GDPR Ready

Your customers' data is stored in the EU

Last updated: September 28, 2026

Most chat tools ship from US servers and label themselves "GDPR-compliant." We store your data on EU servers in Germany and Finland, encrypt it in transit, and let you sign your DPA from inside the dashboard. No legal email chain.

Infrastructure

  • Hosted in Germany and Finland. Our database and file storage — conversations, visitor profiles, uploads — are in the EU. Some sub-processors are in the US, such as the AI providers that write AI answers; each one is named on our sub-processor list.
  • TLS encryption between your browser, your visitors and our servers.
  • Continuous monitoring across the platform. Operational logs retained for incident review.

Access controls

  • Role-based permissions on every dashboard and API call, enforced server-side.
  • Authentication via Supabase Auth, with row-level security on the database itself. Every server route is gated.
  • Critical actions written to an audit log: who did what, when, from where.

Privacy and GDPR

  • Sign the DPA in one click from your dashboard. Download the countersigned PDF instantly.
  • Every sub-processor is listed publicly with their legal terms linked.
  • Data export and erasure controls, coming as part of the GDPR roadmap.

Compliance documents