A Belgian company under GDPR: what REMI collects, what it will never do with it, and what has honestly not been decided yet.
REMI is built by a Belgian company, so GDPR is the floor here rather than the ambition. The decisions below were taken before the first record exists — protection built in while the schema is still being designed is a different product from protection retrofitted after launch.
The intent is that personal data stays in the EU, with a Belgian or other EU region as the default for the pilot. No storage vendor has been committed yet — deliberately, because that is what keeps residency a criterion for choosing rather than a migration project afterwards. Any processing that would leave the EU gets named, documented and justified before it happens.
This is written intent, and worth what a written intent is worth. REMI holds no certification and claims none, and no client data is being processed today. When a vendor is chosen, the public site's trust page gets a name, a region and a date — and if the answer turns out differently, that page changes rather than quietly staying the same.
It is the question worth asking, and it does not have a finished answer yet: which provider, what exactly is sent, and what is deliberately kept out of it. No AI vendor is committed either. What is already decided is the boundary — personal data is not used to train models that serve anyone but the person it belongs to.
The public site's trust page carries the long version, including the questions we would rather be asked early than late.
Read trust and dataThese two buttons record nothing — there is no feedback pipeline behind them yet, and a control that quietly discards an answer is worse than none. Until there is one, tell us in a sentence and it reaches a person.
Tell us insteadRead next