are separated per order.

Step 3: delivery, after which processing ends

The finished model is stored encrypted. You receive an activation code and download the package through the setup program. It runs on your own hardware inside your network, with no channel back to IonKon. From that point onwards IonKon processes no content from your documents.

Step 4: deletion, with evidence

Training data and the model copies remaining at IonKon are deleted once you confirm receipt. If you do not confirm despite two reminders, the contractual deemed-receipt rule applies and deletion takes place at that point. Independently of this: uploaded documents and the training data derived from them are deleted no later than 30 days after the finished model has been made available. Once deletion has taken place, a deletion record is issued automatically. The legal anchor is Article 28(3)(g) GDPR, under which the processor deletes or returns all personal data after the end of the provision of services and deletes existing copies, together with the storage limitation principle in Article 5(1)(e) GDPR. Returning the source documents is unnecessary because you hold the originals in any case. Invoice and order data are unaffected where commercial and tax retention periods apply.

The processors, with registered office and purpose

STRATO GmbH, Germany: web server, database, mail server and encrypted object storage for the uploaded documents. DataCrunch Oy under the cloud brand "Verda", Finland: GPU compute for data synthesis and fine-tuning, one dedicated instance per order which is deleted afterwards. Akenes SA under the brand “Exoscale”, Switzerland: the same service, processed in Frankfurt, Zagreb or Zurich; the region depends on available capacity.

BuchhaltungsButler GmbH, Germany: invoicing and payment reconciliation, receiving master data only and no training documents. All four process within the European Union or Switzerland. In the data processing agreement the customer grants general authorisation under Article 28(2) GDPR; any change is announced in advance in text form, and objection on serious grounds is possible within 14 days. Under Article 28(4) GDPR sub-processors are bound by the same data protection obligations.

What remains inside the model

This is where the reassuring part ends. In its Opinion 28/2024 the European Data Protection Board states that information from the training set, including personal data, may remain absorbed in the parameters of a model, represented there as mathematical objects, and may be obtained from it by means reasonably likely to be used. Models trained on personal data therefore cannot be considered anonymous in all cases; this has to be assessed case by case. The opinion also names the risk of training content being regurgitated in outputs.

IonKon's own impact assessment rates exactly this as the most significant risk of the processing, classified as medium to high. Automatic removal of personal data before the training examples are generated reduces the risk but does not eliminate it, because no automatic detection of such data works without error. Three practical consequences follow.

Select the material you upload according to what the model should know, not according to what happens to be at hand. Treat the result as an internal assistance system and do not base decisions about individuals on its outputs. Special categories under Article 9 GDPR are excluded by the data processing agreement and require a separate written arrangement.

When you need an impact assessment of your own

Article 35(1) GDPR requires a data protection impact assessment where processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. Guidelines WP 248 rev.01, adopted by supervisory practice, list nine criteria and the rule of thumb that meeting two of them will in most cases indicate an obligation.

A training project typically combines large-scale processing (criterion 5) with innovative use or application of new technological solutions (criterion 8). The list agreed among the German supervisory authorities for the private sector additionally names, under number 11, the use of artificial intelligence, there in relation to steering interaction with data subjects and evaluating personal aspects; whether your project falls under it is a question of the individual case.

The obligation falls on the controller, which means you. IonKon supports you in this under Article 28(3)(f) GDPR and provides its own assessment of the processing as a basis.

What is contractually committed

The data processing agreement is concluded before the first upload. The technical and organisational measures under Article 32 GDPR form Annex 1 to that contract and describe access control at system and permission level, separation, encryption, logging and the deletion concept. If IonKon becomes aware of a personal data breach affecting your data, it notifies you without undue delay and no later than 48 hours after becoming aware, so that you can meet your own 72-hour deadline under Article 33 GDPR. You may carry out audits once a year and whenever there is a specific reason, with on-site inspections announced 14 days in advance. Access to production systems is restricted to two individually documented persons.

This article describes the state of the processing and does not replace legal advice. The binding documents are the data processing agreement including the annex on technical and organisational measures, and the IonKon privacy policy.

Sources

This article reflects the state of affairs on the date given and does not replace legal or tax advice. Our terms and conditions, the data processing agreement and the privacy policy are binding.

All articles
Where your documents go while a model is being built · IonKon