Regulatory Compliance
UBava is built on a foundation of regulatory compliance. Our VHH Privacy Air-Lock cascade ensures GDPR compliance by design — personal data never leaves your jurisdiction unprotected.
General Data Protection Regulation
Regulation (EU) 2016/679Privacy by design via the VHH cascade. PII is tokenized locally before any data reaches external AI providers. No personal data crosses jurisdictional boundaries.
EU Artificial Intelligence Act
Regulation (EU) 2024/1689AI literacy policy implemented under Article 4. Transparency obligations and provider requirements under Articles 16–50 in active preparation.
ePrivacy Directive
Directive 2002/58/ECCookie consent implementation with granular user controls. Only essential cookies are set without explicit consent.
Estonian Personal Data Protection Act
Isikuandmete kaitse seadusFull compliance with Estonian national data protection law. Supervisory authority: Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate).
Data Minimization
Article 25 — Only synthetic tokens are transmitted to AI providers. Real PII never leaves the local tokenization layer.
Purpose Limitation
Data is processed exclusively for the stated AI query purpose. No secondary use, no profiling, no analytics on personal data.
Storage Limitation
Token mappings exist only for the duration of the request-response cycle. No persistent storage of PII on relay infrastructure.
Integrity & Confidentiality
AES-256-GCM encryption on every packet. Tokenized data is cryptographically separated from its real-world referents.
Data Protection Contact
Supervisory Authority
Andmekaitse Inspektsioon
Tatari 39, 10134 Tallinn, Estonia
Company
UBava OÜ
Tallinn, Estonia
Registry Code: Pending Registration