Enterprise Services

AI data and infrastructure. Audit-ready by default.

YPAI builds the consent records, lineage chains, and QA evidence regulated buyers need: EU AI Act Article 10 conformance, GDPR Article 7 consent basis, EEA-only operations.

GDPR Art. 7 EU AI Act Art. 10 EEA jurisdiction ยท DPA included
Sample delivery manifest .json
delivery_id
"ypai-2026-Q1-AB12"
modality
"speech | image | video | lidar | text"
jurisdiction
"EEA / Norway"
consent
{ record_id, signed_at, basis: "GDPR Art. 7" }
lineage
{ collected_at, contributors, devices }
qa
{ sample_rate, ai_act_article: "10", reviewers }
dpa
"included"
delivery_format
"JSON-LD + manifest.sha256"
checksum verified consent attested dpa signed
150+

Languages covered

Speech, audio, text, multilingual NLP

40,000+

Vetted contributors

Identity-verified, consent-bound

100%

Human QA coverage

Every dataset reviewed before delivery

EEA

Operating jurisdiction

Norway-operated ยท zero US CLOUD Act exposure

Operating layers

One engagement model across data, infrastructure, and governance.

01

Data Production

Multimodal training data collected and annotated with consent records, provenance, and quality controls attached from the start.

  • Speech and audio
  • Image and video
  • Text and NLP
  • Sensor data

Speech, image, video, LiDAR, text, eval. 150+ languages with identity-verified contributors.

02

AI Infrastructure and Development

Data pipelines, model workflows, and deployment environments for buyers that need residency, auditability, and operational control.

  • Pipeline design
  • Voice platforms
  • Multimodal workflows
  • Custom deployment

EEA-only data planes. SHA-256 manifest on every delivery. Aligned to EU AI Act Article 10.

03

Enterprise Consulting and Deployment

Governance, architecture, and delivery support for AI deployments that must satisfy procurement, legal, data, and security stakeholders.

  • Governance frameworks
  • Risk notes
  • LLM workflows
  • Delivery documentation

GDPR Article 7 consent records. 30-day erasure SLA. DPA included with every engagement.

Service groups

Structured around how enterprise data work is bought.

The top-level menu is grouped by annotation, collection, and model support so buyers can reach the right capability without decoding the full service catalogue.

PROCUREMENT READINESS

Regulated AI Needs Evidence. Not Just Vendor Promises.

YPAI builds the records regulated buyers need before model deployment: contributor consent, dataset lineage, QA evidence, risk notes, and jurisdiction-aware infrastructure decisions. EU AI Act and GDPR requirements are treated as operating constraints from the first scoping call.

Evidence package

Consent records
Dataset lineage
Annotation guidelines
QA sampling results
Risk notes
Delivery documentation

EU AI Act

Article 10 data governance support with provenance tracking, dataset documentation, and bias evidence.

GDPR

Consent records, lawful-basis documentation, minimization controls, and data-subject workflow support.

EU data residency

Norwegian company structure and EEA operating model for teams that require European jurisdiction.

Request a Procurement Readiness Brief →

We map the evidence package to your data, risk class, and deployment environment.

Enterprise intake

Scope a Data Project.

Send a brief. Most replies land within one EU business day with a feasibility read. NDA-first review on request.

  • DPA included

    GDPR Article 28 aligned. Mapped to EU AI Act Article 10 data governance.

  • EEA-only operations

    Norwegian Aksjeselskap. Self-hosted European servers. Zero US CLOUD Act exposure.

  • Reviewable records

    Consent records, lineage, QA evidence, and manifest.sha256 on every delivery.

Procurement FAQ

What procurement, legal, and security ask first.

Where is data processed and stored?

YPAI is a Norwegian Aksjeselskap with EEA-only operations. Production data lives on self-hosted European servers, not third-party US cloud platforms. Zero US CLOUD Act exposure.

What's the consent model for contributors?

Verified per-contributor consent under GDPR Article 7. Identity-verified contributors with recorded basis and signed-at timestamps in every delivery manifest. 30-day erasure SLA on request.

Do you sign a DPA?

Yes. A Data Processing Agreement is included with every engagement, not on request. The template is GDPR Article 28 aligned and maps to EU AI Act Article 10 data governance requirements.

Who are your sub-processors?

Sub-processor list is provided alongside the DPA at engagement scoping. No US-based sub-processors handle production data. EEA infrastructure across the full data pipeline.

Can you provide a sample SOW or DPA?

Yes. Send a brief above with "sample DPA" or "sample SOW" in the project description. We share the templates plus a redacted past SOW that matches your scope.

How is QA documented?

QA sampling rates, reviewer counts, and pass/fail decisions are recorded per dataset. Every delivery includes a manifest.sha256 plus a JSON-LD record of the QA chain. 100% human QA coverage on production data.