How we build AI into Ninox, what happens to your data, and what stays under your control.
Last updated: September 2026 Version 1.0
Our approach
AI features in Ninox are optional. They are controlled by your own administrators, not by us. You decide whether you want to use AI at all and if you want to give it access to your data. If you decide against it, Ninox works exactly as it did before.
Which features this page covers
- Ninox AI Assistant – a context-aware copilot that helps users build, modify, and understand their Ninox application through natural language.
- Ninox AI Agents – a goal-oriented AI worker that can execute multi-step business tasks inside Ninox on the user's behalf
- AI assisted app creation from excel and CSV – is included as a sub-feature in AI assistant
Roles and responsibilities
Under the GDPR, you are the controller for the personal data in your Ninox databases. Ninox acts as processor and only on your documented instructions. The AI model providers we use act as sub-processors and are named in our data processing agreement.
Under the EU AI Act (Regulation (EU) 2024/1689), Ninox is the provider of the AI systems described here and your organisation is the deployer. If you use Ninox AI to build an application of your own that falls into a regulated category, additional obligations may apply to you directly. See "Permitted use" below.
You stay in control
Ninox AI respects your existing permission model. A user cannot retrieve or generate content from data they could not open in Ninox without AI..
Which models we use and where your data is processed
Our current model provider is Anthropic, whose models we access through its commercial API. Prompts and outputs are processed on Anthropic infrastructure in the United States. This transfer is safeguarded by the EU Standard Contractual Clauses (Art. 46 GDPR) under our data processing agreement with Anthropic. Your Ninox databases themselves remain hosted where they are todayCurrent model provider is Anthropic with its different models.
Our current sub-processor list is available in our Privacy Policy. We have entered into the necessary data protection agreements with the service providers.
Further information on Anthropic’s security can be found here.
What we do not do with your data
- Neither we nor our model providersWe do not use your content to train AI models.
- Prompts and outputs are deleted by the model provider within 30 days and are not reviewed by its staff, except where required by law or to investigate suspected abuse ofpeople at the servicemodel providers.
- We do not use data from one customer environment to produce outputs in another.
- Chat histories and prompts can be deleted by the user themselves.
Transparency
Wherever you or your users interact with a Ninox AI feature, the interface makes clear that an AI system is involved. Content generated by Ninox AI is not published by Ninox; it stays inside your application. If you publish AI-generated text to inform the public, you are responsible for disclosing this under Art. 50(4) of the AI Act.
Accuracy and human oversight
AI outputs can be incomplete or incorrect and must be checked before they are relied upon. Agent actions with external effect are presented for approval rather than executed automatically.
Ninox AI is not designed to make automated decisions about individuals within the meaning of Art. 22 GDPR. If you configure a process in which an AI output determines such a decision, you remain responsible for ensuring that a person with the authority and competence to change the outcome reviews it.
Permitted use
Ninox AI must not be used for practices prohibited under Art. 5 of the AI Act. This includes emotion recognition in the workplace or in education institutions, social scoring, biometric categorisation to infer sensitive attributes, and predicting criminal offences on the basis of profiling alone.
Ninox AI is also not provided for use as, or as part of, a high-risk AI system within the meaning of Annex III to the AI Act — for example recruitment and candidate selection, evaluation of employees, creditworthiness assessment, or decisions on access to education or essential services. If you are considering such a use, please contact us before going live so that the necessary arrangements can be made.
Security
The security of our platform is our top priority. All your business data is encrypted at all times, and we are ISO 27001-certified. Further information can be found on our website.
Contact
If you have any questions about our AI features or would like to get in touch with us: support@ninox.com