Last updated: June 2026
Trust & Security
Overview
We build ChatBakers for marketing agencies and enterprise teams who care where their data lives and who can touch it. This page captures the short answers to the questions your security and legal teams will ask.
Data Hosting
All customer data — agency portals, client metadata, AI visibility results, audit logs, PDF reports — is hosted in EU-only Hetzner datacenters (Falkenstein DE and Helsinki FI). No primary data leaves the EU. The only cross-border transit is the outbound AI provider APIs (OpenAI, Anthropic, Google, Perplexity). These are documented in the sub-processors list below. The query payloads carry only the prompt text you configure, not your account or client identifiers.
GDPR
We act as a Data Processor for the client data you upload to your agency portal; you remain the Data Controller. A standard DPA (Data Processing Agreement) template is available. Email [email protected] and we'll send the latest version within 1 business day.
Right of access, rectification, erasure, and portability are all self-service via the agency portal and the per-user cookie preferences. Manual requests to the contact below are honored within 30 days per GDPR Article 12.
Sub-processors
Vendors that process customer data on our behalf. We update this list when we add or remove a sub-processor and provide 30-day advance notice of changes.
| Vendor | Purpose | Region |
|---|---|---|
| Stripe | Payments + invoicing | EU + US |
| Resend | Transactional email + DKIM | EU |
| OpenAI | AI visibility queries (ChatGPT) | US |
| Anthropic | AI visibility queries (Claude) | US |
| Google AI | AI visibility queries (Gemini, Google AI Mode) | US |
| Perplexity | AI visibility queries (Perplexity, Grok via API) | US |
| Hetzner | Application + database hosting | EU (Falkenstein DE, Helsinki FI) |
| Cloudflare | DNS, edge caching, R2 object storage | Global edge |
| MongoDB Atlas | Primary database + audit log retention | EU (Frankfurt) |
Security
We implement appropriate technical and organisational measures to protect your personal data. These include TLS encryption in transit, encryption at rest, access controls on a need-to-know basis, and ongoing monitoring for anomalies.
To report a vulnerability or request an SBOM or pentest summary, contact us at [email protected]. We acknowledge reports within 1 business day and aim to provide an initial assessment within 3 business days.
Incident Response
We notify affected customers within 72 hours of confirming a personal-data breach, per GDPR Article 33. Notification includes the nature of the breach, categories and approximate number of records affected, likely consequences, and remedial measures taken or proposed.
Contact
For security disclosures, DPA requests, or any compliance questions, contact us at: