YPAI
Services Data Industries Company
AI Data & Evaluation
Data collection and sourcing Consent-led multimodal collection. Dataset licensing Rights-cleared datasets, ready to license. Annotation and curation Labelling, review and adjudication. Model and agent evaluation Human evaluation and regression testing. Explore AI Data & Evaluation Create, source and evaluate the data your AI depends on.
AI Implementation
Discovery and architecture Scope the use case and the system design. RAG and knowledge systems Retrieval over your own knowledge. Agents and workflow automation Agents and automation in production. Private and enterprise deployment Private, controlled deployment. Explore AI Implementation Turn a defined AI use case into a system you can operate.
Delivery
Connected Delivery Data, evaluation and implementation under one structure. Pilots Validate the delivery method before scale.
Explore all services
AI Data & Evaluation
Speech & Audio Data Multilingual speech, acoustic environments and voice data. Image, 3D & Sensor Data Images, documents, multi-view data, LiDAR and sensor fusion. Video, Physical AI & Robotics Data On-camera, conversational, egocentric and robotics data. Dataset Licensing & Sourcing Rights-cleared datasets, bespoke sourcing and acquisition. Annotation & Data Production Ontology design, labelling, review and model-ready delivery. Model & Agent Evaluation Human evaluation, multilingual testing and failure analysis.
Explore AI Data & Evaluation
Operating conditions
AI Companies & Model Developers Training data, preference data and evaluation loops. Automotive & Mobility In-cabin speech, perception, video and sensor data. Financial Services Document AI, knowledge systems and traceability. Healthcare & Life Sciences Specialist data, domain review and privacy-sensitive work. Industrial & Energy Field data, operational workflows and integration. Public Sector Controlled data operations and reviewable AI systems.
Explore industry solutions
Company
About YPAI Company, mission, operating model and delivery history. Partnerships Commercial, technology and delivery collaboration. AI Blog Research, technical perspectives and company updates. Contact Projects, partnerships, procurement and general enquiries.
Become a Contributor Contact us
YPAI
AI Data & Evaluation
Data collection and sourcing Dataset licensing Annotation and curation Model and agent evaluation Explore AI Data & Evaluation
AI Implementation
Discovery and architecture RAG and knowledge systems Agents and workflow automation Private and enterprise deployment Explore AI Implementation
Delivery
Connected Delivery Pilots Explore all services
AI Data & Evaluation
Speech & Audio Data Image, 3D & Sensor Data Video, Physical AI & Robotics Data Dataset Licensing & Sourcing Annotation & Data Production Model & Agent Evaluation Explore AI Data & Evaluation
Operating conditions
AI Companies & Model Developers Automotive & Mobility Financial Services Healthcare & Life Sciences Industrial & Energy Public Sector Explore industry solutions
About YPAI Partnerships AI Blog Contact
Contact us Become a Contributor

Data residency

EU residency, defined operationally

Last updated: July 2026

YPAI operates from Norway (EEA) under GDPR jurisdiction and EU AI Act Article 10 alignment. This page documents what that means for storage, sub-processors, access, and cross-border requests, so the residency posture can go into a vendor risk file without a follow-up questionnaire.

On this page

  • 1. Legal entity and jurisdiction
  • 2. Storage and regions
  • 3. Access model
  • 4. Sub-processors
  • 5. Transfers and requests
  • 6. Erasure at closeout
  • 7. Restricted deployments
  • 8. Frameworks

1. Legal entity and jurisdiction

Entity
Your Personal AI AS, Norwegian Aksjeselskap
Org. nr.
933 915 778 (Brønnøysundregistrene)
Headquarters
Oslo, Norway
US entity
None
CLOUD Act
Not a US-domiciled provider

EEA membership applies and GDPR is the primary regulatory framework. As a Norwegian AS with no US corporate entity, YPAI is not a US-domiciled provider under the CLOUD Act. Cross-border disclosure requests are handled through EU mutual legal assistance treaties.

2. Storage and regions

Default
EEA cloud regions
Region binding
At provisioning, documented in the DPA residency annex
On-premise
Available for restricted deployments

Storage, processing, and contributor pools are bound to the agreed regions at provisioning, and the sub-processor list is locked before collection begins. The buyer documents residency requirements, allowed regions, and restricted sub-processors at scoping; the output is the residency annex to the DPA.

3. Access model

Access is role-based, audit-logged, and scoped to named YPAI personnel and approved sub-processors. Cross-region access (for example, a US partner reviewing a delivery) requires documented justification and buyer notification before it occurs.

4. Sub-processors

The sub-processor list is disclosed at scoping and locked into the DPA. Buyers can require approval of any changes. The list typically includes EEA-resident cloud infrastructure providers, identity verification vendors, and payment processors for contributor compensation.

5. Transfers and cross-border requests

Standard Contractual Clauses are available for any required cross-border transfer. Residency, access locations, and transfer mechanisms are defined per engagement and documented in the DPA. Cross-border disclosure requests are handled through EU mutual legal assistance treaties.

6. Erasure at closeout

Erasure SLA
Contractual, default 30 days from request
Attestation
Delivered as part of project closeout
Tightening
Buyers can set tighter SLAs at scoping

Data erasure runs on request inside the contractual SLA, and the erasure attestation is delivered with the project handover.

7. Restricted deployments

Tighter residency requirements for healthcare and other restricted projects are assessed during scoping. Available controls and operational constraints are documented in the project DPA and reflected in the delivery plan.

8. Frameworks this page is written against

Framework Scope
GDPR Article 6 lawful bases, Article 28 DPA, Article 33 breach notification
EU AI Act Article 10 data governance, August 2, 2026 high-risk applicability
SCCs Standard Contractual Clauses available for any required cross-border transfer
Jurisdiction Norwegian AS (EEA); transfer controls defined per project

Documentation depth is matched to the buyer's risk profile at scoping.

Request a sovereignty assessment Request the DPA
How YPAI processes customer and project data · Speech data DPA overview · Speech data residency

Start with the requirement, not a predefined package.

Bring the objective, current system or dataset, and known operating constraints. YPAI will map the appropriate service line, delivery structure and first validation step.

Contact us Scope a pilot

AI systems, data and evaluation under one accountable delivery model.

New projects · accepting data and AI requirements
Engagement scoped before build
Acceptance defined before delivery
Services
AI Data & Evaluation AI Implementation Controlled Delivery Dataset Licensing
Capabilities
Speech & Audio Image, 3D & Sensor Data Video Data Annotation & Evaluation
Company
About YPAI Partnerships Contact Become a Contributor
Resources & Legal
AI Blog Privacy Terms Cookie Policy Data processing
YPAI · Org. nr. 933 915 778 · Oslo, Norway · Global delivery
Disclaimer LinkedIn ↗ GitHub ↗
EEA-BASED PROCESSING AVAILABLE WHERE REQUIRED · ARTICLE 28 DPA TERMS AVAILABLE
© 2026 YPAI
Install YPAI Faster reopens, offline shell, share-target ready.

Add YPAI to your home screen

Tap the Share button, then Add to Home Screen.