GDPR Ready
Your customers' data is stored in the EU
Last updated: September 28, 2026
Most chat tools ship from US servers and label themselves "GDPR-compliant." We store your data on EU servers in Germany and Finland, encrypt it in transit, and let you sign your DPA from inside the dashboard. No legal email chain.
Infrastructure
- Hosted in Germany and Finland. Our database and file storage — conversations, visitor profiles, uploads — are in the EU. Some sub-processors are in the US, such as the AI providers that write AI answers; each one is named on our sub-processor list.
- TLS encryption between your browser, your visitors and our servers.
- Continuous monitoring across the platform. Operational logs retained for incident review.
Access controls
- Role-based permissions on every dashboard and API call, enforced server-side.
- Authentication via Supabase Auth, with row-level security on the database itself. Every server route is gated.
- Critical actions written to an audit log: who did what, when, from where.
Privacy and GDPR
- Sign the DPA in one click from your dashboard. Download the countersigned PDF instantly.
- Every sub-processor is listed publicly with their legal terms linked.
- Data export and erasure controls, coming as part of the GDPR roadmap.