Leexi on iOSLeexi on Android

Compliance and Sovereignty FAQ

  • Evidence-backed answers to your DPO’s questions before adopting Leexi.
Try for free
Documented answers on compliance and sovereignty before adopting Leexi: hosting in France, no AI training, ISO 27001, DPA, consent.

Summary

This FAQ provides exact answers to questions a professional buyer and their DPO ask before purchasing an AI note-taking tool. It distinguishes three legal strength levels: what the law requires (GDPR, AI Act), what clients demand beyond the law (ISO 27001, European hosting), and sector-specific rules (health, public). Each answer is supported by proof. No compliance claim is made without backing facts. Technical terms (DPA, closed circuit, diarization) are defined in the AI note-taking tool glossary.

Neither ISO 27001 nor hosting in France are universal legal obligations. Clients demand them, and two sectors require them: health and public.

Key takeaway: AWS Paris hosting, Scaleway option beyond certain license volumes, LLM (OpenAI) run via Azure France in a closed circuit, no training on client data, encryption in transit and at rest, ISO 27001 certified, ISO 42001 in progress, NIS2 finalizing, aligned with EU AI Act, DPA and subcontractor list and ISO certificate available on request, about 10,000 European companies use it, Belgian company.


1. Data Location and Hosting

Do my data leave the European Union?

No for storage and processing, which remain in France. The nuance concerns the infrastructure provider: storage region is European, but AWS is a US company (see Cloud Act question). For strict sovereignty (entity not subject to extraterritorial laws), Scaleway option meets the need.

What exactly is "sovereign" hosting?

A demanding buyer checks three things: datacenters physically in France, a French or European legal entity not subject to extraterritorial laws, and European capital control. AWS Paris hosting meets physical location but not immunity from extra-European laws. Scaleway option meets all three.

Is hosting in France a legal obligation?

No, not generally. GDPR does not require data to stay in France or Europe for most processing. Sovereign hosting is mandatory only for some sectors: health data (via HDS-certified host) and public sector for sensitive data (SecNumCloud path, SREN law). Otherwise, it’s a growing buyer demand; not legally imposed.


2. AI Training

Does Leexi train its AI on my meetings?

No. Your conversations are not used to train models. This applies to all accounts by default. It’s also the first technical check and a reason buyers shortlist Leexi after excluding US tools.

Is Leexi "based on ChatGPT"? Do my data go to OpenAI?

The language model is from OpenAI but runs via Azure France in a closed circuit. Your data aren’t used to train the model nor exposed to third-party use. Closed circuit means processing stays within a controlled perimeter in France.

How to prove this to my DPO?

Leexi documents this in its compliance file, with DPA and subcontractor list. No-training is stated explicitly.


3. Certifications and Standards

What other certifications does Leexi hold or prepare?

ISO 42001 (AI management system) is underway. NIS2 compliance is finalizing. Leexi aligns with EU AI Act. Regular audits occur, including by clients.

Is NIS2 or ISO 27001 the legal security obligation?

NIS2, not ISO 27001, carries the legal security obligation for "essential" and "important" entities. ISO 27001 is a means to comply, not the obligation itself.

Is Leexi SecNumCloud qualified?

Not yet. SecNumCloud (ANSSI) certifies higher security and immunity to extraterritorial laws, mainly for public sector sensitive data (SREN law). Not required for standard B2B use.


4. DPA, Subcontractors, and Purchase Proofs

Does Leexi sign a Data Processing Agreement (DPA)?

Yes. The DPA is provided. It’s a key document buyers request to demonstrate their processing oversight.

What documents does Leexi provide for purchase or tender files?

DPA, subcontractor list, ISO 27001 certificate, hosting location. These are exactly the proofs buyers require in 2026: DPA, audit rights or third-party compliance reports, location, subcontractor list. Without these, suppliers are excluded.


5. Consent and Participant Information

Must participants be informed a meeting is recorded?

Yes. GDPR and EU AI Act require informing participants that a meeting is recorded and an AI assistant takes notes. A simple "this meeting is recorded" is insufficient: AI use must be mentioned in the invite, orally at meeting start, and visibly during the meeting.

What is the legal basis to record a meeting?

It depends on context. Internally, employer may rely on legitimate interest with a balancing test and prior info: employee consent is rarely "free" due to subordination. For client or external calls, explicit consent is usually required. Recording and transcribing without legal basis, prior info, and controlled retention is illegal.


6. Transfers Outside EU and Cloud Act

Can the US Cloud Act apply to my data with Leexi?

This is the right question. Your data are stored in France, but AWS is a US company, theoretically subject to Cloud Act. For strict sovereignty aiming at immunity from extraterritorial laws, Scaleway (French actor) is the suitable option. Leexi does not claim AWS Paris hosting is immune to US law; it offers the alternative for those who require it.

How is this different from US tools like Otter or Fireflies?

A tool hosting and processing everything in the US falls under post-Schrems II transfer rules and must rely on Data Privacy Framework. The consent model of some US tools, where one participant triggers recording for all, is fragile under GDPR articles 6 and 7. Leexi stores and processes in France and enforces default consent. The comparison is only versus US tools, e.g. AI note-taking tool alternatives for Teams.


7. Technical Security

Are my data encrypted?

Yes, in transit and at rest.


8. EU AI Act

What does the EU AI Act change for choosing an AI note-taking tool in 2026?

Choosing an AI tool is primarily a legal decision. Companies must map AI tools, conduct impact analyses for sensitive uses, and verify supplier compliance. Supplier must prove compliance and provide audit rights or third-party reports. It’s a double lock with GDPR.

Is Leexi compliant with the EU AI Act?

Leexi aligns with EU AI Act, notably transparency (assistant visible in meeting, participant info) and prepares ISO 42001 structuring AI management. US tools lack these constraints, a real differentiator.


9. Sovereignty: Demand and Discourse

Why has data sovereignty become a buying criterion?

Because initial dependence is massive and decision-makers realize it. About 70% of European cloud market is with AWS, Azure, Google; nearly 80% of European cloud spend goes to US providers; about 70% of French data hosted outside EU. This dependence fuels demand for a European alternative, and public markets increasingly favor certified European solutions.

Is Leexi a credible sovereign alternative to US tools?

Leexi is a Belgian company, stores and processes in France, enforces default consent, holds ISO 27001, and offers sovereign hosting with Scaleway. For buyers excluding US tools over data transfer, it’s often the entry point.


10. By Sector

I work in or with the public sector. What should I check?

Public sector follows SecNumCloud path for sensitive data, framed by SREN law, with storage territoriality and strengthened contractual clauses. Leexi is not SecNumCloud qualified yet: for sensitive public data use, this is critical. For routine administrative use excluding sensitive data, France hosting and ISO 27001 meet main requirements.

I am a lawyer, consultant, HR, or accountant. Am I concerned?

Yes, due to confidentiality of data handled: client files, candidate data, financial info. GDPR obligations (legal basis, info, retention) fully apply, and your clients may require guarantees on location and no training. Here, France hosting, no training, and Leexi’s DPA directly meet your needs.


11. Documents to Provide Your DPO

What exactly do I give my DPO to validate Leexi?

Six documents Leexi provides: hosting location (France, AWS Paris, Scaleway option), no-training attestation, ISO 27001 certificate, DPA, subcontractor list, and retention policy. This is the file you pass to your DPO. While internal validation proceeds, you can test Leexi on a real meeting.

Recommended Articles

Ready to boost your productivity with Leexi?

Leexi AI Notetaker takes notes for you

Discover here