Security & Privacy
GDPRchat is built by FRITS AI ApS in Denmark and runs on a 100% European stack. Your chats are processed and stored inside the EU, under EU law, and no US or Chinese company ever touches them. No tracking, no advertising, and we never train AI models on your data. The few services outside the EU that you can choose to use, such as signing in with Apple, are named further down this page.
Where your data is processed
Provider by provider, this is who handles your data:
- Scaleway (France)AI language model processing, text embeddings, and voice transcription
- Hetzner (Germany)Infrastructure hosting (servers, database, file storage)
- IONOS (Germany)AI image generation and image editing
- Linkup (France)Web search for current information — query text only, stripped of every identifier (no account data, no IP address), sent from our EU servers
No analytics, no tracking pixels, no fingerprinting, and no third-party advertising.
Sub-processors (GDPR Article 28)
These companies process personal data on our behalf to deliver the service. With each one we have a data processing agreement imposing equivalent GDPR obligations, or are in the process of concluding one; the current status for each is shown on our transparency page.
| Sub-processor | Purpose | Country / region |
|---|---|---|
| Scaleway | AI language model processing, text embeddings, and voice transcription | Paris, France |
| Hetzner Online GmbH | Infrastructure hosting (servers, database, file storage) | Germany |
| IONOS Cloud GmbH | AI image generation and image editing | Berlin, Germany (EU/EEA under the AVV) |
| Mollie B.V. | Payment processing | Amsterdam, Netherlands (EEA) |
| Scaleway (Transactional Email) | Transactional email delivery | Paris, France |
How we notify you of changes
Before we add or replace a sub-processor we notify subscribers in advance, and you have 30 days to object, as set out in our Data Processing Agreement.
Linkup (a French company) receives the search query text only — composed by the AI and sent from our servers with no user identifiers or IP address attached. Linkup runs its search infrastructure in the EU, the United States, Canada and Asia-Pacific, so a query may be answered from any of them. Nothing in that request identifies you, so no personal data leaves the EU when a search runs. OpenStreetMap, Open-Meteo, Wikipedia, and Frankfurter.dev receive only non-personal query parameters. Google, Microsoft, and Apple act as independent controllers when you sign in with them — as does Apple for App Store purchases — and are not our sub-processors.
Business customers who enter an EU VAT number to claim a reverse-charge exemption have that number sent to the European Commission’s VIES service (ec.europa.eu) to confirm its validity. VIES receives only the VAT number, only when voluntarily provided, and is operated by the European Commission — not as a sub-processor of FRITS AI ApS.
DataForSEO (an Estonian company) receives a product search term, a country name and a language code when you tap the deep price-comparison button on a shopping answer. The call is made from our servers, so DataForSEO never sees your IP address or any account identifier, and the request cannot be linked to you. It collects the prices from Google Shopping, and its own infrastructure providers include Google and Microsoft in the United States as well as Hetzner in Germany, so a request may be handled outside the EU. It carries no personal data, so this is not a transfer under Chapter V GDPR.
What leaves the EU/EEA
This is the complete list of the places your data can reach outside the EU/EEA, what is sent, when it happens, and the legal basis we rely on. Where we hold no adequacy decision and no Article 46 safeguard, the entry says so.
None of the sub-processors listed above is established outside the EU: every company that processes personal data on our behalf under Article 28 is a European company. The recipients below are a different thing — identity providers you choose, purchases in the iOS app, and map tiles. Web search is a different thing again, and it has its own section after this one: it carries no personal data, so it is not in this list.
- Apple Inc.United States
- What is sent
- For Sign in with Apple: the name and email address you approve — optionally Apple's private relay address instead of your real one. For a purchase in the iOS app: the App Store transaction, from which we receive a signed reference and never your payment details.
- When
- Only if you choose to sign in with Apple, or buy a subscription or credits inside the iOS app. Apple acts as an independent controller in both roles, not as our sub-processor.
- Legal basis
- EU-US Data Privacy Framework adequacy decision of 10 July 2023 (Article 45 GDPR), under which Apple is certified. Should that decision be invalidated or suspended we rely on Standard Contractual Clauses under Article 46(2)(c).
- Google LLCUnited States
- What is sent
- The name and email address held by the Google account you pick.
- When
- Only if you choose to sign in with Google. Google acts as an independent controller for the sign-in, not as our sub-processor.
- Legal basis
- EU-US Data Privacy Framework adequacy decision of 10 July 2023 (Article 45 GDPR), with Standard Contractual Clauses under Article 46(2)(c) as a fallback.
- Microsoft CorporationUnited States
- What is sent
- The name and email address held by the Microsoft account you pick.
- When
- Only if you choose to sign in with Microsoft. Microsoft acts as an independent controller for the sign-in, not as our sub-processor.
- Legal basis
- EU-US Data Privacy Framework adequacy decision of 10 July 2023 (Article 45 GDPR), with Standard Contractual Clauses under Article 46(2)(c) as a fallback.
- OpenStreetMap FoundationUnited Kingdom
- What is sent
- Your IP address for the tile request. If you turn on the precise-location feature, your coordinates rounded to roughly a kilometre are also sent for reverse geocoding. No account data is shared.
- When
- Only when a conversation renders a map, or you enable precise location.
- Legal basis
- The European Commission's United Kingdom adequacy decision of 28 June 2021 (Article 45 GDPR).
Where your searches go
This is a different thing from the list above, kept separate so it cannot be read as part of it. Nothing here receives personal data, so nothing here has a Chapter V basis to state. Where a search is actually handled is a fact you are entitled to all the same, so it is set out in full.
- LinkupFranceNo personal data
- Why this is not a transfer of your personal data
- When the assistant searches the web it sends a query it composed itself. No account, no user identifier, no IP address and no conversation content travel with it. Nothing links it to a person. It is our system's own outbound request — the same as a browser fetching a page — not the user's data. No personal data leaves the EU when a search runs. Determined 2026-09-03, and verified against src/lib/services/linkup-search.ts (callLinkup) rather than asserted.
- What is sent
- the search query, composed by the assistant
- a depth setting (how thoroughly to search)
- an output type (a result list, or a sourced answer)
- how many results to return
- sometimes a domain filter, an image flag, or an earliest date for news
- What is never sent
- your account or user identifier
- your IP address
- your name or email address
- the conversation the question came from
- a cookie, a session or any device identifier
- When
- Whenever an answer needs current information from the web. Linkup is the only company that receives a search: the United States standby we used when a Linkup call failed was removed on 3 September 2026, so a failed search now simply fails rather than being retried somewhere else.
- Where the request can be handled
- Linkup runs its own search infrastructure in the EU, the United States, Canada and Asia-Pacific and allocates queries across those regions by load. It does not guarantee that an individual search is handled locally, and its API has no region parameter, so we cannot pin one search to Europe. We say so rather than imply every search stays in the EU.
Data Processing Agreement
Read our pre-signed Data Processing Agreement online, or download it as a PDF to share with your legal team. No account required.
Data protection contact
We are not required to appoint a Data Protection Officer under Article 37 GDPR, but we treat data-protection enquiries as a first priority. For DPA counter-signing, sub-processor questions, or any GDPR request, contact:
Frits Lyneborg
Founder, FRITS AI ApS
support@frits.aiFRITS AI ApSCVR: 45733785
Nyhavn 38, 1051 København K, Denmark
You may also contact our lead supervisory authority, Datatilsynet (the Danish Data Protection Agency), at datatilsynet.dk