GDPR and security
Where your data lives, who can access it and what we do when something goes wrong. No badge parade — only what we actually do.
Este documento aún no se ha traducido a este idioma. El texto en inglés que figura debajo es la versión aplicable.
1.EU data storage
En resumen: your data lives in Europe — the database in Frankfurt.
Our primary database (Supabase, Postgres) is in Frankfurt. Hosting and CDN run through Cloudflare, with EU regions where possible. A few services process (partly) in the United States — AI models, speech recognition and the safety scan. For those we use European model contracts (SCCs). The full overview with locations is in the privacy policy.
2.Encryption
En resumen: encrypted in transit and at rest.
All traffic to chatbuild.com, your dashboard and the sites we host runs over TLS (https). Data in the database and in object storage is stored encrypted. Sites we publish automatically get a valid certificate — nothing for you to do.
3.Access control and MFA
En resumen: as few people as possible, with two-step verification.
Internal access to production systems is limited to the people who really need it (least privilege) and always sits behind multi-factor authentication. Rights are granted per role and revoked as soon as someone no longer needs them. Support does not look into your data uninvited; only when needed to solve a problem, and that is logged.
4.Logging and monitoring
En resumen: we keep track of what happens, so we spot errors and abuse quickly.
We log system events, errors and data access, and monitor for unusual patterns. For this we use Sentry (errors) and Langfuse (AI processing). Logs have restricted access and are not used for anything other than security, troubleshooting and quality. Retention periods are in the privacy policy.
5.Backups and recovery
En resumen: we make backups and test whether we can restore them.
We make regular encrypted backups of the database. Our recovery objectives: at most [[RPO]] of data loss (RPO) and a recovery time of at most [[RTO]] (RTO). We test restores periodically — a backup you've never restored is not a backup.
6.Separation of customer environments
En resumen: your data and other customers' data stay strictly separated.
Customer data is logically separated: every request is bound to one customer context, and the database enforces that data can only be retrieved within its own environment. The generated sites are separate from each other too, each on its own domain.
7.Safety scan at publication
En resumen: before a site goes live, we check it for unsafe content.
At publication we automatically check for signs of phishing and malware, among others with Google Web Risk, and for links to known harmful domains. If the check trips, the site does not go live and we contact you.
8.Prompt injection and AI abuse
En resumen: the AI may only work on your site — not on someone else's.
Because our AI works with your messages and supplied content, we take specific measures:
- the AI operates within strict boundaries: only on its own customer environment, with limited rights;
- content coming from messages and uploads is treated as untrusted input, not as instructions;
- sensitive actions (such as publishing or connecting a domain) require your explicit confirmation;
- rate limits and abuse detection on messages and AI edits;
- we don't train models on your data, unless you choose to allow it — see the privacy policy.
9.Incident procedure
En resumen: if something goes wrong, you hear it from us — fast and without weasel words.
We have a fixed procedure: identify and contain, investigate what happened, recover, and inform. If it concerns personal data we process for you, we notify you without unreasonable delay and at the latest within [[UREN]] hours, with the information you need for a possible notification to the Dutch Data Protection Authority. The arrangements are in article 9 of the data processing agreement. Afterwards we record what we change to prevent repetition.
10.Staff and confidentiality
En resumen: everyone at our end is bound to confidentiality and knows how we handle data.
Employees and engaged specialists are contractually bound to confidentiality and only get access to what their work requires. They are instructed on working securely and handling personal data. When someone leaves, we revoke access immediately.
11.Tests and pentests
En resumen: we have our security tested periodically, at cadence [[CADANS]].
In addition to automated checks on dependencies and configuration, we have penetration tests performed at a cadence of [[CADANS]]. Findings are addressed by risk. As a business customer you can request a summary of the latest test via [[SECURITY_EMAIL]].
12.Responsible disclosure
En resumen: found a vulnerability? Report it — and we take no legal action against you.
Report a vulnerability to [[SECURITY_EMAIL]] with enough detail to reproduce it. What you can expect from us:
- we confirm your report within [[REACTIETERMIJN]];
- we keep you informed of the fix;
- at your request we credit you as the finder once the issue is resolved;
- we take no legal action against reporters who act in good faith and stick to the rules below.
What we ask of you: don't view, change or download other people's data, don't disrupt any service (no DDoS, spam or brute force), no social engineering or physical break-ins, don't share a vulnerability with third parties before it's fixed, and don't leave backdoors. We offer no monetary reward, unless stated otherwise on [[BUG_BOUNTY]].
13.What we don't claim (yet)
Rather honest than impressive. At this moment we do not have:
- an ISO 27001 or SOC 2 certification;
- an external audit statement about our security;
- a guaranteed uptime percentage or hard SLA (see article 12 of the terms);
- full independence from non-EU services: AI models, speech recognition and the safety scan process (partly) in the US, under SCCs.
If that changes, we update this page — we put nothing here that we can't substantiate.
Pendiente de rellenar
This draft contains placeholders. Replace them all before publication — and claim nothing that isn't true yet.
- [[RPO]]
- Recovery Point Objective of the backups
- [[RTO]]
- Recovery Time Objective of the backups
- [[UREN]]
- Maximum data breach notification period in hours (same as the DPA)
- [[CADANS]]
- Frequency of pentests (e.g. yearly)
- [[SECURITY_EMAIL]]
- Email address for security reports
- [[REACTIETERMIJN]]
- Response time to a report (e.g. 3 working days)
- [[BUG_BOUNTY]]
- Reward policy or "no reward programme"
- [[DATUM]]
- Date of the latest change
- [[VERSIE]]
- Version number
Preguntas frecuentes
Respuestas rápidas a lo que más se pregunta aquí.
¿El dominio es realmente mío?
Sí. Tu dominio se registra a tu nombre. Si dejas ChatBuild, te lo llevas contigo sin más.
¿Mi web cumple automáticamente el RGPD?
Sí. Cada web incluye política de privacidad, política de cookies y formularios seguros. Si cambia la ley, lo actualizamos por ti.
¿Dónde se guardan mis datos?
En servidores dentro de la UE. No recopilamos más de lo necesario y nunca revendemos datos.
¿Tenéis un contrato de encargo del tratamiento?
Sí, va incluido de serie en todos los planes. Leer el contrato de tratamiento de datos