> ## Documentation Index
> Fetch the complete documentation index at: https://docs.realtimelca.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Transparency & privacy

> How Real-Time LCA's AI features use third-party models and handle your data.

We use third-party AI to run certain features, which means some information is sent to a third-party service, processed, and returned. This page explains what that involves and how your data is handled. Whenever a feature uses generative AI, you are informed about that. Today that applies to:

* [AI Classification](/user-guide/integrations/ai-tools/ai-classification)
* [AI Assistant](/user-guide/integrations/ai-tools/ai-assistant)
* [MCP connections](/user-guide/integrations/ai-tools/mcp-server)

## In short

<Info>
  * None of your data is used by Real-Time LCA or any third-party provider to train AI models.
  * The third-party providers process the input and provide output but do not store any data (Zero Data Retention).
  * AI processing runs on servers in the EU.
  * All features are built to meet the EU AI Act's transparency obligations and to handle data in line with GDPR.
</Info>

## The models we use and how they treat data

If not highlighted otherwise, Real-Time LCA AI features use **Mistral** models through the Mistral API. A few things follow from this:

* **No training on your data.** Mistral does not use the information you send to train its models.
* **Nothing stored by Mistral.** We use Mistral's Zero Data-Retention option, so neither the inputs we send nor the outputs Mistral returns are stored on Mistral's side.
* **EU processing.** Mistral processes the data on its own servers in the European Union. Because Mistral is EU-owned and EU-hosted, your data is less exposed to US data-access requests than it would be with a US-based provider — which, depending on your sector and region, may be relevant for sensitive or regulated work.
* **Redaction of personal information.** Information about individual users stored in Real-Time LCA, including names and e-mail addresses, is removed before being sent to AI providers. This does not apply to information within BIM models or your prompt inputs.
* **Prompt storage.** Real-Time LCA stores prompts for up to **90 days** to log usage and improve the product through anonymised evaluation.

Our calls to the AI provider are stateless: everything the model needs to respond — including any conversation history — is sent with each request, so there is nothing for the provider to keep between calls.

## Where this sits under the EU AI Act

Real-Time LCA makes building LCAs and operates no high-risk AI systems. These features fall under the AI Act's lower-risk categories, where the main obligation is transparency:

* The frontend always informs you when you are interacting with AI.
* AI-generated outputs are labelled so you can review them before acting.

## Details about the individual AI features

### AI Classification

* Sends the **semantic properties** of the elements you select — **no geometry or BIM model**. This may include all parameters in your BIM models.
* Uses no information about users, tenants, or projects beyond the materials and type parameters in Real-Time LCA.

### AI Assistant

* Sends your input to the AI model and may query additional project context.
* The assistant can look across your whole project and decides when to query information. What it queries is also sent to the third-party AI provider.

<Warning>
  Never put personal information into a prompt — your prompts are sent to the AI provider. Although the AI provider guarantees that no data is stored and we use strong encryption, there is always a residual risk that data sent over a network could be intercepted.
</Warning>

### MCP connections

* If you connect through the [MCP server](/user-guide/integrations/ai-tools/mcp-server), your client (for example Claude, Mistral, or ChatGPT) controls how your data is handled. That's outside Real-Time LCA, so check your client's terms.
* The MCP server enables access to all project-related information. The only exception is user-specific personal data (name, e-mail).
* The MCP server itself keeps anonymised activity logs on Azure servers in the EU for up to 90 days.

## Roles, oversight, and your rights

**Roles.** You decide what data goes into Real-Time LCA, so you act as the data controller and we process it on your behalf to provide the features you use — the legal basis is performance of our contract with your organisation. The services that process AI data are:

| Sub-processor   | Role                               | Location |
| --------------- | ---------------------------------- | -------- |
| Mistral AI      | Runs the AI models                 | EU       |
| Microsoft Azure | Hosts anonymised MCP activity logs | EU       |

**Security.** Data is encrypted in transit, and AI features can only reach data within your own organisation — never another organisation's projects or materials.

**Human oversight.** AI output is a suggestion, not a decision. You review and accept or reject AI Classification results, and you decide whether to act on the Assistant's answers, so there is no solely-automated decision-making.

**Your rights.** You can ask to access, correct, or delete personal data we hold, and you can raise a concern with your local data-protection authority. For any privacy question or request, contact [support@realtimelca.com](mailto:support@realtimelca.com).

*Last updated: 26 June 2026.*
