Trust
Compliance
Where we stand on data protection today. ChatRobo is early, so this page states our position rather than implying a programme we have not built.
Frameworks & commitments
GDPR & UK GDPR
We act on data-subject requests and design for data minimisation. Ask us for a Data Processing Addendum and we will put one in place with you.
CCPA/CPRA
We do not sell personal information, and we honour privacy rights for California residents.
No certification yet
We hold no SOC 2, ISO 27001 or equivalent attestation, and no audit is currently in progress. If you need one, tell us — it is a cost and a timeline, and knowing it is required changes our planning.
Data processing
When ChatRobo processes messages from your end-users, we act as a processor on your behalf, under your instructions and our Data Processing Addendum (DPA). You remain the controller of that data.
- DPA — email privacy@chatrobo.app and we will agree one with you. We do not yet publish a standard countersigned template.
- Sub-processors — ChatRobo runs on managed hosting and managed Postgres, and uses third-party services for model inference, transactional email and payments. Ask us for the current list and we will send it.
- Model providers— our provider's API terms state that API content is not used to train their models. That is their published term, not a bespoke contract we negotiated.
- Transfers — our infrastructure is hosted in Australia (Sydney). If your obligations require a specific region or transfer mechanism, raise it before you deploy.
Your responsibilities
Because you decide what the assistant is trained on and how it's deployed, you should ensure you have a lawful basis for the data you connect, provide appropriate notice to your end-users, and configure retention to match your policies. We give you the controls; you own the deployment.
Need documentation for a vendor review? See Security or contact us for our DPA, sub-processor list, and security overview.