Security and privacy

How we protect your data and your customers' data

A short, factual overview of where data is stored, who can access it and what happens when you want it deleted. The details live in the legal documents; this page is the summary.

Hosting and storage

Data is stored in a data centre operating in the European Union. Every connection is encrypted in transit (TLS); the website and the app are protected with HSTS and a content security policy (CSP).

Sub-processors and data centre in the DPA

Access control

Each account's data is isolated. You invite team members with roles: Owner, Administrator, Team member, Read-only. Everyone sees only their own account's conversations, leads and settings.

Keys and credentials

Integration credentials (API keys, access tokens) are stored encrypted. With the bring-your-own-AI-key option, model calls run on your own provider account and the key is stored encrypted the same way.

Bot and abuse protection

Public forms are protected by a honeypot field and rate limiting; the contact form and the demo also by Cloudflare Turnstile. Widget embedding can be restricted to your own domains.

AI transparency

The chat tells visitors on every bot that they are talking to artificial intelligence, in the visitor's language and in a way that cannot be switched off, as Article 50 of the EU AI Act requires from 2 August 2026.

AI transparency notice

Data processing and GDPR

Every subscriber gets a data processing agreement (DPA) under Article 28 GDPR. The DPA lists our sub-processors and we announce changes in advance. Transfers outside the EU rely on the EU–US Data Privacy Framework or standard contractual clauses.

Data processing agreement

Retention and deletion

You can delete your account and data yourself: Settings, Account, Delete account. Deletion becomes final within 30 days, except for what the law requires us to keep (for example invoices). You decide the retention period for your visitors' data.

Privacy notice

Incidents and service status

We notify the affected subscriber of a data breach without undue delay. Service status is public and the system is backed up regularly.

Service status

Cookies and measurement

Analytics and marketing cookies are used only with your consent, and rejecting is as easy as accepting. Visitor measurement in the widget can be put behind a consent gate per bot, and conversations started in test mode are excluded from statistics.

Cookie policy

Legal documents

Questions about security?

Write to us and we answer your specific question: what data is stored where, who it is shared with and how it can be deleted.

Contact us