Built for GDPR & the EU AI Act

Trust Center

Saga helps business leaders run strategy and intelligence with AI. Because that work touches board-level and financial decisions, we build it compliance-ready by design — with security, data governance, and AI transparency at the core.

Last updated: March 2026

A note on what “compliant” means. No software can, on its own, make an organisation “fully compliant” or “certified” — that always depends on how you deploy it and requires your own DPO / legal sign-off. What we provide is a platform engineered so that compliance is achievable: the controls, transparency, and data rights are built in. We deliberately say compliance-ready, never “certified” or “fully compliant”.

Trust at a Glance

Key information.

Posture
Compliance-ready by design
Frameworks
GDPR + EU AI Act (Art. 50)
Hosting
Enterprise infrastructure, AWS EU
AI Training
Customer data never used to train external models
Data Rights
Self-service export & deletion

How We Build Trust

Compliance and security, by design.

Built for GDPR

Lawful-basis-driven processing, data minimisation, and EU-region hosting. Data subjects can exercise access (Art. 15), portability (Art. 20), and erasure (Art. 17) — the last two are real self-service actions inside the product, not a support ticket.

Built for the EU AI Act

Saga surfaces AI assistance transparently under Article 50: AI-generated strategy, analysis, and facilitation output is labelled as AI-assisted and asks a human to verify before it is acted upon. Critical outputs keep a human in the loop.

Security

Encryption in transit and at rest, scoped access controls, and per-tenant data isolation. Every request is authenticated and every data query is scoped to your organisation so leadership material never leaks across accounts.

Executive & financial controls

Board-level and financial discussions demand discretion. Workspace content is isolated per organisation, is never used to train external AI models, and stays governed by your service agreement and, where applicable, a signed DPA.

Data governance & residency

Personal and workspace data is processed on enterprise-grade infrastructure in AWS EU regions, with sub-processors bound by data processing agreements and retention limited to what each purpose requires.

Portability & control

You can download a machine-readable JSON copy of your account and workspace data at any time, and permanently delete your account — which cancels billing and erases your workspace — directly from Account & Privacy.

Your Rights

Real, self-service data rights.

01

Access & portability (Art. 15 / 20)

Download a structured JSON export of your profile, organisation, and workspace content from Account & Privacy in the app — no request queue, generated on demand.

02

Erasure (Art. 17)

Permanently delete your account with a typed confirmation. We cancel any active subscription first, then erase your workspace and personal data. The action is irreversible by design.

03

AI transparency (AI Act Art. 50)

AI-assisted output is clearly labelled and asks you to verify before acting. Saga is a decision-support tool for leaders — a human always stays accountable for the decision.

04

Correction & objection

You can update your profile in the app, and you can contact us to rectify, restrict, or object to processing, or to lodge a complaint with a supervisory authority.

Data Controller

INSTRAT Technology ApS

Saga is a platform of INSTRAT Technology ApS, registered in Denmark. For security, compliance, or DPA inquiries, contact ale@instrat360.com.

Contact trust team