GDPR in day-to-day support, not just in the imprint
Published on March 18, 2025

Data protection in support is uncomfortably concrete. It is not about a banner. It is about the fact that your inbox holds addresses, order values, and occasionally very personal reasons for a return.
Where the data sits
We encrypt with AES-256 and host on GDPR-compliant German servers. A data processing agreement is available. Your conversations are not used to improve models for other merchants, and what your agent learns stays in your account.
What that means inside the product
Data protection you only see in a contract is worth little. So it sits in places where you notice it. Sensitive cases can be reviewed before they send rather than going out on their own. You enable automation category by category, not in one sweep. And the agent pulls order data at the moment it needs it, instead of hoarding it in advance.
What we do not claim
We are not a law firm and this is not legal advice. The information duties and deletion policies on your side stay your job. What we provide is a system that does not get in the way of them, and a straight answer about where which data sits when you need one.