How We Handle Data – AI Act, DSA & EU Data Act

Last Updated —  27.07.2026

How We Handle Data

Ximilar builds narrow, task-specific computer vision and vision-language models — image classification, object detection, segmentation and visual search. This page explains, in plain terms, how that work fits three EU frameworks that govern data and AI: the AI Act, the Digital Services Act and the Data Act. It summarises our Terms of Use & Privacy, which remain the governing document. Where the two differ, the Terms of Use control.

AI Act

Ximilar builds narrow, task-specific computer vision and vision-language models — image classification, object detection, segmentation and visual search. This section explains where that work sits under Regulation (EU) 2024/1689 (“EU AI Act”).

What we build

– Ximilar’s models are narrow AI: each is trained for one task — classification, detection, segmentation, recognition or search. We do not build or offer general-purpose AI models under the AI Act’s definition (a model with broad, cross-task capability, such as a foundation model or general chatbot).
– Our vision-language model (VLM) offering fine-tunes and deploys existing models for narrow recognition tasks. It is not a general-purpose model, and we do not expose it as one.

What we don’t do

– We do not build or offer facial recognition, biometric identification, biometric categorisation, emotion inference or social scoring — the practices the AI Act prohibits outright under Article 5. This is a product boundary, not just a policy statement: our Services are not designed for these use cases.
– We do not provide the high-risk AI systems listed in Annex III of the AI Act (for example, systems used in recruitment, credit scoring, law enforcement, or access to essential services).

Where our services sit

Under the AI Act’s risk-based framework, Ximilar’s services fall into the minimal-risk category: they are not prohibited, not high-risk, and not general-purpose AI models.

Your responsibility as a customer

If you deploy Ximilar’s models inside a use case the AI Act treats as high-risk — for example, a medical diagnostic tool, a hiring system, or critical-infrastructure monitoring — you become the Provider or Deployer of that system under Article 25, and the corresponding obligations (risk management, technical documentation, human oversight, registration) sit with you, not with Ximilar. Full detail is in the Acceptable Use and EU AI Act Compliance section of our Terms of Use.

Digital Services Act (DSA)

Under the DSA, Ximilar operates as a hosting service: we store data — training datasets — at your request, through your account. We do not publish or distribute that data to the public or share it with other customers, which is what would make us an online platform under the DSA; we are not one.

What this means in practice

– We do not monitor stored content proactively — the DSA does not require this, and we don’t do it (Article 8).
– We maintain a single point of contact for EU authorities and for recipients of our Services, and a notice-and-action mechanism so anyone can report content they consider illegal. Details and the reporting address are in the Single Points of Contact and Reporting Illegal Content sections of our Terms of Use.
– We review notices in line with Article 16 of the DSA and act on well-founded reports.

EU Data Act

You can export everything you put into Ximilar, and everything we generate from it, through our public API at any time, at no extra cost:

– Your original content, labels and annotations
– Metadata and training datasets with multimedia
– Prediction results
– Your VLM models

The underlying model weights, architecture and runtime for our Image Recognition and Object Detection services stay on Ximilar’s infrastructure and are not exportable — you access them through the API rather than downloading them. Everything else you produce on the platform is yours to take with you, as set out in the Visual Content section of our Terms of Use. Our API documentation is publicly available via docs.ximilar.com.

Deletion

You can request deletion of your account at any time through in-app chat, our website or our contact form. Training data, models and personal information are deleted within 48 hours; encrypted backups are purged within 30 days. On termination, we provide reasonable transition assistance for 30 days.

Full data-processing terms, including our role as processor under Article 28 GDPR, are in the Terms of Use & Privacy.