Trust
Compliance
How ChatRobo helps you meet your data-protection obligations when you deploy AI to your customers.
Frameworks & commitments
GDPR & UK GDPR
We support data-subject requests, offer a Data Processing Addendum, and rely on Standard Contractual Clauses for international transfers.
CCPA/CPRA
We honour privacy rights for California residents and do not sell personal information.
SOC 2 (in progress)
We build to SOC 2 Trust Services Criteria and are pursuing formal attestation. Contact us for our current status and roadmap.
Data processing
When ChatRobo processes messages from your end-users, we act as a processor on your behalf, under your instructions and our Data Processing Addendum (DPA). You remain the controller of that data.
- DPA — available to all customers; email privacy@chatrobo.app to countersign.
- Sub-processors — we maintain a current list of the vendors that help run ChatRobo (hosting, model inference, email, payments) and provide notice of material changes.
- Model providers — contractually prohibited from training their foundation models on your content.
- Transfers — safeguarded by Standard Contractual Clauses where applicable.
Your responsibilities
Because you decide what the assistant is trained on and how it's deployed, you should ensure you have a lawful basis for the data you connect, provide appropriate notice to your end-users, and configure retention to match your policies. We give you the controls; you own the deployment.
Need documentation for a vendor review? See Security or contact us for our DPA, sub-processor list, and security overview.