Governance
Operating an agent platform from Barcelona means the data protection questions are not an export concern, they are the default condition. Here is how we have built around them and where the genuine difficulties remain.
Yaju Team · 9 July 2026
Plenty of vendors treat European data protection as a compliance appendix. We operate from Barcelona, so it is simply the environment, and the design follows from it rather than being retrofitted.
That does not make it straightforward. It makes it familiar, which is different.
Data protection law separates a controller, who decides why and how personal data is processed, from a processor, who acts on a controller's instructions.
For data about our own customers, we are the controller. For the content our customers send through the platform, they are the controller and we are the processor. Those are different obligations, and conflating them produces both over-promising and under-delivering.
Practically: if an individual asks us to delete data that a customer put into the platform, the request belongs with that customer, and we tell them so rather than acting unilaterally.
The usual approach is to process wherever is convenient and cover the transfer with contractual clauses. That is lawful and it is not our default.
Our default is processing inside the European Union, with Barcelona as the primary region, which removes the question for most customers rather than answering it. Where a contract requires a specific location, processing can be pinned to it. Where a transfer outside the EEA is genuinely unavoidable, it is covered by the Standard Contractual Clauses together with encryption at rest and in transit and role-based access control.
A traditional system stores what you put in it. An agent system also stores what it did: the plan, the intermediate steps, the tool calls, the audit trail.
That record is genuinely necessary. It is what makes governance possible and what answers a regulator eleven months later. It is also personal data when it concerns identifiable people, and it accumulates faster than anyone expects.
Our position is that audit data is retained for the period needed to meet legal and contractual obligations and then deleted or irreversibly anonymised, and that customers can see what is held rather than having to ask.
This is short because it should be. Content that passes through the platform is not used to train models. It is not a setting you have to find and disable.
Two places, honestly.
The first is data minimisation in a retrieval system. An agent works better with access to more context, and data protection asks you to process the minimum necessary. Those pull in opposite directions and the resolution is a judgement about scope rather than a technical control. We help by making access boundaries enforceable, but the decision about what an agent should reach is the customer's.
The second is explaining an outcome. The right to understand a decision is easier to satisfy for a rules engine than for an agent that assembled a plan across several steps. A complete audit trail is the best available answer and it is a record of what happened rather than a simple explanation of why.
Saying otherwise would be tidier and less true.
The Privacy Notice covers our own processing, and the Trust Center covers subprocessors, transfers and security reporting. Data processing agreements and questionnaires can be requested at contact@capconsultor.eu.