Trust & compliance

Compliance shouldn't have to be dug out of legal documents. Here is the full overview: where your data lives, how it is protected, and how the platform keeps you on the right side of both the GDPR and the AI Act.

Old wooden door secured with a sturdy bolt and padlock

GDPR in practice

Not promises in the air, but concrete mechanisms. The details are in the data processing agreement; here is the essence.

Hosted in the EU

The servers run at Contabo in Germany and the language model is Mistral AI in France. Full sub-processor overview in the DPA.

DPA included

The DPA is an annex to the Terms of Service and is entered into automatically at signup. No separate negotiation needed.

48-hour breach notice

In case of a personal data breach we notify you no later than 48 hours after becoming aware of it. The GDPR's own deadline to the supervisory authority is 72.

Concrete deletion deadlines

Knowledge base and conversation data are deleted no later than 30 days after termination, and backups rotate out no later than 21 days after that.

Encrypted all the way

TLS on all traffic and encryption at rest of the servers' data drives. Access keys are stored with AES-256-GCM.

Your data is yours

Tenant isolation at every layer, no training of general models on your content, and export in a standard format at any time.

Ready for AI Act Article 50

Since 2 August 2026, the EU's AI Act has required that users are clearly informed when they are talking to an AI. The requirement also applies to businesses that put a chatbot on their website, and the fines are substantial.

The fabrikken platform delivers the transparency out of the box: the chatbot presents itself as an AI, obtains explicit consent before the first message with timestamped documentation, and answers with source references, so nobody is in doubt about what they are talking to. In other words, Article 50 transparency is a built-in part of the product, not a project you have to run yourself.

The platform provides the tools; your specific setup and use remain your responsibility, cf. the Terms of Service.

Compliance FAQ

The questions your DPO asks first.

Where does our data live?

In the EU: hosting at Contabo in Germany and the language model at Mistral AI in France. Two transparent exceptions: speech-to-text is processed by Speechmatics in the UK (EU adequacy decision), and the network layer is currently provided by Cloudflare under the EU-US Data Privacy Framework. We are actively working to phase out the latter in favour of a purely European solution.

Who owns and controls the data?

You do. Your material and the knowledge base remain yours, the content is never used to train general language models, and you can have everything delivered in a commonly used format at any time.

What happens when we cancel?

Knowledge base, conversation data and configuration are deleted no later than 30 days after termination; backup copies rotate out no later than 21 days after that. Completed deletion is confirmed on request.

How do you handle security breaches?

We notify you without undue delay and no later than 48 hours after becoming aware of a breach, with the information you need for your own notification to the supervisory authority within 72 hours.

Can the chatbot be closed to the public?

Yes. Internal chatbots can be protected with IP gating, self-registration or named login, so only your own users have access.

Do we need to write our own data processing agreement?

No. Our DPA is entered into as an annex to the Terms of Service at signup and contains instructions, technical measures, the sub-processor list and deletion deadlines.

Does your DPO have more questions?

Talk to us