Security & Privacy

GDPRchat is built by FRITS AI ApS in Denmark and runs on a 100% European stack. Your data is processed inside the EU, under EU law — no US or Chinese providers in the core path, no tracking, no advertising, and we never train AI models on your data.

Where your data is processed

Provider by provider, this is who handles your data:

  • Mistral AI (France)AI language model, embeddings, and voice transcription
  • Hetzner (Germany)Servers, database (PostgreSQL / pgvector), and file storage
  • Black Forest Labs (Germany)AI image generation
  • Brave Search (US)Web search for current information — query text only, stripped of every identifier (no account data, no IP address), sent from our EU servers

No analytics, no tracking pixels, no fingerprinting, and no third-party advertising.

Sub-processors (GDPR Article 28)

These companies process personal data on our behalf to deliver the service. We have a data processing agreement with each one imposing equivalent GDPR obligations.

Sub-processorPurposeCountry / region
Mistral AIAI language model, embeddings, and voice transcriptionFrance
Hetzner Online GmbHInfrastructure hosting (servers, database, file storage)Germany
Black Forest LabsAI image generationGermany
Brevo (Sendinblue)Transactional email deliveryFrance
Mollie B.V.Payment processingNetherlands (EEA — no third-country transfer)

How we notify you of changes

Before we add or replace a sub-processor we notify subscribers in advance, and you have 30 days to object, as set out in our Data Processing Agreement.

Brave Search (US) receives the search query text only — composed by the AI and sent from our servers with no user identifiers or IP address attached. OpenStreetMap, Open-Meteo, Wikipedia, and Frankfurter.dev receive only non-personal query parameters. Google, Microsoft, and Apple act as independent controllers when you sign in with them — as does Apple for App Store purchases — and are not our sub-processors.

Data Processing Agreement

Read our pre-signed Data Processing Agreement online, or download it as a PDF to share with your legal team. No account required.

Data protection contact

We are not required to appoint a Data Protection Officer under Article 37 GDPR, but we treat data-protection enquiries as a first priority. For DPA counter-signing, sub-processor questions, or any GDPR request, contact:

Frits Lyneborg

Founder, FRITS AI ApS

support@frits.ai
FRITS AI ApS
CVR: 45733785
Nyhavn 38, 1051 København K, Denmark

You may also contact our lead supervisory authority, Datatilsynet (the Danish Data Protection Agency), at datatilsynet.dk

Related documents