Chatwize

Legal & Compliance for Businesses

At Chatwize, we are committed to providing safe, transparent, and efficient AI-driven solutions. Our technology is designed to help businesses improve customer interactions while ensuring privacy, data protection, and compliance with industry best practices.

We collaborate with trusted technology providers and implement security measures that meet high standards for data protection and responsible use of AI. For detailed information on how we process data in accordance with the GDPR, please refer to our Data Processing Agreement (DPA), which you can find in the middle of this page.

*We prioritize security, compliance, and user control, so businesses can deploy AI with confidence.

Privacy & Data Protection

Businesses using Chatwize can choose not to store personal data. In that case, the chatbot is intended solely for informational purposes. At the beginning of each chat conversation, a disclaimer is shown instructing users not to enter personal data.

We also recommend mentioning in the disclaimer that the user is communicating with an AI chatbot and not a human employee. This makes it immediately clear to the visitor and provides their explicit consent before the conversation begins.

If a business does want to process personal data, it is important to activate the disclaimer function and refer to the privacy policy and terms and conditions. Users must first agree to these terms before they can chat. This can optionally also be included in the cookie notice on your website.

Additionally, we advise updating your privacy policy and terms and conditions with a brief section on the use of an AI chatbot. This ensures full transparency and complies with current legislation in a user-friendly manner.

At Chatwize, we enable businesses to proactively control and manage their data. Conversations are retained for as long as the customer account is active, unless a shorter period has been agreed: an automatic deletion period can be configured per customer environment (from 7 days onwards), after which conversations are permanently deleted. In addition, businesses can manually manage and delete conversations at any time. This allows organizations to effectively align their own data storage policies with privacy regulations and internal security standards.

Users have full control over their data and can permanently delete conversations at any time. Once deleted, the data is completely erased from our system and cannot be recovered. Businesses using Chatwize can manage stored conversations via the platform and manually delete data if necessary. This ensures that customer data is handled safely and can be permanently deleted upon request, to maintain compliance with privacy legislation and data protection standards.

Businesses using Chatwize are responsible for ensuring the correct management of data and compliance with the GDPR (General Data Protection Regulation). We offer tools that allow businesses to manage their privacy settings, data retention, and security configurations. For transparency, Chatwize provides a Data Processing Addendum (DPA) that explains in detail how data is processed, stored, and protected. Businesses can consult this legal documentation to ensure they meet regulatory standards and understand and comply with their data protection obligations.

Legal & Compliance Documents

AI Act Statement & Disclaimer

Download

Privacy Policy for Chatwize Services

Read online

Terms & Conditions

Read online

Data Processing Addendum (DPA)

On request

Security and Compliance Statement

On request

Sub-processor Overview

On request

Security & Hosting

Chatwize runs entirely on European infrastructure: the application in Amsterdam and the database with document storage in Frankfurt. Our infrastructure providers are ISO 27001 and/or SOC 2 certified and we demonstrably apply the measures from these frameworks. Our Security and Compliance Statement, which you can request here, describes them in detail.

All storage takes place within the European Union: uploaded documents, the knowledge base, conversations and account data reside in Frankfurt and Amsterdam. The only processing outside the EU is the generation of the answer itself, by OpenAI, under EU Standard Contractual Clauses (SCCs).

All connections are encrypted via TLS (HTTPS) and data is stored encrypted. Customer data is strictly separated per customer through row-level access control (Row Level Security) at database level; this isolation is tested periodically. Critical administrative accounts are protected with two-factor authentication, and the database is backed up automatically every day, with a demonstrably tested restore procedure.

Chatwize uses the OpenAI API. Data processed via the API is not used by OpenAI to train or improve AI models; this is contractually established in the OpenAI data processing agreement. OpenAI may briefly retain API input for abuse detection.

View OpenAI DPA