Trust

Compliance

How ChatRobo helps you meet your data-protection obligations when you deploy AI to your customers.

Frameworks & commitments

GDPR & UK GDPR

We support data-subject requests, offer a Data Processing Addendum, and rely on Standard Contractual Clauses for international transfers.

CCPA/CPRA

We honour privacy rights for California residents and do not sell personal information.

SOC 2 (in progress)

We build to SOC 2 Trust Services Criteria and are pursuing formal attestation. Contact us for our current status and roadmap.

Data processing

When ChatRobo processes messages from your end-users, we act as a processor on your behalf, under your instructions and our Data Processing Addendum (DPA). You remain the controller of that data.

  • DPA — available to all customers; email privacy@chatrobo.app to countersign.
  • Sub-processors — we maintain a current list of the vendors that help run ChatRobo (hosting, model inference, email, payments) and provide notice of material changes.
  • Model providers — contractually prohibited from training their foundation models on your content.
  • Transfers — safeguarded by Standard Contractual Clauses where applicable.

Your responsibilities

Because you decide what the assistant is trained on and how it's deployed, you should ensure you have a lawful basis for the data you connect, provide appropriate notice to your end-users, and configure retention to match your policies. We give you the controls; you own the deployment.

Need documentation for a vendor review? See Security or contact us for our DPA, sub-processor list, and security overview.