Trickhouse

Enterprise · Data sovereignty

Generative AI with
control over your data

Where data is processed, which model sees it and who has access are not side questions in generative AI. They shape the architecture. This page describes the available operating models and how we assess them in projects.

Get in touch
01

Data protection is an architecture question

With generative AI, data protection cannot be added to an existing tool afterwards. It is defined in the architecture: which data leaves the company, which services process it, how long inputs and results are stored and who may access them.

Generative AI adds a few particulars. Inputs can contain personal data, trade secrets or image rights, and depending on the provider, separate terms apply to further processing. The legal assessment belongs with your data protection and legal advisers. Our job is to make sure the technical implementation can reflect the requirements.

02

Three operating models compared

There is no single right model. The choice depends on the kind of data, the volume, company policies and the IT you already have.

External services (SaaS)

The provider runs the model and the infrastructure.

  • Quick start without your own infrastructure
  • Data is processed under the provider's terms
  • Model and version changes are up to the provider
  • A fit for non-critical content

Rented GPU infrastructure in Europe

Models run on servers provided for you.

  • Custom workflows with open-weight models
  • Access, logs and versions under your control
  • Costs follow the compute time you use
  • Operated together with your IT

Your own infrastructure (on premises)

Models run inside your own network.

  • The highest degree of control over data and operation
  • Purchase, operation and maintenance of the hardware are yours
  • A fit for very sensitive data or an existing data centre setup
03

Model choice: open weight and open source

We prefer open-source software and open-weight models. With open-weight models the model weights are available and can be run yourself. That is not the same as open source in the strict sense: licences differ, for example on commercial use, and we check them before a project starts.

The advantage lies in control over version and operation, less dependence on single providers and the ability to adapt, for example with trained models for a consistent brand face. The limit: not every open-weight model matches the best proprietary service on every task. We assess this per use case and show you the differences on your own material.

04

Rights, roles and traceability

Besides the place of processing, control during operation decides.

Roles and permissions

Who may start jobs, approve results or change workflows is defined and enforced technically.

Logging

Jobs, versions and approvals stay traceable so results can be explained later.

Data minimisation

Only the data a task needs goes into a workflow. Retention and deletion are agreed in advance.

Labelling

Generated content is labelled, for example in line with the requirements of the EU AI Act. Results can be given metadata for this purpose.

05

How we proceed

We first clarify your requirements: which data occurs, who uses the system and which rules apply in the company. From that we draw up a sketch of the data flows and a recommendation for the operating model. Then we implement the workflow, hand it over with documentation and train the users.

We do not give legal advice or a blanket assurance of legal compliance. Compliance does not come from a tool but from data flow, contracts and purpose. An example of an implemented environment is the enterprise platform for generative image and video AI.

Frequently asked questions

Does data sovereignty mean everything has to run on premises?

No. On premises is one model of several. For many applications rented GPU infrastructure in Europe is enough, and for non-critical content an external service can be too. What matters is that the choice fits the kind of data on purpose.

Where is data processed in Trickhouse projects?

We decide that per project together with you: on your own or rented GPU infrastructure, in European cloud environments or on premises. We put the data flows in writing.

Are open-weight models suitable for commercial use?

That depends on the individual model and its licence. Some allow commercial use without restriction, others attach conditions. We check the licence before a model is used.

Does that make a solution GDPR compliant automatically?

No. Compliance results from purpose, legal basis, contracts and data flow, not from a single tool. We provide the technical foundation, the assessment stays with your data protection and legal advisers.

How does Trickhouse deal with the EU AI Act?

We take labelling, documentation and the relevant evidence into account from the start in each process. Which obligations apply to your company is for your legal advisers to assess. In consulting we support the practical implementation.

Ready for your next project?

Tell us briefly what you want to achieve with generative AI. We advise you on content production, digital twins, AI workflows and integration, and get back to you within 24 hours with an initial assessment.

Get in touch