The three questions European procurement asks an Asian vendor
Transfer basis, AI Act exposure, and whether anyone will be awake when you need them. Most vendor pages avoid all three. Here are our answers up front.
We start from the fact that Singapore has no adequacy decision
Most vendors selling into the EU from Asia lead with "GDPR compliant" and hope nobody asks the follow-up. The follow-up is: on what transfer basis? Singapore does not hold an EU adequacy decision, so a transfer to us runs on Standard Contractual Clauses supported by a documented Transfer Impact Assessment, under an Article 28 processor agreement. We bring that paperwork to the first call instead of discovering it in your vendor-security review six weeks later.
AI Act classification before architecture, not after
With the Act's high-risk obligations under Annex III now applying, the question of which tier your system falls into is an architectural constraint, not a legal footnote. A lead-scoring agent and a creditworthiness or employment-screening agent are different builds under the Act — logging, human oversight, technical documentation and data-governance duties attach to one and not the other. We classify at scoping so you are not retrofitting an audit trail into a shipped system.
A two-to-three hour window we actually keep
Singapore is UTC+8, so the honest number is two hours of overlap with CET in winter and three in summer — around 09:00–11:00 your time, more with Warsaw or Helsinki. Anyone quoting you five or six hours is describing a timezone that doesn't exist. What makes it work is that the window is protected: a standing daily slot at the start of your day, with written handover covering the hours we're ahead, so decisions never wait a full cycle.
Compliance mechanics, stated plainly
Send this section to your DPO. If anything here doesn’t match your requirements, it is a scoping conversation rather than a dealbreaker.
What we build for European operators
Module A
Deterministic agents for regulated operations
Document extraction, enquiry routing, lead qualification and automated reporting — built with the logging and human-oversight hooks that make an agent defensible to an auditor, not just performant in a demo.
Explore AI automationModule B
Web platforms that pass Core Web Vitals and a cookie audit
Next.js and headless architectures built for genuine multi-language operation across European markets, with consent management and tag governance treated as part of the build rather than a plugin added at launch.
View web engineeringModule C
Technical SEO across multi-market, multi-language estates
hreflang architecture that survives a redesign, JSON-LD entity graphs, and market-by-market search strategy for businesses running one brand across a dozen European domains and languages.
Explore technical SEOEngineered for Europe’s regulated sectors
What your DPO will ask
Send us the scope and the regulatory position. You will get an architecture, an AI Act risk classification, and the transfer mechanics in writing.