Data protection
GDPR and chatbots
A chatbot on your website processes whatever visitors type into it, and that regularly includes personal data. That brings data protection law into play, however small your business is.
This page explains which obligations usually follow from that, which of them we take on as the provider and which stay with you. It is not legal advice; there is a separate paragraph on that at the end.
Written from the EU GDPR, read in the UK
We are a provider based in Germany, and our service is subject to the EU General Data Protection Regulation (GDPR). This page is written from that standpoint, and the articles it cites are articles of the EU GDPR.
For a business in the UK, the UK GDPR applies. In its main principles it corresponds to the EU GDPR, but it is a separate law. Read the points below as a description of our service and a guide to the usual obligations, not as a statement of UK law.
What data a chatbot actually processes
Before you talk about obligations, it is worth looking at what is actually involved. With our bot it is three things, and no more.
- The text of the conversation
- Everything the visitor writes and everything the bot replies. What a visitor types in is up to them, and some write more than would be necessary.
- Contact details left voluntarily
- Name, phone number, email address, if the visitor gives them of their own accord because they want a call back. The bot does not ask for them unless the visitor wants it to.
- What is technically necessary
- A random identifier, so that the conversation does not break off when the page reloads. No IP address with the conversations and no cookies.
What we take on as the provider
These points are our responsibility. The same points are set out in detail in our privacy policy and in the data processing agreement you receive from us.
- Conversations and contact details from the chat are deleted after 30 days at the latest, unless agreed otherwise.
- The chat window sets no cookies. No IP addresses are stored with the conversations.
- Data is stored on a server in Germany.
- To produce the answer, the question goes to Anthropic in the United States, on the basis of the EU standard contractual clauses under Article 46 GDPR.
- A data processing agreement under Article 28 GDPR is concluded with every customer before processing begins.
- The chat window carries the notice required by Article 50(1) of the EU AI Act that an AI is answering.
What stays with you
Four points that depend on your business and that nobody can take off your hands. We provide the template wording; you have to put it in place yourself.
- 1. Conclude a data processing agreement
- Under Article 28 GDPR it is mandatory as soon as we process personal data on your behalf, and it is concluded before the start. You get it from us; you do not have to draw it up.
- 2. Update your privacy policy
- It has to say that you use a chatbot, who operates it, what data is involved, how long it is stored, and that a transfer to the United States takes place to produce the answer. We supply the wording.
- 3. Keep your record of processing activities
- Under Article 30 GDPR most businesses keep such a record. The chatbot belongs in it as an entry of its own.
- 4. Determine the lawful basis
- For running a chatbot to answer customer enquiries, businesses usually rely on legitimate interests under Article 6(1)(f) GDPR, or on steps taken prior to entering into a contract under point (b). Which one is right in your case depends on how you use it.
The notice under the EU AI Act
Under the EU AI Act there is a separate obligation in addition to the GDPR: under Article 50(1), people must be informed that they are interacting with an AI system, unless this is obvious.
With us, this notice is shown visibly in the chat window without you having to do anything. The bot also does not pretend to be a person if someone asks it directly.
How you can check a provider
Five questions you should put to every chatbot provider, ourselves included. The answers should come in writing, not over the phone.
- In which country are the servers on which the conversations are stored?
- Does a request leave the EU, and if so, on what basis under Chapter V GDPR?
- After what period are conversations and contact details deleted, and does that happen automatically?
- Do I get a data processing agreement under Article 28 GDPR, and may I read it beforehand?
- Does the chat window set cookies or include third-party services?
Related
Questions about data protection? Ask us first.
We will send you the data processing agreement and the wording for your privacy policy to read before anything goes live. We reply within 24 hours.
Request the documentsLast checked: 3 October 2026