AR3S as an AI system
AR3S uses language models to analyse content, so the system is designed to reflect AI Act requirements concerning, among other things, documentation, transparency and human oversight.
Compliance
Materials analysed by the system may contain health data, information protected by professional secrecy and other confidential information. GDPR, AI Act and data-protection requirements are incorporated from the system-design and infrastructure-selection stages.
Under its current intended use, AR3S supports law firms and professional representatives in analysing case materials. System outputs are intended for further professional review and use by the user.
AR3S uses language models to analyse content, so the system is designed to reflect AI Act requirements concerning, among other things, documentation, transparency and human oversight.
Under its current intended use — as a tool supporting law firms and professional representatives — AR3S should not be classified as a high-risk AI system within the meaning of Article 6 of the AI Act.
AR3S provides analytical output for professional review. The final assessment of the material, procedural decisions and the way the output is used remain with the lawyer.
AR3S analyses the content of expert opinions and the underlying source material. The system does not create profiles of experts, doctors, patients, witnesses or other individuals appearing in case files.
The client remains the controller of case materials, while AR3S processes data only to the extent necessary to perform the requested analysis. The data-protection model also covers materials subject to professional secrecy and other confidentiality obligations.
Materials submitted to AR3S are not used to train models, improve the system or for purposes unrelated to performing the requested analysis.
The client remains the data controller, while AR3S and its technology providers process data within an appropriately governed chain of processors and sub-processors.
We select AI models, OCR, hosting and other technical services with regard to data retention, processing location, access rules and the possibility of secondary use.
Fully anonymising case documentation at the analysis stage is not practically possible without removing information relevant to assessing the expert opinion. AR3S therefore relies on pseudonymisation — removing direct identifiers while preserving the content needed for a reliable analysis.
Pseudonymisation as the standard
Working with pseudonymised data is legally permissible, including for documentation containing special-category personal data such as health data. Full anonymisation is not required, provided that the processing complies with applicable GDPR safeguards and requirements.
Additional safeguards
Pseudonymisation is complemented by technical and organisational measures appropriate to the nature of the data being processed.
For pilots, AR3S will use infrastructure located in the EU/EEA so that client data is not transferred outside this area. Processing location is one of the core criteria for selecting AI model providers and other infrastructure services.
External legal review
In July 2026, an external legal review covered, among other matters, the AI Act, GDPR, the processing of health data, professional secrecy, liability and the Data Act.
The findings are being incorporated into product development and pilot preparation.
The compliance scope is updated as the product and deployment model evolve.
Compliance · Pilots
Before a pilot begins, the scope of processing, deployment model and responsibilities of the parties should be reflected in documentation appropriate to the client and the intended use.
contact@ar3s.tech