User input goes to your ocatis server, is encrypted and forwarded to the model provider you configured with your own keys. Conversation content is stored in your own database in your own infrastructure. ocatis is a control plane, not a data processor for AI content.
Roles and responsibilities
Role
Who
What
Controller
Customer
Determines purposes and means of processing
Provider / processor
itcv GmbH (EU) or ORDIS Co., Ltd. (RoW)
Supplies the platform and hosting where agreed
A Data Processing Agreement (AVV) and a sub-processor list are available for EU customers on request.
Data subject rights
Right
How ocatis supports it
Art. 15 Access
Administrators can export user data
Art. 16 Rectification
Users edit their own profile
Art. 17 Erasure
Administrators delete users and conversations
Art. 20 Portability
Structured data export in Enterprise Edition
Art. 21 Objection
Model enablement rules restrict specific processing per scope
Art. 22 Automated decisions
Human-in-the-loop MCP tool policies: Ask and Deny
Third-country transfers
When you configure a US-based model provider, your prompts are transmitted to that provider. ocatis makes this explicit and governed: administrators decide which providers are available. Standard Contractual Clauses between you and your provider are your responsibility, since you bring your own keys. Local-only inference with Ollama or LM Studio means no third-country transfer at all.
Technical and organizational measures
Encryption at rest (AES-GCM) and in transit (TLS), role-based access control with per-group and per-organization isolation, audit logging in Enterprise, encrypted credential vault, configurable retention per deployment, regular security reviews.
EU AI Act readiness
ocatis is a general-purpose AI system in the sense of Regulation (EU) 2024/1689. Model documentation and training-data summaries come from your providers. ocatis contributes the governance layer that helps organizations meet transparency and oversight obligations: model enablement, tool policies, reasoning controls and audit trail.