Automation and AI

n8n in business: licence, GDPR, the AI Act and your first processes

Short answer

n8n is a tool for building workflows that connect company systems (ERP, email, CRM, spreadsheets, APIs) with AI models. The Community edition can be run free of charge on your own server and used for the company's internal processes under the Sustainable Use License, but it must not be offered to customers as a service for building their own workflows. Start with one process that someone does every day by the same rules, with a named owner and an error alert.

This guide is for a business owner or an operations manager who wants to know what can realistically be automated in n8n, how much it costs, where the data will sit and what obligations the AI Act brings. We write from the perspective of a team that has hundreds of automations running in its deployments: some in n8n, some as our own services in Python.

What is n8n and what is it used for in a company?

n8n is a tool for building workflows from ready-made blocks: something happens, data passes through successive steps, and at the end it lands in another system or with a person. In a company it is used to connect the ERP, email, CRM, spreadsheets and APIs, and to plug in AI models wherever a document or a text has to be read.

Nodes, triggers, webhooks and code where needed

Every workflow starts with a trigger: a schedule, a new message in a mailbox or a webhook, that is, an address that another program calls when something changes. Next come integration nodes (e.g. a database, HTTP, email), logic nodes (conditions, loops, merging data) and the Code node, in which you can add a fragment in JavaScript or Python. The AI Agent node lets you build an agent that uses tools, e.g. a database query or sending a message.

The workflow is visible on a diagram, so it is easy to discuss with the department it concerns. Complex logic spread over dozens of nodes, however, quickly becomes hard to maintain.

Where to start with automation in n8n?

In short: with one process that someone performs every day by fixed rules. Before you build the first workflow, measure that process, name its owner and plan what happens when the automation gets it wrong.

  1. Choose one process and measure it. How many times a day it repeats and how long it takes today. Without that you cannot judge whether the automation paid off.
  2. Name the process owner. A specific person from the department who knows how the process should work and receives business alerts.
  3. List the systems and access. Where the data comes from, where it should go and on which accounts. Use technical accounts instead of employees' private accounts.
  4. Build a pilot in which the result is a draft first. For the first weeks a person checks every result before it goes further.
  5. Add an error workflow and an alert before launch. An automation that silently stops working is worse than none.

n8n, Make and Zapier: how they differ

No ranking, because the choice depends on the company. The differences concern mainly where it runs, billing and data control:

n8nMakeZapier
Where it runsyour own server (Community, Business, Enterprise) or n8n Cloudthe vendor's cloudthe vendor's cloud
What you pay forin Cloud for the monthly number of executions, regardless of the number of steps; self-hosted Community with no licence feesfor credits: most module actions use 1 creditfor tasks, that is, successful action steps (triggers do not count)
Data controlwith self-hosting, data and logs stay with youdata passes through the vendordata passes through the vendor

We also work with Make and Zapier in deployments. For simple cloud integrations they can be quicker to start. n8n has the advantage where data control, a large number of executions or direct access to systems in the company network, e.g. the ERP database, matter.

Is n8n free?

Yes, if you run the Community edition on your own server and use it for the company's internal processes. n8n Cloud and the Business and Enterprise editions are paid. With self-hosting you pay for the server, backups, updates and the time of the person who maintains it.

Sustainable Use License: what is allowed and what is not

n8n is not open source in the OSI sense. The code is made available under the Sustainable Use License, which allows you to use and modify n8n for internal business purposes or non-commercially. The licence FAQ gives examples.

Allowed:

  • automating your own company's processes,
  • building workflows for customers on your instance, as long as customers cannot create or edit them,
  • charging for building, deploying and maintaining workflows, training and consulting,
  • installing and maintaining n8n on the customer's server, as long as you do not additionally host it for them,
  • using n8n in the background of your own product in which users run workflows that you built and connect their accounts to them, but do not create or edit them.

Not allowed:

  • hosting n8n as a service in which customers build their own workflows,
  • letting external users configure workflows through their own interface, an API, MCP or an AI agent,
  • selling n8n under your own brand (white-label) or making it your own automation product,
  • using Enterprise features without a licence.

Self-hosted or n8n Cloud

According to the n8n documentation, without a licence key the instance runs as the free Community edition, and after registering with an email a few additional features are unlocked. Paid plans are required for, among others, projects, SSO, environments, external secret vaults, log streaming, sharing workflows and credentials, and Git versioning. Before you decide, check the current pricing.

Cloud takes the infrastructure off your hands. Self-hosting requires someone who looks after Docker, the database, HTTPS, backups and updates.

Does n8n on your own server settle the GDPR question?

It helps, but does not settle it by itself. Data flowing through a self-hosted instance stays in your infrastructure, and n8n is neither its controller nor its processor (privacy). You are responsible for the logs, the keys and the data sent to AI models.

Where the data, execution logs and credentials are

A checklist for a self-hosted instance:

  1. Execution logs contain the data that passed through the workflow, including personal data. By default n8n deletes executions older than 14 days, and when there are more than 10 thousand, also the oldest ones (manage execution data). You can save only executions with an error.
  2. Credentials (passwords, API keys) are encrypted with a key created at first start. Set your own N8N_ENCRYPTION_KEY and keep it outside the database backup, because without it you cannot restore the credentials from a backup, and a backup together with the key lets you decrypt them all (documentation).
  3. Telemetry is on by default and covers, among others, the shape of workflows and the domains of the services you connect to, but not the data in workflows. In n8n Cloud it cannot be switched off (privacy). With self-hosting you switch it off with the variable N8N_DIAGNOSTICS_ENABLED=false (control telemetry).
  4. Access to the editor: separate accounts, 2FA, an editor not exposed publicly on the internet. Webhooks can be public, the editor does not have to be.

With n8n Cloud, n8n is, according to its own documentation, both a controller (e.g. of account data) and a processor of workflow data. A data processing agreement (a DPA with standard contractual clauses) is part of the terms.

AI models and personal data

When a workflow sends an invoice or an email to an AI model, the data goes to its provider. You need a data processing agreement (Article 28 of the GDPR), knowledge of where the data is processed and whether it is used to train models, and minimization: the content of the document goes to the model, not the customer's whole history. UODO, the Polish data protection authority, has published lists of questions to ask before deploying an AI tool (in Polish), separately for SMEs using ready-made systems. It is a good starting point.

Which processes to automate first?

In short: those that someone performs every day by the same rules and whose result is easy to check. Below are five typical candidates.

1. Invoices from email → OCR and AI → ERP or approval workflow

  1. Trigger: a new message in the invoice mailbox.
  2. Discard messages that are not invoices and unpack archives.
  3. Read a PDF with a text layer directly, a scan through OCR and an AI model.
  4. Check the rules: the tax ID (NIP) checksum, whether net plus VAT gives gross, the bank account on the VAT white list.
  5. Compare with invoices fetched from KSeF (Poland's National e-Invoicing System) so that nothing is counted twice.
  6. Send for approval or create a document in the ERP.

We describe the details of this process in our KSeF integration with Comarch ERP XL, which also reads invoices that arrive outside KSeF.

2. Orders from email → system

A customer sends an order in the body of an email or in an attachment. The workflow recognizes the counterparty by address and tax ID, reads the lines, matches them to the product register and creates the order. Lines that could not be matched we do not guess: they go to the sales rep. When orders come from a shop rather than email, see the guide on shop-to-ERP integration.

3. Counterparty verification

For a new counterparty, or before a transfer, the workflow fetches data from GUS (REGON), CEIDG or KRS and checks the bank account on the VAT white list. It saves the result with the counterparty and reports discrepancies (a different account than on the invoice, a struck-off entity) to the person who approves the payment. The registers we connect to are listed in technologies and integrations.

4. A daily report and alerts

A daily report gathers figures from several systems into one message. Send alerts by email or Telegram only when something needs a reaction: an invoice has been waiting for approval too long, the ERP synchronization is stuck, a counterparty failed verification. A channel that rings non-stop stops being read.

5. A quoting agent

A customer enquiry (email, file, scan) goes to an AI agent that recognizes the lines, picks goods from the product register and calculates prices according to the company's rules. The result is a draft quote that the sales rep checks and sends. The agent does not send anything to the customer on its own.

When n8n, and when your own service in Python?

n8n works well for integrations and workflows that change often and have clear logic. Your own service is better when the volume is large, the logic complex and an error costly, because then you need tests, code review and versioning. Both forms run with us, often in one process.

Criterionn8nA service in Python
Time to the first versionshortlonger
Complex logic, many exceptionshard to maintainnatural
Automated testslimitedfull
Versioning and change reviewGit in paid plans, JSON exportGit, code review
Changes by a non-technical personpossibleno

AI in automations: where it helps and where it harms

Reading, classification and summaries

AI reads documents without a template well, classifies messages ("invoice, order, complaint, spam") and summarizes long threads. It does poorly where a rule is enough: comparing amounts, checking a tax ID or a payment due date. A rule is cheaper, faster and always gives the same result. Every AI reading is worth checking with rules before it goes further.

A human in the loop for financial decisions

Invoice approval, a transfer, a discount, a message to a customer: here AI prepares and a person decides. In n8n the AI Agent node has a built-in human-in-the-loop mechanism: selected agent tools require approval by a person, e.g. through Telegram or Slack, before they run.

The AI Act in automations: status as of October 2026

Article 50: a bot must say that it is AI

Since 2 August 2026 Article 50 of Regulation (EU) 2024/1689 has applied. An AI system intended for direct interaction with people must be designed so that it informs the other party of this, unless it is obvious from the context. The obligation rests on the provider, and a company that built the bot in n8n itself is also a provider. The obligation also covers a bot for employees.

The Digital Omnibus: high-risk systems later

Regulation (EU) 2026/1744 (the Digital Omnibus on AI), published on 24 July 2026, moved the obligations for high-risk systems from Annex III to 2 December 2027. It did not move the obligation from Article 50(1). A transitional period, until 2 December 2026, was given only to generative systems placed on the market before 2 August 2026, in respect of marking synthetic content (Article 50(2)). Typical office automations are in principle not high-risk systems, but be careful with AI that assesses job candidates, employees or the creditworthiness of individuals: those uses are in Annex III.

The Polish act on artificial intelligence systems

The Act of 3 July 2026 (Journal of Laws 2026, item 1003) has applied since 11 August 2026. The market surveillance authority is the Commission for the Development and Safety of Artificial Intelligence. Some of the provisions, including those on inspections, proceedings and penalties, enter into force on 28 October 2026.

Maintenance: monitoring, errors, retries, the process owner

An automation without maintenance eventually stops working silently: someone changes the mailbox password, a supplier changes the file format, an API starts returning different fields.

A checklist:

  • Error workflow: in n8n every workflow can have an error-handling workflow assigned that starts from the Error Trigger node and sends an alert (documentation).
  • Retries: retry brief connection errors with growing intervals, and once the attempts run out mark the task as failed, with the option of a manual retry. Nothing should disappear.
  • Idempotency: a retried task must not create a second document. Check whether the record already exists.
  • The process owner: a specific person from the department, not "IT", who knows what the workflow does and receives business alerts.
  • Backups and updates: a database backup, an export of workflows, the encryption key in a safe place, n8n updates tested before deployment.

Typical mistakes: one shared login to all systems, workflows on an employee's private account and no alert on error.

How we do it in Business Panel

In Business Panel, deployed in a company from the wholesale industry, automations run in two layers: integration workflows, e.g. collecting orders, in n8n, and processes with a lot of logic, that is, fetching invoices from KSeF, the approval workflow and export to Comarch ERP XL, as services in Python run on a schedule. Writes to the ERP go through a retry queue, and every automation has a run history and an error alert. The AI assistants that we use in automations are described on the page about AI automation.

Prefer to talk right away? Write to us.

Questions and answers

What is n8n and what is it used for in a company?

n8n is a tool for building automation workflows from ready-made nodes: triggers, integrations with systems, conditions, code and AI models. In a company it is used to move data between systems, read documents from email, for reports, notifications and simple AI agents that prepare drafts for a human to approve.

Is n8n free to use in a company?

The Community edition run on your own server is free if you use it for the company's internal purposes. n8n Cloud and the Business and Enterprise editions, with features such as SSO, projects or Git versioning, are paid. With your own server the real cost is infrastructure, backups, updates and the time of the person who maintains it.

Can n8n be hosted on your own server because of GDPR?

Yes. According to the n8n documentation, data that flows through a self-hosted instance stays in your infrastructure, and n8n is neither its controller nor its processor. Hosting it yourself does not take care of GDPR by itself, though: you need to limit the retention of execution logs, protect the credential encryption key and sign data processing agreements with the AI model providers you send data to.

Can I use n8n in a product for customers?

Yes, within limits. The n8n licence FAQ allows you to use n8n in the background of your own product in which users run workflows that you built, and even connect their own accounts to them. You may not, however, give them the ability to create or edit workflows, host n8n as a service or sell it under your own brand.

Does a chatbot built in n8n have to say that it is AI?

Yes. Since 2 August 2026 Article 50(1) of Regulation (EU) 2024/1689 requires an AI system intended for direct interaction with people to inform them of this, unless it is obvious from the context. The obligation rests on the provider of the system, which also means a company that built the bot in n8n itself. The Digital Omnibus did not postpone this obligation (Article 50(1)).

Sources

  1. Community license (Sustainable Use License) — n8n documentation
  2. License FAQ — n8n documentation
  3. Choose how to use n8n (Cloud, self-hosted editions) — n8n documentation
  4. Privacy (self-hosted and n8n Cloud, DPA) — n8n documentation
  5. Manage execution data — n8n documentation
  6. Set a custom encryption key — n8n documentation
  7. n8n pricing (billing per execution) — n8n.io
  8. Make pricing (credits) — make.com
  9. How is task usage measured in Zapier — Zapier Help Center
  10. Control telemetry — n8n documentation
  11. Handle errors gracefully (error workflow) — n8n documentation
  12. Human-in-the-loop for tools (AI Agent) — n8n documentation
  13. Regulation (EU) 2024/1689 (the Artificial Intelligence Act) — EUR-Lex
  14. Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ EU of 24 July 2026 — EUR-Lex
  15. Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003) — ISAP (in Polish)
  16. Before you deploy an AI tool, check whether it complies with the GDPR — UODO, the Polish data protection authority (6 August 2026, in Polish)
  17. Regulation (EU) 2016/679 (GDPR) — EUR-Lex

Legal and technical status as of 9 October 2026. This article is for information only and is not legal or tax advice.

Keep reading

  • Service

    Process automation and AI

    Automations, AI agents and notifications that take repetitive work off your team.

    Service details
  • Service

    KSeF and Comarch ERP integrations

    Purchase invoices from KSeF connected to Comarch ERP XL, document workflow and CRM. Typically up to 3 months from project start.

    Service details

Want to implement this in your company?

Describe how this process looks in your company today. The first conversation and a preliminary analysis are free, and we reply within 24 hours.