Skip to main content
All CollectionsData Protection, Security & Law
FAQ: Google Vertex (LLM & AI Model)
FAQ: Google Vertex (LLM & AI Model)
Marius Roth avatar
Written by Marius Roth
Updated over a week ago

What exactly is Google Vertex?

Vertex AI is a machine learning (ML) platform that can be used to train and deploy ML models and AI applications and customise large language models (LLMs) for AI-powered applications.

We use this platform to differentiate between document types.

What is a Large Learning Model (LLM)?

LLMs are powerful models designed to understand and generate human language. In our case, automated decision making is generated based on data that recognises whether an uploaded document is a contract, invoice or other type of document.

Where is the data processed?

Data processing takes place exclusively in the European Economic Area, in our case: Frankfurt am Main. Through the Google Vertex service from Google Cloud.

What is the address of Google Cloud?

Google Cloud EMEA
70 Sir John Rogerson's Quay
Dublin 2
Ireland

When will processing begin?

From 26 September 2024 at the earliest, by which time there will be more information on the implementation of the new feature.

Is personal data processed?

Yes, but this is not the primary purpose of the processing operation. It is possible that the documents sent in may contain personal data. For example, the name of the contact person or an e-mail address of the company that contains a name and the full name of a signatory. The documents submitted are the types of documents processed by Candis, i.e. invoice documents, contracts for contract management and other documents that are uploaded for filing. By their nature, these documents contain direct personal data.

Is the data used for general training of a Google AI?

No. As part of its AI offerings for customers, Google has expressly ensured that this data is used exclusively for the purpose intended by the customer and only in the language model used by the customer.

Does AI create a profile in accordance with Art. 22 GDPR?

According to Art. 22 GDPR, profiling refers to a profile about a natural person. The AI integration merely categorises what type of document it is; this could include personal data such as the name of a contact person or the name in the email address. This does not create a profile about the natural person.

What security measures have we taken?

We have concluded an order processing contract with Google Cloud and checked the technical and organisational measures. We have also carried out a data protection impact assessment and a transfer impact assessment (these are available on request).

The data is encrypted at rest and during transmission using AES-256 encryption. The data systems are divided according to the following diagram and encrypted with different keys:

Google Vertex AI also has the following certifications: ISO 27001, 27017, 27018, 27701; SOC 1, 2, 3.

detailed reports:

Why Google Vertex?

After examining the various providers of LLMs, we decided in favour of Google, as only here is the contractual basis (AVV, as well as assurance of a closed learning model, documentation and security information) and infrastructure tools for the processing we are aiming for possible.

Did this answer your question?