Your company's data stays your company's.

An assistant that knows your rules, prices and numbers has to keep them safe. Below, exactly where the data is, who sees it and what we never do with it.

Where the data is

  • Servers in Germany, in the EU. Logically separate database per customer; no customer ever sees another's data.
  • Custom option: installation on your own server when your internal policy requires it.
  • Daily encrypted backups, kept for 30 days.

What is encrypted

  • Documents and knowledge chunks, at rest and in transit (TLS).
  • Conversations from every channel.
  • AI keys and channel tokens: encrypted, never shown after saving, replaceable any time.
  • Access to your database (Custom): read-only, encrypted credentials, connection restricted to our IP addresses.

What we never do

  • We never use your documents or conversations to train models, neither ours nor the providers'.
  • We never sell or pass data to third parties. The AI provider receives only the text needed for an answer, through your key, under its API terms (no training on API data).
  • We never keep conversations beyond your plan's retention: 30 days on Free, 365 on Pro, after which they are deleted.

Who has access

  • You and the people you add, with roles: owner, admin, agent.
  • The GatPilot team: only at your request, for support, with logged access.
  • Team members (Team Assistant): only their own conversation.

Your control

  • Delete any source, conversation or the whole account, any time, from the dashboard. Deletion is final after 30 days.
  • Export conversations and leads (CSV).
  • Disconnect any channel with one click.

Compliance

  • Processing under the GDPR for EU customers. Data Processing Agreement (DPA) available on request for Pro and Custom.
  • Sub-processors: hosting provider in Germany; the AI provider you choose, under your own key.

Frequently asked questions

Yes, on the Custom plan.

It receives only the text needed for the answer, via API, without training. With your own key, the contractual relationship is directly between you and the provider.

All data is permanently deleted after 30 days. You can export before.

Not yet. The infrastructure runs at an ISO 27001 certified provider in Germany.

Questions about security?