All payments made in the preview are in test mode.

Bringing light to a new era of AI.

Answer a few questions. Get a sourced GDPR and AI Act assessment your lawyer can review.

For startups and larger teams without in-house legal.

Sourced to GDPR, the EU AI Act and EDPB guidance.

NyTid · AssessmentExample · fictional company
Built on

GDPR · EU AI Act · EDPB guidelines · ICO guidance · IMY · CJEU case law

One conversation. A sourced assessment.

Data map

  • ✓ Product database
  • ✓ Customer support tools
  • ✓ Cloud storage and file exports
  • ○ Bought or scraped lists

See what you get.

How to read this

Example · fictional company · not legal advice

Legal position as of today · Draft for legal review

MEDIUM RISK — You can probably do this, but not yet. Three things need fixing first.

GDPR: Proceed with safeguardsAI Act: Limited risk · ProviderAutomated decisions: Not applicable

Using support tickets to train your own AI assistant

In short

You can probably use past support tickets to train your assistant. First, tell your customers and give them an easy way to say no. Right now you do neither.

What we relied on

You told us: the tickets come straight from your customers; you first collected them to give support; your privacy notice does not mention AI training; people cannot ; you remove names and email addresses before training; you tried synthetic examples and they were too thin; the helpdesk tool stores the data in the EU.

Assumed: the tickets rarely contain sensitive details, because you answered "Not sure" (see gap 1 below).

Still unknown: whether removing names also catches personal details written in free text.

The question

Can you use support tickets, collected to give support, to train your own assistant, and on what basis?

The rules

  • 1 Law · GDPR Art. 5(1)(b): data collected for one purpose can be used for another only if the new purpose is with the first.
  • 2 Law · GDPR Art. 6(4): five things decide whether a new purpose is compatible: the link between the purposes, the context and what people would expect, the kind of data, the possible consequences, and the safeguards.
    What does this rule say?

    If you want to use data for something new, ask five questions. How close is the new use to the old one? Would people expect it, given how they gave you the data? How sensitive is the data? What could go wrong for the people involved? What protections do you have? If the answers mostly point the same way, that tells you whether the new use fits.

  • 3 Law · GDPR Art. 6(1)(f): you can rely on if you have a real reason, you need the data for it, and it does not outweigh people's rights.
  • 4 Law · GDPR Art. 13(3): tell people before you use their data for a new purpose.
  • 5 Law · GDPR Art. 21(1): when you rely on legitimate interests, people can object, and you must stop unless you can show compelling grounds.
    What does this rule say?

    If you rely on legitimate interests, people can object to your use of their data. Once they do, you must stop, unless you can show a very strong reason that outweighs their interests.

  • 6 Official guidance · ICO on legitimate interests: guidance suggests working through three questions, purpose, necessity and balancing.

Applying the rules

Does the new use fit the old one (Art. 6(4))? 2

  • Link between the purposes: training a support assistant is close to giving support. Points toward compatible.
  • What people expect: customers wrote tickets to get help, and many would not expect their messages to train a model. Points against.
  • Kind of data: mostly free text, which can hold personal details. Mixed.
  • Consequences: low for individuals if personal details are removed, higher if the model repeats them. Mixed.
  • Safeguards: you remove names and email addresses. Points toward, but untested on free text.

Do work as the basis (Art. 6(1)(f))? 3 6

  • Purpose: improving your support is a real business interest.
  • Necessity: you tried synthetic examples and they were too thin, so real tickets are needed.
  • Balancing: this holds only if people are told and can opt out.

Strongest argument against

"Customers wrote for help, not for training, and free text may hold private details your filter misses."

Why it does not change the result: it lowers our confidence, and it is exactly why the notice, the opt-out and a test of the filter are conditions.

Conclusion

Proceed with safeguards.

Confidence: Medium

Because we cannot see how well your filter catches personal details in free text.

This would change if: the tickets hold health or other at scale (then Art. 9 applies and legitimate interests cannot carry it alone 7), or customers were promised their tickets would only ever be used for support.

What to do

  1. 1.Tell current and new customers about the AI training before it starts. You can fix this yourself
  2. 2.Add an easy opt-out and honour it. You can fix this yourself
  3. 3.Test that your filter catches personal details in free text. You can fix this yourself
  4. Gap 1 (from the data map): find out whether the tickets contain sensitive details.
  • Where the data is stored: no problem, it stays in the EU.
  • Automated decisions about people: not relevant, the assistant does not decide anything about a person.
  • AI Act: limited risk, so people must be told they are talking to an AI 8. You are the .

Sources

  1. [1] GDPR Art. 5(1)(b) · Law
  2. [2] GDPR Art. 6(4) · Law
  3. [3] GDPR Art. 6(1)(f) · Law
  4. [4] GDPR Art. 13(3) · Law
  5. [5] GDPR Art. 21(1) · Law
  6. [6] ICO — legitimate interests in practice · Official guidance
  7. [7] GDPR Art. 9 · Law
  8. [8] EU AI Act Art. 50 · Law

NyTid doesn't hand you a stamp and ask you to trust it. Every conclusion is structured, sourced, and ready for your lawyer to challenge. You stay responsible.

Made for teams without a lawyer on staff.

Startups

Shipping your first AI features on your first real data, and need the paperwork right from day one.

Larger companies

Many systems, unclear data flows, and no privacy lawyer sitting on the product team.

Legal and compliance teams

A structured, cited first draft you can review and challenge instead of writing from scratch.

The NyTid Mark

A transparency marker, not a certification. It shows a team documented its reasoning with NyTid — anyone can check the code below.

Verify a NyTid mark

If a company shows you a NyTid mark, you can confirm it's real here.

€97

per assessment · delivered within 48 hours

  • Guided data map
  • Combined GDPR and AI Act risk rating
  • Sourced assessment document (PDF)
  • “What needs to change” list
Start assessmentOr try the free demo

Questions

No. NyTid is a drafting aid. It structures and sources your reasoning, and qualified counsel should review it before you rely on it.

See where your data stands.