Last updated: June 2026

Trust & Security

Overview

We build ChatBakers for marketing agencies and enterprise teams who care where their data lives and who can touch it. This page captures the short answers to the questions your security and legal teams will ask.

Data Hosting

All customer data — agency portals, client metadata, AI visibility results, audit logs, PDF reports — is hosted in EU-only Hetzner datacenters (Falkenstein DE and Helsinki FI). No primary data leaves the EU. The only cross-border transit is the outbound AI provider APIs (OpenAI, Anthropic, Google, Perplexity). These are documented in the sub-processors list below. The query payloads carry only the prompt text you configure, not your account or client identifiers.

GDPR

We act as a Data Processor for the client data you upload to your agency portal; you remain the Data Controller. A standard DPA (Data Processing Agreement) template is available. Email [email protected] and we'll send the latest version within 1 business day.

Right of access, rectification, erasure, and portability are all self-service via the agency portal and the per-user cookie preferences. Manual requests to the contact below are honored within 30 days per GDPR Article 12.

Sub-processors

Vendors that process customer data on our behalf. We update this list when we add or remove a sub-processor and provide 30-day advance notice of changes.

Vendor Purpose Region
Stripe Payments + invoicing EU + US
Resend Transactional email + DKIM EU
OpenAI AI visibility queries (ChatGPT) US
Anthropic AI visibility queries (Claude) US
Google AI AI visibility queries (Gemini, Google AI Mode) US
Perplexity AI visibility queries (Perplexity, Grok via API) US
Hetzner Application + database hosting EU (Falkenstein DE, Helsinki FI)
Cloudflare DNS, edge caching, R2 object storage Global edge
MongoDB Atlas Primary database + audit log retention EU (Frankfurt)

Security

We implement appropriate technical and organisational measures to protect your personal data. These include TLS encryption in transit, encryption at rest, access controls on a need-to-know basis, and ongoing monitoring for anomalies.

To report a vulnerability or request an SBOM or pentest summary, contact us at [email protected]. We acknowledge reports within 1 business day and aim to provide an initial assessment within 3 business days.

Incident Response

We notify affected customers within 72 hours of confirming a personal-data breach, per GDPR Article 33. Notification includes the nature of the breach, categories and approximate number of records affected, likely consequences, and remedial measures taken or proposed.

Contact

For security disclosures, DPA requests, or any compliance questions, contact us at:

UGIPO Group s.r.o.

Pobrezni 249/46, Karlin, 186 00 Praha, Czech Republic

Email: [email protected]

Related Pages