//FAQ
// FAQ & Comparison

Everything asesorías and
gestorías ask.

Fifteen answers, a benchmark against Aranzadi, and the primary sources behind them. For the full February 2026 regulatory framework, see .

// Frequently Asked — After Feb 2026
Q1

But ChatGPT Enterprise / Claude Enterprise has EU data residency. Isn't that enough?

No. The February 2026 AEPD doctrine specifically addresses this defence. Data residency answers where the bytes sit at rest. Operational sovereignty asks a different question: who can technically and legally cause the processing to stop, be inspected, be modified, or be subpoenaed? For OpenAI, Anthropic, Microsoft and Google, the answer is the same: a US-headquartered company subject to US extraterritorial law (CLOUD Act, FISA 702, EO 14117). EU residency does not change that. The AEPD has now formalised that this is an Article 32 problem in its own right. See source 2.

Q2

We signed a DPA (Data Processing Agreement) with OpenAI / Microsoft. We're covered, right?

A valid Article 28 DPA is a necessary condition, not a sufficient one. The February 2026 guidance is explicit that Article 28 (the processor relationship) and Article 32 (security of processing) are independent obligations. A perfect DPA does not cure an operational-sovereignty defect. You also still need to defend the processor relationship itself — and for asesorías as sujetos obligados under Ley 10/2010 anti-money-laundering rules, sharing client financial profiles with unverified third parties is a separate problem on top. See source 2, source 5 and source 6.

Q3

We only use AI for non-sensitive tasks like drafting emails. The strict rules don't apply, do they?

The moment a name, a NIF, a tax figure, a payslip line, a bank statement, a contract clause or an AEAT communication enters the prompt, you are processing personal data under GDPR. The AEPD's January 2026 decalogue (Cuidado con lo que le confías) is explicit on this point and directed at workers in firms exactly like yours. The "we only use it for emails" defence does not survive a single inspection that pulls actual prompt logs. See source 4.

Q4

Isn't local AI dramatically worse than GPT-4 / Claude / Gemini?

In 2023, yes. In 2026, no — not for the workloads that matter to a Spanish firm. Modern open-weight models (Llama 3.x, Qwen 2.5, Mistral Large, DeepSeek) running on the right hardware match or beat first-generation commercial APIs on Spanish-language tasks, document Q&A, citation-preserving retrieval, structured extraction and agentic workflows. AIibiza is built on Mac Studio (96GB unified memory) and NVIDIA DGX Spark (128GB) — hardware that hosts the same class of model that ran on a datacentre rack two years ago. The compliance gap has closed; the capability gap has not opened.

Q5

What about Aranzadi / Lefebvre / vLex AI features? They're Spanish, aren't they?

They may be Spanish-branded, but the sovereignty question is architectural rather than linguistic. Where a legal-AI product depends on US-controlled cloud infrastructure, identity, key-management or control-plane services, it creates the same class of CLOUD Act and FISA 702 exposure that the February 2026 sovereignty doctrine requires controllers to document. Under that doctrine, a Spanish-language UI on top of non-sovereign control-plane infrastructure is not enough by itself. AIibiza is designed so the inference, embeddings, index, orchestrator and keys can sit on hardware the client can physically point to. See source 2, source 9, source 10 and source 11.

Q6

What if the AEPD never actually fines us?

The AEPD has issued more than €40M in fines in the last three years and the trend line is steeper, not flatter. But the more immediate exposure is not the AEPD: it is civil liability to the client when sensitive data leaks, professional indemnity insurance that excludes cloud AI use, AML supervision by SEPBLAC for asesorías as sujetos obligados, and the EU AI Act's Article 50 transparency duties, which took effect on schedule on 2 August 2026 even after the Digital Omnibus pushed the high-risk system deadlines back to December 2027 and August 2028. The February 2026 doctrine is not the ceiling of the risk — it is the floor. See source 6 and source 8.

Q7

Can't we just self-host an open-source model on a VPS?

You can, and it is dramatically better than ChatGPT. But a VPS at Hetzner, OVH or AWS Frankfurt still leaves you with a control-plane problem: the keys, the IAM, the underlying virtualisation and the physical hardware are not under your sovereignty. The AEPD's sovereignty doctrine is hardware-aware. A local appliance — physically located in the client's office or in a Spanish-sovereign datacentre under a Spanish entity — is the architecture that most directly addresses the sovereignty question. See source 2.

// Benchmark

AIibiza vs Aranzadi after
the February 2026 doctrine

DimensionAranzadi (Thomson Reuters / Lefebvre)AIibiza
HostingCloud/SaaS architecture — verify region, processor chain, IAM, key management and control planeLocal appliance: Mac Studio 96GB + NVIDIA DGX Spark 128GB, on premises or Spanish-sovereign DC
GDPR Art. 28 (processor)Standard vendor DPA/subprocessor model — verify parent entity, subprocessors and control-plane exposureClient data is processed locally on the client's designated appliance; AIibiza access, if any, is governed by an Article 28 DPA (drafted, in legal review), just-in-time authorization and audit logging
GDPR Art. 32 (sovereignty, Feb 2026)Any non-EEA or US-controlled control-plane dependency creates documented Article 32 sovereignty risk to assessDesigned to keep the control plane physically and legally inside Spain, reducing Article 32 sovereignty exposure by architecture
Agentic AI (AEPD v1.2, Feb 2026)Vendor-controlled system — verify agent transparency, client-visible audit logs and testing evidenceHermes Agent: versioned prompt registry, per-action audit log, golden testing harness, declarative circuit breakers
BOE / BOIB / jurisprudenciaNational BOE + jurisprudencia (commercial database)Live BOE ingestion daily + extensible to BOIB (Balearics), DOGC, DOUE, CENDOJ, AEAT bulletins, registros mercantiles
Citation trackingInternal proprietary IDsCitation-preserving retrieval with original source links and Obsidian backlinks
MultilingualSpanish-firstSpanish + Catalan/Mallorquín + English embeddings tuned for the Balearic legal context
Data exitVendor ecosystem export terms must be reviewedPlain markdown (Obsidian) + QMD — fully portable, your own filesystem
Inspection trailVendor determines available inspection evidenceFull audit log on your own disk, append-only, defensible to the AEPD
// Questions Gestoría Firms Ask.

Questions Gestoría Firms Ask.

Eight answers.
Booking a call is faster.

?What happens when the hardware breaks?

Standard manufacturer warranty plus a continuity plan we design with you. The NAS × 3 backup is designed to prevent data loss — recovery takes hours, not days. For Studio and Enterprise tiers, redundancy is built into the architecture.

?Who maintains the system?

We do. Remote access requires explicit authorisation per session, runs through an encrypted point-to-point tunnel, and the entire session is recorded. Just-in-time access — no standing credentials, no surprise logins. Everything visible in the audit log, which you own.

?Can I migrate my existing data — A3, Sage, ContaPlus, Holded?

Yes. We ingest PDF, DOCX, XLSX, and structured exports. Your firm's memory — internal criteria, templates, resolved queries, historical files — is indexed in the first weeks. The system gets sharper the longer you use it.

?Do I need a DPO?

If you handle Article 9 personal data (health, ideology, sexual life — common in laboral procedures) or Article 10 data (criminal records, administrative sanctions) at scale, almost certainly yes. The AEPD package includes a justified DPO designation analysis. We can recommend qualified external DPOs in the Balearic Islands.

?What changes in August 2026?

The EU AI Act's (Regulation 2024/1689) Article 50 transparency obligations take effect on August 2, 2026, unchanged by the Digital Omnibus: systems used in financial and fiscal advice must be disclosed to the client as AI. The Digital Omnibus (in force since July 2026) deferred high-risk system obligations to December 2027 (standalone systems) and August 2028 (systems embedded in regulated products) — but left Article 50 untouched. Document 12 in the AEPD package is our compliance plan, updated for both dates.

?What about the catalan agencia — ACPDP — for clients in Cataluña?

The same architecture works. AEPD is the national authority, ACPDP applies to specific Catalan public-sector tracks. Both are satisfied by the same package because both apply RGPD and LOPDGDD. We adjust the Article 13 information notices for the Catalan reference where needed.

?Can the AI make decisions about my clients automatically?

No, by design. Every output is labelled as AI-generated under Article 50 of the AI Act. Anything with legal or financial effect is reviewed by you before it leaves the firm. The system is your associate, not your replacement — that distinction is contractual and technical, not aspirational.

?What does pricing look like?

Hardware at market price (RAM and GPU costs move week to week — we won't lie about a number). Setup, training, the AEPD package, and the DPA (drafted, currently in legal review) are included in every tier. A 30-minute sizing call gives you a real quote against your firm's actual volume. No pressure, no commitment.

// Sources

Primary AEPD and EU references
for the framework on this page

  1. 1.AEPD — Guía sobre Inteligencia Artificial y Protección de Datos — Most recent edition, 2024 baseline updated 2026. The original cloud-AI-with-client-data warning shot.
  2. 2.AEPD — Soberanía operativa en el tratamiento de datos personales — February 2026. The Article 32 sovereignty doctrine.
  3. 3.AEPD — IA agéntica desde la perspectiva de protección de datos, v1.2 — 18 February 2026. The agentic AI guidance.
  4. 4.AEPD — Decálogo "Cuidado con lo que le confías" — January 2026. Citizen- and worker-facing guidance on not pasting personal data into cloud AI tools.
  5. 5.GDPR Articles 28 and 32 — Regulation (EU) 2016/679 — Processor obligations and security of processing.
  6. 6.Ley 10/2010 — Anti-money-laundering obligations for sujetos obligados.
  7. 7.Ley General Tributaria, Art. 95 — Secreto tributario.
  8. 8.EU AI Act — Regulation (EU) 2024/1689 — Article 50 transparency duties in force from August 2026; high-risk system obligations deferred to December 2027 / August 2028 by the Digital Omnibus.
  9. 9.US CLOUD Act (18 U.S.C. § 2713) — Extraterritorial reach of US data requests over US-headquartered cloud providers.
  10. 10.US FISA Section 702 — Surveillance exposure for non-US persons processed on US infrastructure.
  11. 11.Executive Order 14117 — US bulk-data and government-related data access framework.
  12. 12.AEPD — Transcripción de voz con IA — January and April 2026 AEPD blog guidance on voice data, transcription, responsibility, rights and transparency.
// Start the conversation

Ready to stop watching
AI happen and start
running it?

We take a small number of new clients per quarter. If you are considering working with AI Ibiza, the conversation starts here.

base: Ibiza, Spain — clients: worldwide
response_time: within 24 hours
new_clients: limited / per quarter

Or reach Gee directly on WhatsApp

+66 80 223 7720