Customer communication is among the most sensitive information a company manages. As an AI chatbot from Germany, we treat every message with the utmost care – and have built in data protection from the very first line of code.
Why data protection matters especially for an AI chatbot
A chatbot sees what customers write – often more than would appear in a classic contact form. That's exactly why it matters to us that this data doesn't end up somewhere abroad, but is processed under clear, European rules. "Privacy by design and by default" is no buzzword for us, but the foundation HeroChat is built on.
Hosting and processing in Germany
HeroChat is operated in data centres in Germany. Your data does not leave the European legal area without a valid legal basis. This means that every single processing operation is governed by the strict requirements of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) – and not by the less strict rules of other countries.
Data protection at a glance
- Server location and processing in Germany
- Data processing under Art. 28 GDPR – you remain the controller
- Your data is not used to train public AI models
- Technical and organisational measures according to the state of the art
Data processing: you stay in control
When you use HeroChat, you are the "controller" in the sense of the GDPR – we act as processor on your behalf and strictly according to your instructions. We provide the corresponding data processing agreement (DPA); you'll find it, along with further documents, in the sidebar.
Which data we process
We follow the principle of data minimisation: we only process what is truly necessary to run the chatbot. Essentially, this is the chat content needed to answer an enquiry, as well as contact details your customers provide themselves. Technical metadata is generated where it is required for secure and stable operation – no more and no less.
Artificial intelligence, used responsibly
Your customers' data is not used to train public AI models. The AI processing serves solely to answer the respective enquiry and takes place within the framework of the GDPR. This way you benefit from modern AI without giving up control over your data.
WhatsApp and the Business API
For WhatsApp we exclusively use Meta's official WhatsApp Business API. Meta is involved here as an additional processor. The data protection framework arises from Meta's terms as well as from our DPA. We have linked the most important sources on this in the sidebar.
Technical and organisational measures
Encrypted transmission, restrictive access controls, logging and the regular review of our systems protect your data according to the state of the art. We provide a detailed overview of our technical and organisational measures (TOM) as a document.
Your rights as a data subject
Access, rectification, deletion, restriction, data portability and objection: all data subject rights under Art. 15–21 GDPR are available to you. To exercise them, an informal message to us or directly to our data protection officer is enough.
Questions? Talk to us
Data protection thrives on transparency – and on people who answer questions. In the sidebar you'll find your direct contacts, first and foremost our data protection officer Dr. Martina Zell. Reach out any time.
This page serves transparent information and does not replace legal advice. The privacy policy and the data processing agreement (DPA) in force at any given time are authoritative.
Ready to reply faster?
Try HeroChat for free – 100 messages per month, no credit card required.
Try for free