← Back to the help centre
Security, GDPR and the AI Act
The part nobody wants to read, and the part that can cost you a fine. Here it is, short.
Where is my customers' data stored?
On servers inside the European Union. Neither your business data nor your customers' conversations are used to train models.
Who is responsible for the data, you or me?
You are the data controller and we are the processor. In plain terms: the data is yours, we only process it to provide the service, and that is signed in a processing agreement.
Do you sign a data processing agreement?
Yes, always, and before anything is switched on. Article 28 of the GDPR requires it and we have it ready; it is not something to improvise.
A customer asks me to delete their data. What do I do?
You tell us and it is deleted everywhere: database, conversation history and backups. It is built as a process, not as a favour someone remembers to do.
How long are conversations kept?
Ninety days, and then they delete themselves. We do not keep endless history "just in case".
What does the EU AI Act require of me?
Since 2 August 2026, that you tell people they are talking to an AI. That is Article 50. All our bots say so up front, so that part is covered without you doing anything.
What if I need a data protection impact assessment?
It depends what data you handle. If you deal with health data or do profiling, probably yes. We tell you whether your case calls for one and help with the technical side, though you are the one who signs it.
Are there backups?
Every night, encrypted and off the main server. And we test that they restore, which is the part almost nobody does.
Didn't find what you were after?
Write to us and we answer ourselves, with no bot in between.