GDPR and security
Where your data lives, who can access it and what we do when something goes wrong. No badge parade — only what we actually do.
1.EU data storage
In short: your data lives in Europe — the database in Frankfurt.
Our primary database (Supabase, Postgres) is in Frankfurt. Hosting and CDN run through Cloudflare, with EU regions where possible. A few services process (partly) in the United States — AI models, speech recognition and the safety scan. For those we use European model contracts (SCCs). The full overview with locations is in the privacy policy.
2.Encryption
In short: encrypted in transit and at rest.
All traffic to chatbuild.com, your dashboard and the sites we host runs over TLS (https). Data in the database and in object storage is stored encrypted. Sites we publish automatically get a valid certificate — nothing for you to do.
3.Access control and MFA
In short: as few people as possible, with two-step verification.
Internal access to production systems is limited to the people who really need it (least privilege) and always sits behind multi-factor authentication. Rights are granted per role and revoked as soon as someone no longer needs them. Support does not look into your data uninvited; only when needed to solve a problem, and that is logged.
4.Logging and monitoring
In short: we keep track of what happens, so we spot errors and abuse quickly.
We log system events, errors and data access, and monitor for unusual patterns. For this we use Sentry (errors) and Langfuse (AI processing). Logs have restricted access and are not used for anything other than security, troubleshooting and quality. Retention periods are in the privacy policy.
5.Backups and recovery
In short: we make backups and test whether we can restore them.
We make regular encrypted backups of the database. Our recovery objectives: at most [[RPO]] of data loss (RPO) and a recovery time of at most [[RTO]] (RTO). We test restores periodically — a backup you've never restored is not a backup.
6.Separation of customer environments
In short: your data and other customers' data stay strictly separated.
Customer data is logically separated: every request is bound to one customer context, and the database enforces that data can only be retrieved within its own environment. The generated sites are separate from each other too, each on its own domain.
7.Safety scan at publication
In short: before a site goes live, we check it for unsafe content.
At publication we automatically check for signs of phishing and malware, among others with Google Web Risk, and for links to known harmful domains. If the check trips, the site does not go live and we contact you.
8.Prompt injection and AI abuse
In short: the AI may only work on your site — not on someone else's.
Because our AI works with your messages and supplied content, we take specific measures:
- the AI operates within strict boundaries: only on its own customer environment, with limited rights;
- content coming from messages and uploads is treated as untrusted input, not as instructions;
- sensitive actions (such as publishing or connecting a domain) require your explicit confirmation;
- rate limits and abuse detection on messages and AI edits;
- we don't train models on your data, unless you choose to allow it — see the privacy policy.
9.Incident procedure
In short: if something goes wrong, you hear it from us — fast and without weasel words.
We have a fixed procedure: identify and contain, investigate what happened, recover, and inform. If it concerns personal data we process for you, we notify you without unreasonable delay and at the latest within [[UREN]] hours, with the information you need for a possible notification to the Dutch Data Protection Authority. The arrangements are in article 9 of the data processing agreement. Afterwards we record what we change to prevent repetition.
10.Staff and confidentiality
In short: everyone at our end is bound to confidentiality and knows how we handle data.
Employees and engaged specialists are contractually bound to confidentiality and only get access to what their work requires. They are instructed on working securely and handling personal data. When someone leaves, we revoke access immediately.
11.Tests and pentests
In short: we have our security tested periodically, at cadence [[CADANS]].
In addition to automated checks on dependencies and configuration, we have penetration tests performed at a cadence of [[CADANS]]. Findings are addressed by risk. As a business customer you can request a summary of the latest test via [[SECURITY_EMAIL]].
12.Responsible disclosure
In short: found a vulnerability? Report it — and we take no legal action against you.
Report a vulnerability to [[SECURITY_EMAIL]] with enough detail to reproduce it. What you can expect from us:
- we confirm your report within [[REACTIETERMIJN]];
- we keep you informed of the fix;
- at your request we credit you as the finder once the issue is resolved;
- we take no legal action against reporters who act in good faith and stick to the rules below.
What we ask of you: don't view, change or download other people's data, don't disrupt any service (no DDoS, spam or brute force), no social engineering or physical break-ins, don't share a vulnerability with third parties before it's fixed, and don't leave backdoors. We offer no monetary reward, unless stated otherwise on [[BUG_BOUNTY]].
13.What we don't claim (yet)
Rather honest than impressive. At this moment we do not have:
- an ISO 27001 or SOC 2 certification;
- an external audit statement about our security;
- a guaranteed uptime percentage or hard SLA (see article 12 of the terms);
- full independence from non-EU services: AI models, speech recognition and the safety scan process (partly) in the US, under SCCs.
If that changes, we update this page — we put nothing here that we can't substantiate.
Still to fill in
This draft contains placeholders. Replace them all before publication — and claim nothing that isn't true yet.
- [[RPO]]
- Recovery Point Objective of the backups
- [[RTO]]
- Recovery Time Objective of the backups
- [[UREN]]
- Maximum data breach notification period in hours (same as the DPA)
- [[CADANS]]
- Frequency of pentests (e.g. yearly)
- [[SECURITY_EMAIL]]
- Email address for security reports
- [[REACTIETERMIJN]]
- Response time to a report (e.g. 3 working days)
- [[BUG_BOUNTY]]
- Reward policy or "no reward programme"
- [[DATUM]]
- Date of the latest change
- [[VERSIE]]
- Version number
Frequently asked questions
Quick answers to what people ask most here.
Is the domain really mine?
Yes. Your domain is registered in your name. If you leave ChatBuild, you simply take it with you.
Is my site automatically GDPR-proof?
Yes. Every site gets a privacy policy, cookie policy and secure forms. When the law changes, we update it for you.
Where is my data stored?
On servers within the EU. We collect no more than necessary and never resell data.
Do you have a data processing agreement?
Yes, it's included with every plan as standard. Read the data processing agreement