Skip to content
Contact

Compliance

A robot that talks to people touches two pieces of legislation: the General Data Protection Regulation and the EU AI Act. This page says what that means in practice on our side, and what you need to have ready on yours.

The short answer

  • The visitor is told they are talking to a machine.
  • We use no biometrics and do not offer them even as an option.
  • Speech recognition, the language model and voice synthesis run with providers inside the EU.
  • Robot behaviour is a written graph of steps that can be printed and filed with the procurement documents.

01 — Data protection

GDPR in a deployment

Who is the controller

At your site you are the controller and we are the processor. The data processing agreement is part of the deployment and is signed with the order, not sent afterwards.

What is processed during a conversation

Speech is turned into text so the robot can answer. What is kept, for how long and who can reach it is your decision and is written into the processing agreement. If you do not want anything kept, we switch it off and verify the setting on the machine itself.

No biometrics

The robot does not recognise faces, does not score emotions and does not sort people by characteristics. We do not build that in even when a customer asks for it.

Where the data runs

The voice layer runs with providers inside the EU. You get the named list of processors and their processing locations before you sign, not on request afterwards.

Visitor rights

Questions about data collected at a site go to the controller, which is the owner of the space. As processor we help them answer inside the deadlines the regulation sets.

02 — AI Act

What the EU AI Act requires

Transparency

A person must know they are talking to a machine. The robot says so itself, and the notice on the machine is part of the deployment rather than a label printed later.

Prohibited practices

Emotion recognition in the workplace and in education is prohibited, and so is biometric categorisation of people. We do neither, so that conversation does not arise here.

Risk classification

Our robots inform, guide and carry. They do not make decisions about people, do not screen candidates and do not judge access to services. We still write the classification down for each deployment rather than assuming it.

Behaviour known in advance

Behaviour is a graph of steps drawn by an operator, and every step has an explicit condition for moving on. The graph prints and goes into the file. A free-running language model cannot give you that.

AI literacy

Staff working with the robot have to know what it can and cannot do. Training at handover is part of the deployment, not an extra service.

What we do not claim

This text is not legal advice and we do not sell it as such. What is written here are our commitments and the documents you receive with a deployment. Your own lawyer still has to look at your site and your case.

The robot supports your staff and never replaces them. That is not only a sales line: it is exactly why the robot makes no decisions about people and does not fall into the high-risk class.

Behaviour known in advance

Questions

What the legal team asks

Does the robot record visitors?
The robot needs a microphone and a camera to do its job. What is kept, for how long and who can reach it is decided at deployment and written into the processing agreement. If you do not want anything kept, we switch it off and verify the setting on the machine, not only in the document.
Do you use facial recognition?
No, and we do not offer it as an option. The robot does not know who is standing in front of it, and that cannot be turned on with a setting.
Where is the voice processed?
Speech recognition, the language model and voice synthesis run with providers inside the EU. It is the condition that opens the door to large companies and the public sector, and the reason we built that layer ourselves.
What do I need to prepare as the customer?
An entry in your record of processing activities, a visitor notice in a visible place, and a person who answers questions about data. We give you a template for all three.
Is the robot a high-risk AI system?
For the jobs it does with us, no. It informs, guides and carries, and it makes no decisions about people. We still write the classification for each deployment separately, because it follows the purpose and not the machine.
Do I get conformity documentation for the machine?
Yes, before handover. Where a document for a particular model is still in progress we say so up front and do not promise a date we cannot keep.
Can I see what the robot has been doing?
Yes. The console shows where it was, what it did and when. The log exists to run the machine, not to watch visitors.
Who is liable if the robot says something wrong?
You approve the content and the behaviour is written in advance, so the origin of a mistake can always be shown. What the model must not say on its own is locked in the graph rather than left to a prompt.

Send us your compliance questions.

The form is at the bottom of this page. If you are writing from a legal team, say so in the message and we answer with the processing agreement and a description of the behaviour graph rather than a presentation.

Go to the form

Enquiry

Tell us where the robot should stand.

Buying or renting, a shop or a trade fair. Two sentences are enough — we reply within two working days, by email, without a call.

Or directlyinfo@vandri-robotics.com

We store this enquiry only to answer it. No marketing, no profiling. More on privacy

or write to us directly at info@vandri-robotics.com