Trust center
Roles: provider and deployer
Localign is the provider of the AI system. The customer is the deployer. Each role carries specific obligations under the EU AI Act, and the AI Annex makes the split explicit.
Mode A and Mode B
In Mode A, no personal data is shared with external AI models. In Mode B, customer-approved external AI models may be used after the customer's organisational approval and explicit per-prompt consent. Sensitive-data detection runs before forwarding under Mode B.
Prohibited practices
The customer attests at signing that the product is not used for practices prohibited under article 5 AI Act, including subliminal or manipulative techniques, exploitation of vulnerabilities, social scoring, untargeted face scraping, emotion recognition in workplaces or education, biometric categorisation by sensitive traits, and real-time remote biometric identification outside the article 5 exceptions.
High-risk deployer obligations
Where the deployer's use qualifies as high-risk, the customer commits to a fundamental rights impact assessment where required, human oversight, use in line with the instructions for use, retention of logs and information of data subjects where the regulation prescribes.
No training or fine-tuning
Localign does not process personal data to train, improve or fine-tune its own or any third-party AI models. Contracts with external model providers under Mode B include a corresponding training and fine-tuning prohibition.
How the product enforces it
Mode A is the default and is enforced in code: the orchestrator does not call any external model unless the customer's organisation has activated Mode B and the end user has given explicit per-prompt consent. Before any forwarding under Mode B, a sensitive-data scan blocks the request if it carries personal data the user has not approved for the chosen provider. Customer attestation against article 5 prohibited practices is captured at signing and re-affirmed in the AI Annex.
Logs and traceability
Every conversation and tool call is recorded with a stable trace identifier so the deployer can reconstruct what happened during a high-risk use under article 14 oversight. Conversations also continue to completion if the user's tab disconnects mid-answer, so accidental browser refreshes never silently drop a session that already touched personal data.
Sectoral overlays
Where the deployer operates in healthcare, legal services, education, government or financial services, additional sector rules apply on top of the AI Act. See the dedicated Sectoral annexes page for the named annex Localign attaches to your contract per sector.