Loading...

Compliance

Built for organisations where compliance is not optional

Mnemo is designed from the ground up for professional organisations operating under regulatory obligations. This page covers our compliance posture in plain terms — for compliance officers, procurement teams, and anyone doing formal due diligence.

Compliance areas covered

UK GDPR & EU GDPR

Mnemo processes personal data only as described in our Data Processing Agreement. Arion Flow Ltd acts as the data processor; your organisation remains the data controller. We operate under GDPR Article 28 contracts. Deployment is EU-based with UK GDPR alignment. Data residency is configurable to meet your jurisdiction requirements.

EU AI Act awareness

Mnemo is a retrieval-augmented AI system, not a general-purpose AI tool. It does not make autonomous decisions that affect individuals — it assists human knowledge workers by surfacing relevant document content. This classification places it outside the high-risk AI system categories under the EU AI Act. We monitor ongoing regulatory developments and update our practices accordingly.

Audit logging

Every query, every document upload, every permission change, and every login is logged with a timestamp and user identifier. Audit logs are immutable and available for export. This supports internal governance requirements and external audit obligations, including FOI compliance for public sector customers.

Access controls

Access is managed at the workspace level using role-based permissions. Administrators set who can view, query, or manage each workspace. Permissions can be restricted to named individuals. All access is authenticated via your chosen identity provider. There is no anonymous access to any document or query interface.

Data residency

Mnemo is deployed in EU-based infrastructure by default. UK-only deployment is available. No document content, query data, or user data is processed or stored outside the agreed jurisdiction. We do not use multi-region replication that would move data across jurisdictional boundaries without explicit agreement.

No training on your data

Your documents are never used to train or fine-tune any AI model — ours or anyone else's. The AI models used by Mnemo are not updated or modified based on your queries or document content. This is a hard architectural guarantee, not a policy preference.

What data Mnemo processes

Understanding what data enters and leaves Mnemo is essential for any compliance assessment. Here is a clear breakdown.

Document content

The text of files you upload or connect. Stored and indexed within your deployment environment. Not shared externally.

User account data

Name, email address, organisation, and role. Used for authentication and access control. Retained for the life of the account.

Query data

Questions asked through the knowledge assistant and the responses generated. Logged for audit purposes. Not used for model training.

Usage metadata

Timestamps, document counts, and query volumes. Used for system monitoring and billing. Contains no document content.

For procurement teams

Common questions we receive during procurement and security assessments:

Do you have a Data Processing Agreement?

Yes. Our standard DPA is available at arionflow.com/legal/data-processing. We can also execute customer-supplied DPAs on request.

Where is data stored?

EU-based infrastructure by default. UK-only deployment is available. We will confirm the specific region(s) in writing as part of contracting.

Who are your sub-processors?

Our current sub-processor list is included in the DPA and updated whenever we make changes. We provide 30 days' notice of any new sub-processors.

Do you hold any security certifications?

We are working towards ISO 27001 certification. Our current security controls are documented and available under NDA for formal procurement processes.

What happens to our data if we stop using Mnemo?

On termination, we delete all customer data within 30 days. You can request an export of your indexed documents at any point before termination.

Need more detail for a formal assessment?

We are familiar with procurement questionnaires, supplier due diligence processes, and information security assessments. Get in touch and we will provide what you need.

Contact Us