AI Cube Pro processes models and knowledge in your controlled environment. Data paths, permissions and operations are documented; in managed operations, the people involved accept a written secrecy obligation.
External AI services process client, patient or other confidential data through additional involved parties.
A DPA addresses the GDPR layer but does not alone settle necessity, secrecy obligations and the access chain under §203.
Models, knowledge sources, logs, backups and remote maintenance together form the actual data path.
In a managed service, contributing persons and any further participants must also be effectively bound to secrecy.
We configure and operate AI Cube Pro for GDPR- and §203-compliant use when required. This includes controlled data paths, limited permissions, documented maintenance, the appropriate DPA and written secrecy obligations for the people involved.
§203 StGB protects confidential information entrusted by clients, patients and other parties. The necessary involvement of contributing persons is permitted. What matters is that access is limited to what is necessary, the people involved are bound to secrecy and the complete data and maintenance path is controlled.
With public AI services, inputs and documents leave your own infrastructure. Whether a service is suitable in a specific case therefore depends not only on a DPA, but also on data flows, subprocessors, access permissions and the actual use.
On-premises inference, local vector search and internally operated interfaces keep technical processing in your controlled environment. This reduces external data paths and subprocessors and allows access to be limited precisely.
When we provide setup or operations as a contributing person, the people involved accept a written secrecy obligation and are instructed about the criminal consequences. Where personal data is involved, this is combined with a DPA, limited administrative rights and documented maintenance paths.
These technical and contractual building blocks form part of the agreed §203 scope:
Data-protection layer
Secrecy and instruction on criminal consequences
necessary rights, logging and controlled paths
This content is general information and not legal or tax advice. The specific implementation under §203 must be reviewed professionally on a case-by-case basis.
The local AI platform brings AI chat, knowledge spaces and local models into your network. It is configured for the agreed GDPR and §203 framework; professional-software integrations remain a clearly scoped integration service.

Ready for use in under two weeks after configuration approval
EUR 5,999 excl. VAT
RAG, data sources, integrations, secure connectivity and custom workflows are scoped separately.
Optional managed operations from EUR 149.90 excl. VAT per AI Cube and month; §203 scopes include a DPA, limited administrative rights, written secrecy obligations for the people involved and instruction on the criminal consequences
Confidentiality norm, use cases and professional-software integration - profession-specific.
§203 · Case data · RAG
Case-law research, draft pleadings and case knowledge with locally deployed AI configured for §203-compliant use.
Learn more§203 · DATEV · Client data
Process documents, correspondence and firm knowledge with locally deployed AI configured for §203-compliant use.
Learn more§203 · Patient data · PMS
Practice knowledge, drafts and documentation with local models in the practice network.
Learn more§203 · HIS · air-gapped
Doctor's letters, tumour board, coding at volume - air-gapped in your own data centre.
Learn more§203 · Therapy data · local
Drafts, professional research and internal knowledge with local models in the practice.
Learn more§203 · Deeds · RAG
Deed drafts and register-law research - party data stays in the office.
Learn more§203 · Working papers · RAG
Working papers, IDW PS research, report drafts - client figures stay in-house.
Learn moreSovereign AI is a lifecycle, not a device purchase - and everything stays on your infrastructure.
Workshop, sizing, data classification and §203 contract framework. We understand your stack, professional software and compliance requirements before we recommend.
On-premise build on your hardware, RAG on your documents with access control, integration into your professional software, secrecy obligation + DPA.
Updates, monitoring, model upgrades and RAG maintenance as a service contract - or you operate fully yourself. Handover and knowledge transfer included.
From hardware and inference through RAG and integration to operations and security - no interface ping-pong between advice, build and operations.
On-premise deployment at your site; external integrations, updates and remote access are configured deliberately and documented.
Ollama, vLLM, Open WebUI, Qdrant - operable internally, no vendor lock-in.
DPA, written secrecy obligation and instruction of contributing persons about the criminal consequences.
Describe the workflow and data that should be processed locally or in a controlled environment.
Answers to the most important questions
Yes. Section 203(3) StGB permits the necessary involvement of other contributing persons. The specific use needs controlled data paths, an effective secrecy obligation and the other data-protection and profession-specific requirements.
A DPA is an important part of the GDPR layer. For secrets under §203, necessity, involved persons, secrecy obligations, access rights and further providers must also be assessed.
The organisation must define which data may be processed, who receives access and how service providers are involved within the §203 framework.
Server location is only one criterion. Provider identity, subprocessors, access rights, third-country transfers, contracts and the actual processing also matter.
AI Cube Pro costs EUR 5,999 excluding VAT including hardware, base setup, hardening, an agreed local model and five hours of initial setup and support. Larger deployments are quoted per project.
A fully local or isolated deployment can be configured. Updates, external models, web search and remote maintenance are then unavailable or require controlled transfer procedures.
Common open-source LLMs (Llama, Qwen, Mistral, Gemma) on NVIDIA hardware - from the AI Cube as a GB10 appliance for a single practice to an RTX GPU server for larger institutions. No vendor lock-in.
We document data paths, roles, technical safeguards and operating responsibility. For a §203 scope, the people involved accept a written secrecy obligation and are instructed about the criminal consequences; an appropriate DPA is added where personal data is processed.
From local AI integration to architecture, data sovereignty and ongoing operations.
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.