The precise version, not the reassuring one.
This is the first question every operator asks us, and most vendors answer it with a sentence designed to end the conversation. Below is the whole data path instead — what stays with you, what leaves, what is removed before it does, and how you verify any of it. Written to be forwarded to your DPO.
The rest of this page is each of those four in detail, including the parts that are uncomfortable.
PlayerDesk runs in your environment — your cloud account, your VPC, or your own hardware. It is not a multi-tenant SaaS with your players in someone else's database.
Player database. Event stream from your PAM. Conversation history. The token–identity mapping. Audit and reasoning logs. Your knowledge base. All of it, permanently.
One thing: the redacted text of the conversation currently being answered, plus the retrieved policy snippets needed to answer it — sent to a language model endpoint and discarded after the response.
An Arctura-side copy of your players, your chats or your outcomes. There is no central database of operator data on our side to be breached, subpoenaed or sold.
Arctura engineers do not have standing access to your environment. Access for support or incident work is granted by you, limited to named individuals, time-boxed and logged — on your side, where you can revoke it without asking us.
Before any request leaves your environment, it goes through a redaction stage that runs inside your perimeter. It works in layers, because no single technique is sufficient:
<PLAYER_7f3a> rather than a name — so the model can still reason about "the same player" without knowing who that is.We will not tell you that redaction is airtight, because it is not, for us or for anyone else. A player can phrase something in a way that no pattern and no model catches. Free text is adversarial by nature.
So redaction is the first layer, not the only one. Underneath it sit three more: zero retention at the model provider, so anything that slips through is not stored; EU-only processing, so it never leaves the jurisdiction; and a contractual no-training guarantee, so it cannot end up in a model's weights. Any vendor who tells you their redaction alone makes the question moot is either not thinking about it or hoping you aren't.
If your regulator or your own risk appetite requires that nothing whatsoever leaves the perimeter, PlayerDesk runs on a self-hosted open-weights model inside your environment. It costs more in infrastructure and gives up some quality; we will tell you honestly which of your topics that trade-off affects.
We do not hide behind "industry-leading AI providers". The language model behind your deployment is one of Anthropic, OpenAI or Azure OpenAI. Which one is fixed when your deployment is configured, written into your contract, and not changed without notifying you in advance.
Requests are served from EU-region endpoints. No transfer of conversation data outside the EU/EEA.
Endpoints are configured so that requests are not persisted after the response is returned.
Enterprise terms prohibit the use of your requests for model training or improvement. This is contractual, not a setting.
Every sub-processor is listed with its role and region, and any change is notified before it takes effect.
Supporting infrastructure that Arctura operates on its own side — nothing containing player data — is EU-hosted (Hetzner, Frankfurt). The contracting entity is Gazolin Production SRL, Baia Mare, Romania, trading as Arctura.
Every request PlayerDesk makes is recorded in your environment with a full trace: the original message, the redacted version that was actually transmitted, which fields were tokenised, which endpoint answered, the response, and the reasoning that led to the action taken. Your DPO reads the same log we do, in the same place, without asking us for an export.
That trace serves three audiences at once: your compliance team reviewing a specific player's case, your DPO answering a subject access request, and your regulator asking why an automated system said what it said. It is also what makes the quality-control layer possible — you cannot grade a decision you cannot reconstruct.
Deletion follows your retention policy, not ours. The logs live in your storage under your rules. There is nothing on our side to delete, which is a simpler answer than a deletion certificate.
These are the questions that separate a real answer from a comfortable one. We publish them because we would rather be measured against them than against a brochure.
The full buyer's guide — 12 questions vendors hope you won't ask →
If something here does not satisfy your data protection officer, we would rather find that out in a 30-minute call than in month four of a deployment. Bring the objections.
Or write: hello@arctura.eu