Who is responsible for what
For your visitors' conversations, you are the controller and we are your processor: we store and process them on your behalf, to run your agent, and for nothing else. We do not sell data, show advertising or build profiles, and we do not train models on your content or your conversations. An agency sits in between: its client is the controller, the agency their processor, and we are the agency's. A data processing agreement is available: write to management@sri-group.eu.
Where the data lives
| What | Who | Where |
|---|---|---|
| The application | Vercel | Frankfurt, Germany |
| Agents, sources and conversations | Neon (Postgres) | European Union |
| Uploaded files and logos | Cloudflare R2 | EU jurisdiction |
| Writing the answers | Cortecs | A European model gateway |
| Turning text into search vectors | OpenAI | United States |
| E-mail we send: reports, lead and ticket alerts | Resend | United States, sent from servers in Ireland |
The two steps outside the EU. To search by meaning, each passage of your sources and each question is turned into a row of numbers. That step runs at OpenAI in the United States, under its data-processing terms, and OpenAI does not train on it. The e-mails we send go through Resend, which processes mail in the United States under the EU-US Data Privacy Framework and standard contractual clauses. We name both rather than let "EU-hosted" suggest otherwise.
What is stored about a visitor
- The conversation, with the sources and measurements behind each answer, until you delete it.
- No IP address. For the message limit we keep a fingerprint of it for 24 hours, made with a key that changes every day.
- No cookies. The widget sets none, and keeps nothing in the visitor's browser before they use the chat.
- No name or e-mail address, unless you switch on the contact form or tickets and the visitor fills them in.
What the GDPR asks of you, and how this helps
- Tell visitors. Your privacy notice names the chat, what it stores and the processors above. Our privacy page and Data and privacy give you every fact to write it from.
- Collect only what you need. The chat asks for no personal details unless you switch the contact form or tickets on. If you let the contact form ask for consent to news and offers, it asks for it separately and records the words the visitor agreed to.
- Answer requests. A visitor may ask what you hold and ask for it to be erased. You find their conversation in Activity and delete it, and contact details and tickets each have their own delete.
- Keep it in the EU where you can. Your visitors' conversations, your sources and your files are stored in the EU.
The AI Act comes on top
The GDPR is about personal data. The EU AI Act adds that visitors must know they are talking to an AI. Every ChatterLab widget says so in the widget's language, and no plan or setting removes it. The AI Act and your chatbot.
Questions about the GDPR
Is ChatterLab GDPR compliant?
Yes, in what is ours to do: we act as your processor, with a data processing agreement on request, keep your visitors' conversations, your sources and your files in the EU, set no cookies, store no IP addresses, and give you the tools to erase what a visitor asks you to. Two steps run in the United States under data-processing terms, as listed above. Whether your own use complies also depends on you: your privacy notice, and what you ask your visitors for.
Is any data transferred outside the EU?
Yes, two things, both under data-processing terms: the text of your sources and of each question passes through OpenAI in the US to be turned into search vectors, and the e-mails we send go through Resend in the US. Conversations, sources and files are stored in the EU.
Do I need a cookie banner for the chat?
The widget sets no cookies, and stores nothing in the visitor's browser before they use the chat. Once they send a message, it keeps two numbers in the browser's storage until the tab is closed, to hold the conversation together; neither identifies a person. The optional second nudge, an invitation to chat later in a visit, keeps one more value and appears only when your site passes your visitors' consent. Whether your cookie notice mentions these is for you to decide: most treat them as functional.
Can I get a data processing agreement?
Yes. Write to management@sri-group.eu and we send you our data processing agreement to sign.
Can a visitor have their data erased?
Yes. You find the conversation in Activity and delete it. Contact details and tickets each have their own delete, and a file a visitor sent can be erased on its own.