GDPR and security
Where your data lives, who can access it and what we do when something goes wrong. No badge parade — only what we actually do.
Questo documento non è ancora stato tradotto in questa lingua. Il testo inglese qui sotto è la versione che fa fede.
1.EU data storage
In breve: your data lives in Europe — the database in Frankfurt.
Our primary database (Supabase, Postgres) is in Frankfurt. Hosting and CDN run through Cloudflare, with EU regions where possible. A few services process (partly) in the United States — AI models, speech recognition and the safety scan. For those we use European model contracts (SCCs). The full overview with locations is in the privacy policy.
2.Encryption
In breve: encrypted in transit and at rest.
All traffic to chatbuild.com, your dashboard and the sites we host runs over TLS (https). Data in the database and in object storage is stored encrypted. Sites we publish automatically get a valid certificate — nothing for you to do.
3.Access control and MFA
In breve: as few people as possible, with two-step verification.
Internal access to production systems is limited to the people who really need it (least privilege) and always sits behind multi-factor authentication. Rights are granted per role and revoked as soon as someone no longer needs them. Support does not look into your data uninvited; only when needed to solve a problem, and that is logged.
4.Logging and monitoring
In breve: we keep track of what happens, so we spot errors and abuse quickly.
We log system events, errors and data access, and monitor for unusual patterns. For this we use Sentry (errors) and Langfuse (AI processing). Logs have restricted access and are not used for anything other than security, troubleshooting and quality. Retention periods are in the privacy policy.
5.Backups and recovery
In breve: we make backups and test whether we can restore them.
We make regular encrypted backups of the database. Our recovery objectives: at most [[RPO]] of data loss (RPO) and a recovery time of at most [[RTO]] (RTO). We test restores periodically — a backup you've never restored is not a backup.
6.Separation of customer environments
In breve: your data and other customers' data stay strictly separated.
Customer data is logically separated: every request is bound to one customer context, and the database enforces that data can only be retrieved within its own environment. The generated sites are separate from each other too, each on its own domain.
7.Safety scan at publication
In breve: before a site goes live, we check it for unsafe content.
At publication we automatically check for signs of phishing and malware, among others with Google Web Risk, and for links to known harmful domains. If the check trips, the site does not go live and we contact you.
8.Prompt injection and AI abuse
In breve: the AI may only work on your site — not on someone else's.
Because our AI works with your messages and supplied content, we take specific measures:
- the AI operates within strict boundaries: only on its own customer environment, with limited rights;
- content coming from messages and uploads is treated as untrusted input, not as instructions;
- sensitive actions (such as publishing or connecting a domain) require your explicit confirmation;
- rate limits and abuse detection on messages and AI edits;
- we don't train models on your data, unless you choose to allow it — see the privacy policy.
9.Incident procedure
In breve: if something goes wrong, you hear it from us — fast and without weasel words.
We have a fixed procedure: identify and contain, investigate what happened, recover, and inform. If it concerns personal data we process for you, we notify you without unreasonable delay and at the latest within [[UREN]] hours, with the information you need for a possible notification to the Dutch Data Protection Authority. The arrangements are in article 9 of the data processing agreement. Afterwards we record what we change to prevent repetition.
10.Staff and confidentiality
In breve: everyone at our end is bound to confidentiality and knows how we handle data.
Employees and engaged specialists are contractually bound to confidentiality and only get access to what their work requires. They are instructed on working securely and handling personal data. When someone leaves, we revoke access immediately.
11.Tests and pentests
In breve: we have our security tested periodically, at cadence [[CADANS]].
In addition to automated checks on dependencies and configuration, we have penetration tests performed at a cadence of [[CADANS]]. Findings are addressed by risk. As a business customer you can request a summary of the latest test via [[SECURITY_EMAIL]].
12.Responsible disclosure
In breve: found a vulnerability? Report it — and we take no legal action against you.
Report a vulnerability to [[SECURITY_EMAIL]] with enough detail to reproduce it. What you can expect from us:
- we confirm your report within [[REACTIETERMIJN]];
- we keep you informed of the fix;
- at your request we credit you as the finder once the issue is resolved;
- we take no legal action against reporters who act in good faith and stick to the rules below.
What we ask of you: don't view, change or download other people's data, don't disrupt any service (no DDoS, spam or brute force), no social engineering or physical break-ins, don't share a vulnerability with third parties before it's fixed, and don't leave backdoors. We offer no monetary reward, unless stated otherwise on [[BUG_BOUNTY]].
13.What we don't claim (yet)
Rather honest than impressive. At this moment we do not have:
- an ISO 27001 or SOC 2 certification;
- an external audit statement about our security;
- a guaranteed uptime percentage or hard SLA (see article 12 of the terms);
- full independence from non-EU services: AI models, speech recognition and the safety scan process (partly) in the US, under SCCs.
If that changes, we update this page — we put nothing here that we can't substantiate.
Ancora da compilare
This draft contains placeholders. Replace them all before publication — and claim nothing that isn't true yet.
- [[RPO]]
- Recovery Point Objective of the backups
- [[RTO]]
- Recovery Time Objective of the backups
- [[UREN]]
- Maximum data breach notification period in hours (same as the DPA)
- [[CADANS]]
- Frequency of pentests (e.g. yearly)
- [[SECURITY_EMAIL]]
- Email address for security reports
- [[REACTIETERMIJN]]
- Response time to a report (e.g. 3 working days)
- [[BUG_BOUNTY]]
- Reward policy or "no reward programme"
- [[DATUM]]
- Date of the latest change
- [[VERSIE]]
- Version number
Domande frequenti
Risposte rapide a quello che ci si chiede più spesso qui.
Il dominio è davvero mio?
Sì. Il dominio è registrato a tuo nome. Se lasci ChatBuild, te lo porti via senza problemi.
Il mio sito è automaticamente conforme al GDPR?
Sì. Ogni sito riceve un'informativa privacy, un'informativa cookie e moduli sicuri. Se la legge cambia, aggiorniamo tutto noi.
Dove vengono conservati i miei dati?
Su server nell'UE. Non raccogliamo più del necessario e non rivendiamo mai i dati.
Avete un accordo sul trattamento dei dati?
Sì, è incluso di serie in ogni piano. Leggi l'accordo sul trattamento dei dati