Last updated: May 2026
Private AI for businesses - your data never leaves Norwegian servers
Your company wants to use AI for customer service, document analysis, or internal productivity. But you cannot risk sensitive contracts, customer data, or trade secrets ending up as training material at OpenAI, Google, or Microsoft. Datafolka offers private AI on Norwegian servers - you use a modern language model just like ChatGPT, but nothing you write or upload is stored, shared, or used to train anyone else's models. Quote available on request.
Why Norwegian businesses need a private AI
The Norwegian Data Protection Authority (Datatilsynet) is clear: "When you paste text into ChatGPT, you are sending information to OpenAI's servers in the USA, which constitutes a transfer of personal data to a third country and requires a legal basis under the GDPR." For many Norwegian businesses handling customer data, health records, or legal documents, establishing that legal basis is far from trivial. The Court of Justice of the EU's Schrems II ruling makes US-based AI services legally unstable even when data is stored in the EU - as long as the provider is an American company, US authorities can demand access under the CLOUD Act and FISA 702.
The result: we see law firms, accounting firms, and healthcare providers that want to use AI but have said no because the compliance risk is too high. We have also encountered municipalities and public agencies with a blanket prohibition on using ChatGPT for internal documents. Private AI on Norwegian servers removes this dilemma. The model runs at a Norwegian data centre provider under Norwegian jurisdiction. Your data never leaves Norway. No training data is sent anywhere.
What you get, concretely
We set up a private AI instance dedicated to your organisation. That includes:
- Norwegian-trained language model - NorMistral, NorwAI, or Mistral Large depending on your needs. Understands Norwegian professional language better than standard GPT-4
- Hosted by a Norwegian provider - we use established Norwegian data centres with documented GDPR compliance and data sovereignty
- Web interface - your employees log in with BankID or SSO and use the AI like an ordinary chat application
- No training-data sharing - neither conversations, documents, nor prompts leave the dedicated instance
- Logs you own - we can delete or export all data on request, and you can shut down the instance permanently at any time
- Integration with internal systems - possible to connect to SharePoint, Microsoft 365, email, or case-management systems via an on-prem connector
- DPIA and data processing agreement - we deliver ready-made documentation that Datatilsynet may request
Who this is right for
Private AI is not for everyone. If you only need to generate blog posts or write Excel formulas, free ChatGPT or Microsoft Copilot offers better value for money. But if your organisation handles one or more of the following categories, it is likely no longer defensible to use standard AI services:
- Law firms and legal advisors - client confidentiality is non-negotiable. You cannot paste contract text into ChatGPT
- Accounting and auditing firms - client data, financial records, and payroll data carry specific secrecy obligations
- Healthcare, psychologists, physiotherapists - GDPR's special categories of personal data require particularly strict safeguards
- HR departments and recruitment - CV screening with ChatGPT is classified as high-risk under the EU AI Act from August 2026
- Municipalities and public agencies - central government has tightened requirements following the Riksrevisjonen's document 3:18
- Companies with IP-sensitive documents - patent drafts, source code, business plans, and contracts that must not leak
How the technology works
Private AI is not magic. It is open-source language models running on a GPU server that you pay for. We use Mistral, Llama, and Norwegian NorMistral models - weights that are open and that we can run with any provider without asking OpenAI for permission. That means there is never a legal grey area about where your data goes. You have a server, we have placed a modern language model on it, and you run it yourselves.
The inference layer runs vLLM or Ollama depending on the use case. For a company with ten to fifty concurrent users, an NVIDIA H100 instance is sufficient. For dedicated enterprise deployments we set up redundancy and automatic scaling. We typically place the hosting with a Norwegian provider with documented GDPR compliance and Norwegian ownership - Terakraft, Bulk Infrastructure, or Green Mountain.
We also establish a logging policy from day one: what is logged, for how long, and who has access. You own the logs, not us. We cannot read them without your explicit instruction - that is built into the contract.
Comparison: private AI vs public ChatGPT vs Microsoft Copilot
We are often asked what the difference actually is. Here is a rough comparison:
- Public ChatGPT/Claude/Gemini (free or Plus) - your prompts may be used for training. Data is stored in the USA. Schrems II issues. Minimum age 18. Illegal to use with personal data without an extensive risk assessment
- ChatGPT Enterprise / Claude for Work - business version with a data processing agreement. Data is not used for training. However, servers are still in the USA and OpenAI is subject to US law
- Microsoft 365 Copilot - data is processed in Microsoft's EU cloud and kept within the M365 boundary. Behind the facade it is still Azure OpenAI with an American owner. The CLOUD Act applies
- Private AI (what we deliver) - open models, Norwegian servers, Norwegian ownership, no American vendor in the chain. Datatilsynet-safe without additional DPIA questions about Schrems II
The legal difference is small on paper. The practical difference is significant: with private AI you do not have to convince your compliance officer, board, or Datatilsynet that the risk is acceptable. You have documentation proving the risk is not there.
What it costs
Pricing depends on the number of users, how heavily the AI will be used, and whether you need dedicated or shared infrastructure. We do not offer an off-the-shelf product - each installation is configured to your needs. Get in touch for a no-obligation conversation, and we will put together a concrete quote based on your situation.
As a guide, a private AI for ten to fifty users typically falls in the same price range as ChatGPT Enterprise licences - but you get documented data sovereignty on top. For larger deployments or integration with internal systems, there is an initial implementation cost.
What about private individuals?
We regularly receive enquiries from private individuals who want the same solution - a chat AI for personal questions about health, law, or finance where they do not want the conversation to end up in OpenAI's training data. We have a separate offering for this: a local installation on your own PC with an open language model, set up by us in an hour. No cloud involved at all. Send us an email if this is relevant for you.
We handle the rest too
Private AI is rarely the only IT challenge a business faces. We offer a complete range of IT services for businesses in Stavanger - read more about IT security, strategic IT consulting, and bespoke software development. If you are already using AI without being entirely sure of your compliance status, we can conduct a risk assessment as a first step.
Ready to talk about private AI?
We will have an informal conversation about what your organisation needs, what is realistic, and what it will cost. No prior AI experience required - we meet you where you are. Call 958 68 662 or send a message.
Book a conversation about private AI