AI processing in Germany
Every step of AI processing at Sally happens on Sally's own large language model, operated end-to-end in our own infrastructure in Germany. No external AI providers are involved and meeting content, transcripts and metadata stay inside our systems at every step: the language model, the databases, the backups.
How AI processing works
Meeting audio is transcribed by our in-house Whisper-based model on our own GPU servers at Hetzner in Germany. No third-party AI provider is involved.
Transcripts are then processed by Sally's own large language model, hosted on the same infrastructure in Germany. Every prompt and every response stays inside our systems.
Results are written back to the Sally database in Germany over an encrypted connection and stored encrypted at rest. Data never leaves Germany.
What this means in practice
Inference runs on Sally's own language model, operated end-to-end in our own infrastructure in Germany. No external AI providers involved.
Customer data is never used to train or improve our models, contractually and technically.
Optionally configure Sally to use your organization's own language models, so no data ever leaves your infrastructure for AI processing.
The safeguards that apply
The technical and organisational measures in Annex 1 of the DPA apply to the entire processing chain including AI inference: encryption at rest with AES-256, TLS 1.3 transport encryption, role-based access control, strict multi-tenancy separation, audit-proof logging, and confidentiality obligations for all Sally staff with access to customer data.
If your organization connects Sally to external AI tools via MCP (Claude, ChatGPT, etc.), that data flow leaves Sally's controlled environment. See External AI Tools (MCP) for the responsibility split when data crosses that boundary.
See also: Hosting & Subprocessors for where AI processing happens, and the TOMs PDF for the technical control reference.