Security & Privacy
GDPRchat is built by FRITS AI ApS in Denmark and runs on a 100% European stack. Your data is processed inside the EU, under EU law — no US or Chinese providers in the core path, no tracking, no advertising, and we never train AI models on your data.
Where your data is processed
Provider by provider, this is who handles your data:
- Mistral AI (France)AI language model, embeddings, and voice transcription
- Hetzner (Germany)Servers, database (PostgreSQL / pgvector), and file storage
- Black Forest Labs (Germany)AI image generation
- Brave Search (US)Web search for current information — query text only, stripped of every identifier (no account data, no IP address), sent from our EU servers
No analytics, no tracking pixels, no fingerprinting, and no third-party advertising.
Sub-processors (GDPR Article 28)
These companies process personal data on our behalf to deliver the service. We have a data processing agreement with each one imposing equivalent GDPR obligations.
| Sub-processor | Purpose | Country / region |
|---|---|---|
| Mistral AI | AI language model, embeddings, and voice transcription | France |
| Hetzner Online GmbH | Infrastructure hosting (servers, database, file storage) | Germany |
| Black Forest Labs | AI image generation | Germany |
| Brevo (Sendinblue) | Transactional email delivery | France |
| Mollie B.V. | Payment processing | Netherlands (EEA — no third-country transfer) |
How we notify you of changes
Before we add or replace a sub-processor we notify subscribers in advance, and you have 30 days to object, as set out in our Data Processing Agreement.
Brave Search (US) receives the search query text only — composed by the AI and sent from our servers with no user identifiers or IP address attached. OpenStreetMap, Open-Meteo, Wikipedia, and Frankfurter.dev receive only non-personal query parameters. Google, Microsoft, and Apple act as independent controllers when you sign in with them — as does Apple for App Store purchases — and are not our sub-processors.
Data Processing Agreement
Read our pre-signed Data Processing Agreement online, or download it as a PDF to share with your legal team. No account required.
Data protection contact
We are not required to appoint a Data Protection Officer under Article 37 GDPR, but we treat data-protection enquiries as a first priority. For DPA counter-signing, sub-processor questions, or any GDPR request, contact:
Frits Lyneborg
Founder, FRITS AI ApS
support@frits.aiFRITS AI ApSCVR: 45733785
Nyhavn 38, 1051 København K, Denmark
You may also contact our lead supervisory authority, Datatilsynet (the Danish Data Protection Agency), at datatilsynet.dk